• On MovieTome: The 10 worst movies of 2009 so far!
April 2, 2007 12:33 PM PDT

JavaScript bug-hunting tool 'stolen'

by Joris Evers
  • Font size
  • Print
  • Post a comment

Web security firm SPI Dynamics tried to keep private a tool that turns PCs of unknowing Web surfers into drones for hackers, but the source code has made it onto the Web anyway.

"Jikto's code is in the wild," SPI researcher Billy Hoffman wrote in a blog post on Monday. "A guy named LogicX grabbed a copy...and posted it on Digg just a day after Shmoocon."

The individual was able to get the code because Hoffman in his presentation at the hacker conference displayed the Web address of the site hosting Jikto.

"If someone watched very closely they could see the URL of where Jikto's code was...Someone could have seen the URL and grabbed it," Hoffman wrote.

Jikto is a Web-application vulnerability scanner created in JavaScript. It can silently crawl and audit public Web sites, and then send the results to a third party, Hoffman said in his ShmooCon presentation. Jikto can be embedded into an attacker's Web site or injected into trusted sites by exploiting a common Web security hole known as a cross-site scripting flaw, he said.

Hoffman initially planned to release Jikto's code at ShmooCon, but changed his plans after higher-ups at SPI said he shouldn't. The reason: Jikto could be used for malicious purposes.

Recent posts from News Blog
Nvidia puts NForce chipset development on hold
Opera 10 browser is here
Neil Young Archives Blu-ray: Rip off?
Acronis revises survey results about backup habits
Acronis miscalculates data on users' bad backup habits
Flickr co-founder presses beta button
Comcast, Sony open retail store
Cox to try coaxing the Internet into submission

A CNET Conversation with Eric Schmidt

CNET's Tom Krazit and Molly Wood sit down with Google CEO Eric Schmidt to discuss the future of Android, the Chrome OS, the problem of real-time search indexing, and more.

Verizon tests sending RIAA copyright notices

The No. 2 phone company, known for its reluctance to intervene in antipiracy cases, strikes an agreement to forward copyright notices on behalf of the music industry.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right