Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Better System Admin Tools: Oracle Management Pack for Linux | Main | 10 Tips for Minimizing Complexity to Improve Security »

Vista Security: Gadgets Could be New Avenue of Attack

At least one security vendor is warning that Vista’s widgets (small utility programs like desktop applications form Google and Yahoo) could become a popular method of attack. The problem, is that gadgets are applications with full access to process resources. They are not like Java applets that run in a sandbox. This is bad news according to some.

One problem is the potential for one widget to change the behavior of another. Ulrika Hedquist writing in PC Advisor quotes Eric Chien of Symantec

"And because all gadgets support JavaScript, cross-platform infections are possible," he adds. "A Yahoo gadget could, potentially, infect a Vista gadget, for example."

Although it should be relatively easy to spot script code that directly modifies another widget, malware writers are likely to use modifying code to obscure the function their code. Again, from the PC Advisor article:

On the other hand, because most gadgets are written in script languages, it is also quite easy to add to the existing code and modify the gadget. Some frameworks do prevent gadgets from being modified, but gadgets are easily modified in Vista, [Chen] says.

Gadgets written using compiled languages will require anti-malware tools for signature-based or behavior-based detection. Fortunately, Microsoft and security vendors have worked out their differences about Vista kernel access and there will be plenty of third-party options when the consumer version of Vista ships next week. See Gregg Kezeir’s Microsoft Lines Up Vista Security Partners in Dr. Dobbs Portal for more on that.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/194

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net