Author Topic: How does your system become infected by just browsing  (Read 5325 times)

0 Members and 1 Guest are viewing this topic.

victor43

  • Guest
How does your system become infected by just browsing
« on: January 23, 2010, 06:27:21 PM »
I am looking to find out the mechanics of their technique that essentially uses a browser to infect ones system.

I have personal experience of contracting a what I believe a virus/malware and it ending up somewhere on my computer and not in the browser cache.How is this possible and how can registry be modified at the same time ? I believe that the virus is able to circumvent the browser memory/disk space and into the rest of the system ? I just don't know how this is done.

Any comments would be appreciated

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: How does your system become infected by just browsing
« Reply #1 on: January 23, 2010, 06:38:26 PM »
A security hole in the browser allows execution of commands outside the browser. Technically, a 'vulnerability' is 'exploited' to download, install and run malware, or malicious software.

Try Googling "browser vulnerability" or "browser exploit" for more information.
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

zerospam

  • Guest
Re: How does your system become infected by just browsing
« Reply #2 on: January 23, 2010, 08:50:54 PM »
To expand upon FreewheelinFrank's note, malware theoretically can exploit a security flaw in anything that touches it, not just a browser. Before your browser sees a web page, it passes through several layers of hardware, firmware, and software. Malware could exploit a security flaw in any of these layers to infect your machine.

Imagine that, for example, your operating system's ethernet or wifi driver has a bug that writes some data onto a portion of the stack it doesn't own when it receives a certain kind of IP packet. Imagine also that an attacker has discovered how to exploit this flaw, and has put her exploit (malware) onto a website. When you browse to that site, your browser asks the operating system to request data from it. The website sends, among other things, the malware back to your computer. Your computer's ethernet driver reads the malware, malfunctions, and eventually begins to execute the malware, which can then do anything it wishes.

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: How does your system become infected by just browsing
« Reply #3 on: January 23, 2010, 09:04:23 PM »
To expand upon FreewheelinFrank's note, malware theoretically can exploit a security flaw in anything that touches it, not just a browser. Before your browser sees a web page, it passes through several layers of hardware, firmware, and software. Malware could exploit a security flaw in any of these layers to infect your machine.

Imagine that, for example, your operating system's ethernet or wifi driver has a bug that writes some data onto a portion of the stack it doesn't own when it receives a certain kind of IP packet. Imagine also that an attacker has discovered how to exploit this flaw, and has put her exploit (malware) onto a website. When you browse to that site, your browser asks the operating system to request data from it. The website sends, among other things, the malware back to your computer. Your computer's ethernet driver reads the malware, malfunctions, and eventually begins to execute the malware, which can then do anything it wishes.

Indeed-  malware has exploited many web-facing applications, not just browsers. Flash, Java, PDF are the usual suspects in browsing drive-by downloads, not to mention the man helpful features of IE and Windows that seem to avail themselves so well to "misuse".
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog


Hermite15

  • Guest
Re: How does your system become infected by just browsing
« Reply #5 on: January 23, 2010, 09:15:10 PM »
activeX in Internet explorer  ;D ... can happen to any site, legit or not, any time, without that the site's owner would even be aware of anything.

zerospam

  • Guest
Re: How does your system become infected by just browsing
« Reply #6 on: January 23, 2010, 09:42:34 PM »
activeX in Internet explorer  ;D ... can happen to any site, legit or not, any time, without that the site's owner would even be aware of anything.
On this and similar topics, three of the best things you can do to avoid drive-by infections are (1) Keep your OS up-to-date; (2) Don't use IE (except for Microsoft updates); and (3) Run your browser in a non-administrator account that is allowed access only to the data that it needs to run.

Running a browser in an administrator account is simply begging to be infected.

Oh, and the single best thing you can do to avoid infections generally is to never run anything that isn't digitally signed by a reliable source.
« Last Edit: January 24, 2010, 05:02:36 AM by zerospam »

victor43

  • Guest
Re: How does your system become infected by just browsing
« Reply #7 on: January 24, 2010, 03:45:44 AM »
Many thanks for the informative replies. Will definitely read through everything carefully.

That's the kind of replies I was searching for but previous searches on google did not turn up anything.

Victor

Offline Shiw Liang

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1432
Re: How does your system become infected by just browsing
« Reply #8 on: January 24, 2010, 03:54:09 AM »
Wow internet explorer is not safe at that point?
OMG!!!

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3695
  • If at first you don’t succeed; call it version 1.0
Re: How does your system become infected by just browsing
« Reply #9 on: January 24, 2010, 04:52:25 AM »
Quote
Wow internet explorer is not safe at that point?
OMG!!!
Are you being sarcastic, or did you really not know about that?
Windows 10,Windows Firewall,Firefox w/Adblock.

kadenk

  • Guest
Re: How does your system become infected by just browsing
« Reply #10 on: January 24, 2010, 05:31:22 AM »
if you use the avast sandbox for your web browser or better yet sandboxie. makes drive by and other things like that a thing of the past (more powerful, and lets you try out programs before installing them)

if you want to try sandboxie (it's free) you can get it here but only if you are using 32 bit operating system

if you have avast pro obviously use that sandbox

http://www.sandboxie.com/SandboxieInstall.exe