Version: 2008
  • On MovieTome: See the villain of IRON MAN 2!

Comments on: Tool turns unsuspecting surfers into hacking help

With Jikto, JavaScript on a Web site can turn PCs into a bug-hunting tool, thus doing a hacker's dirty work.

Add a Comment (Log in or register) (16 Comments)
  • prev
  • 1
  • next
That's Nice!
by Kings X Rocks! March 21, 2007 4:53 AM PDT
I especially like the part where Hoffman is going to release it publicly later on. AND, the next version will exploit as well as probe.

Wouldn't it be sufficient to just SAY that it can be done via JS and require a signed "use-it-and-go-to-jail-form" before anyone can hear the details of how?
Reply to this comment
Not much point
by Hoser McMoose March 21, 2007 7:40 AM PDT
Even if he doesn't release it and no one from the presentation does either, the only real details required are "JavaScript version of Nikto". From that pretty much any malicious hacker with experience in JavaScript could write the thing. It might take an extra week or so, but that's about it.
hi
by n3td3v March 21, 2007 6:55 AM PDT
how much did they pay you mr.evers?
Reply to this comment
Lets's "pollute" Java some more
by felgercarbnaysay March 24, 2007 9:31 PM PDT
When you say "they" I assume you mean Microsoft.
Reward
by videofuel March 21, 2007 8:43 AM PDT
Should we thank this guy or hate him?
Reply to this comment
hate
by n3td3v March 21, 2007 8:52 AM PDT
he is adding to the problem.

he knows all types (including malicious hackers) will use this tool, and he doesn't care.

all he cares about is his own status at the security conference in 2007.

more than likely he has a web site too, with adverts at the side as well.
View reply
Thank him.
by fcekuahd March 21, 2007 10:02 AM PDT
Everybody who programs in JavaScript and AJAX already knows about this possibility. It's great that he's bringing it to our attention. IMO, unrestricted cross-site scripting is a major security hole in JavaScript and it should either be restricted or tools should be provided to manage it.

One thing about this though: JavaScript implementations typically aren't very good at managing threads, so if a malicious site is running a process like this, it should be pretty obvious. You will see a noticeable degradation in the responsiveness of your web browser.
View reply
Extortion
by guruwannabe March 22, 2007 9:32 AM PDT
What this guy and his company are attempting to do is same thing that the mafia does. They are releasing a hacking tool and his company will sell you a product that will protect you from it. Any business owner knows you need to buy protection from the mob!
Reply to this comment
Turn off Java Script
by javaclinic2 March 24, 2007 5:45 PM PDT
I think, it is time to TRAIN the most dangerous threat "THE USERS". Since i see one of the solution for Stopping Java Script attack is to turn them off. BUT in this way all of web 2.0 based application will stop working.

May be it will solvable with some Firefox plugins.

Zeeshan Ali Shah
www.Xeeshan.com
Reply to this comment
I am NOT turning off Javascript
by Ilgaz March 25, 2007 8:52 AM PDT
If any site I visit plants a javascript crap on my machine, I am
calling the authories. At least they know who to question now.

These type of new idiots really made security business get bad
name from average user.
Reply to this comment
bugs me not lol
by aabcdefghij987654321 March 25, 2007 11:18 AM PDT
noScript and firebug are so gonna kick ur lousy little scripts ass.
Reply to this comment
bugs me not lol
by aabcdefghij987654321 March 25, 2007 11:19 AM PDT
and bug me not owns cnet
Reply to this comment
Jikto Source Leaked
by justanotheruser March 25, 2007 11:45 PM PDT
The Jikto source appears to have been leaked and subsequently
taken down here:

http://blog.vulnerableminds.com/2007/03/javascript-internal-
port-scan-source_25.html
Reply to this comment
jikto
by Shakyamuni July 31, 2007 3:36 PM PDT
this is a dangerous one...
Reply to this comment
(16 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement