|
Aardvark DailyThe world's longest-running online daily news and commentary publication, now in its 30th year. The opinion pieces presented here are not purported to be fact but reasonable effort is made to ensure accuracy.Content copyright © 1995 - 2025 to Bruce Simpson (aka Aardvark), the logo was kindly created for Aardvark Daily by the folks at aardvark.co.uk |
Please visit the sponsor! |
So you're a savvy websurfer running the latest versions of browser and OS software -- patched to perfection. You're safe -- right?
Well it would appear that that type of smugness could come before a very nasty fall.
While perusing the newswires this morning I noticed that there seem to be an awful lot of gaping holes in the fabric on the internet today.
In fact, it might be a good day to leave the DSL connection turned off if you've got a faint heart.
First-up, if you're a YahooMail user then your account is at risk of being hijacked by a simple little ploy that can hand your session cookies over to any script-kiddy with half a brain.
Watch this video for a demonstration of how simple that exploit can be.
However, if you're a GMail user then you're safe -- unless of course -- you have Java installed on your browser. If you do have the supposedly super-secure sandboxed system running then there's a great zero day exploit just waiting to ruin your day.
Even webmasters are getting it in the neck from the hackers right now, with reports suggesting that more than 200,000 websites are presently vulnerable to a remote code attack, delivered by way of SQL injection against servers using the Ruby on Rails framework.
Time to put on your cyber-kevlar vest and flak jacket me thinks!
Maybe it's also time to remind folks of the many advantages that can be had from setting up a separate "minimalist" PC with which to do their websurfing.
Grab that old bit of hardware, throw a half-decent Linux distro on it, install some of your favourite OSS Net aps and away you go!
If, at any time, you become concerned that it may have been compromised -- just nuke the drive's contents and re-install from scratch. It's a pretty easy job to copy the key config files over to the new install (unlike a Windows setup) and you'll once again have that "ring of confidence" that you're surfing cleanly.
It might be a good idea to remind less savvy friends and family *not* to open unsolicited emails or click on unsolicited links (remember that YahooMail exploit?). Good security is as much about good practice as it is about having good software and the latest patches.
Now perhaps readers can help me...
I'm not a smartphone user. In fact, my phone is the dumbest phone on the planet (I've already whined and whinged about this crappy LG phone before). In fact, this phone is so lame that it seems to suffer from the Y2.013K bug.
Yes, that's right, at the stroke of midnight on Jan 1, 2013, it updated its date from 31/12/2012 to utter gibberish and now it displays a date of 104/51/2012M. What's more, when I attempt to manually reset the date, the new digits that appear on the screen bear no relationship to the buttons I press on the keypad.
Ugh!
But that's not my problem -- what I'm wondering is... what do people do if/when their fancy smartphone gets infected by a bad virus/worm?
With a PC you can (as a final measure) simply do a low-level format of the drive and re-install the OS/apps. What are the options with your Samsung Galaxy or other super-duper Android-based device?
Please visit the sponsor! |
Oh, and don't forget today's sci/tech news headlines
Beware The Alternative Energy Scammers
The Great "Run Your Car On Water" Scam