Symantec Blogs: Security ResponseSyndicate content

Andrea Lelli | December 6th, 2007
0 comments

Given the choice when browsing, I woulddownload and save an executable file rather than directly run it. Freewill has always been a hot topic in philosophy and when it comes to Webbrowser security the topic suddenly gets hot as well! I was recentlybrowsing a well known adware vendor Web site when I decided to downloada game and try it. As usual I came across a normal download page:

image1_lrg.jpeg
Figure 1: The standard Web download interface

After clicking “continue” I was prompted with the usual “FileDownload” message box from Internet Explorer, but it actually took me awhile to realize something was missing:

image2_lrg.jpeg
Figure 2: File...

Andrea Lelli | October 25th, 2007
0 comments

A couple of weeks ago in thisblog entry, we learned how misleading applications advertise themselveson the Web. Now we'll take a closer look at the other side of things tosee how misleading applications infiltrate users' machines in order toconvince people to download and purchase them.

We are used to seeing malware that uses all sorts of tricks tocompromise a user's machine in order to steal valuable information orperform fraudulent activities. The purpose of all of this? Of course!Money! Why else would the miscreants otherwise make the effort ofstudying new tricks and developing new malware when they can simplyconvince users to give up their money spontaneously?

This is how it goes with misleading applications. They can appear inseveral ways, such as in downloaders or simply via browseradvertisements: "Your...