PDF and Flash files under threat from cryptic code
Disguised or hard to understand code is become more of a threat to Web 2.0 websites as criminals taking advantage of JavaScript.

PDF and Flash files are under attack by criminals using code obfuscation' and the latest Web 2.0 techniques, according to a report by Finjan.
The new report claimed that malicious obfuscated code' - meaning source code or intermediate code which is very hard to read or understand - has now evolved into a serious threat.
It looked at examples where obfuscated code had not only been embedded in HTML web pages on legitimate websites, but also in rich-content files thanks to the use of JavaScript.
"Since JavaScript is the most-used scripting language for communication with web browsers, third-party applications such as Flash players, PDF readers and other multimedia applications have added support for JavaScript as part of their application," said Yuval Ben-Itzhak, chief technology officer of Finjan.
Ben-Itzhak said this offered crimeware authors ways to inject malicious code into rich-content files used by ads and user-generated content for Web 2.0 websites.
Obfuscated code has been around a while; it has been reportedly been used since 2005 as a weapon for propagating malicious code. It was able to bypass the traditional signature-based solutions which had been used by security vendors.
Finjan claimed code obfuscation utilities and other encoding methods allowed cybercriminals to plant invisible' malicious code, which infected a user's machine every time they visited the malicious site.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Last year IT PRO looked at the threat provided by dynamic code obfuscation'.
-
Asus ZenScreen Fold OLED MQ17QH review
Reviews A stunning foldable 17.3in OLED display – but it's too expensive to be anything more than a thrilling tech demo
By Sasha Muller
-
How the UK MoJ achieved secure networks for prisons and offices with Palo Alto Networks
Case study Adopting zero trust is a necessity when your own users are trying to launch cyber attacks
By Rory Bathgate
-
Adobe releases third unscheduled Flash security update
News Software giant forced to act following discovery of flaw affecting video sharing site Dailymotion
By Clare Hopping
-
100 fake eBay listings put users' privacy at risk
News Innocent users' accounts being used to post malicious listings
By Clare Hopping
-
eBay UK users warned of cross-site scripting attacks in listings
News Online auction site falls victim to hackers who've tampered with listings to steal users' login details
By Caroline Donnelly
-
FBI allegedly used browser vulnerability to target child abuse ring
News American intelligence agency operation reportedly leads to Irish extradition.
By Jane McCallion
-
Hitachi unveils ‘industry first’ 25nm SSD
News The storage giant brings single-level cell NAND flash to enterprise storage.
By Jennifer Scott
-
Adobe focuses on cross-platform app development
News Adobe appeals to developers with cross-platform app tools.
By Paul Briden
-
Adobe tops security risk list
News Acrobat Reader leads the pack as the most risky PC vulnerability.
By Paul Briden
-
Web firm accused of spying on children
News Class action claims widget tracks users' online habits through Flash cookies.
By Martin James