With the development of Web 2.0, the interaction between the Internet is getting stronger and stronger, but according to Itzik Kotler, head of IT security company radware security operation center. Javascript may become a new hacker attack point.
In addition to developing new signature and analysis tools for radware scanning software, Kotler is also looking for new security vulnerabilities. According to his findings, a security vulnerability in Javascript allows hackers to copy files from customers' computers rather than easily detect them.
At the RSA Security Conference held in London this week, Kotler demonstrated this hacking method and demonstrated how to execute htmlCodeTo detect the existence of antivirus software. Kotler said that this new attack method will attract cyber criminals because of the following two advantages: 1. This method is not easy to detect, and 2. cross-platform cross-browser.
He concluded that although this attack method has not been used by hackers, browser vendors and security companies must ensure that browsers are more flexible while not opening backdoors for hackers.