GIFAR: A photo that can steal your online credentials
Aug 4th, 2008 | By Premnath Sah | Category: TechnologyBy placing a new type of hybrid file on Web sites that let users upload their own images, researchers can circumvent security systems and take over Web surfers’ accounts
At the Black Hat computer security conference in Las Vegas next week, researchers will demonstrate software they’ve developed that could steal online credentials from users of popular Web sites such as Facebook, eBay, and Google.
The attack relies on a new type of hybrid file that looks like different things to different programs. By placing these files on Web sites that allow users to upload their own images, the researchers can circumvent security systems and take over the accounts of Web surfers who use these sites.
They call this type of file a GIFAR, a contraction of GIF and JAR, the two file types that are mixed. At Black Hat, the researchers will show attendees how to create the GIFAR while omitting a few key details to prevent it from being used immediately in any widespread attack.
more here
RSS Feed
Email







