JavaScript
SSCC 105 - HP printers, Google blocks ad blockers, Apple does the 2-step, and more...
Have you joined thousands of others, and become a loyal listener to the "Chet Chat" yet?
Here's the latest Naked Security podcast, Sophos Security Chet Chat 105, discussing a range of recent and newsworthy topics from the world of computer security.
Anatomy of a "feature" - should JavaScript be allowed to change a web link *after* you click on it?
A young web coding enthusiast from Manchester, UK, recently published a thought-provoking hackette intended to highlight the risks of relying only on "look before you click."
Paul Ducklin wants to know what you think of it...
Apple's own Macs bitten by Java-based malware attack
Apple released a statement today acknowledging that they were victims of the same attackers that Facebook talked about last week. A zero-day Java vulnerability infected Apple Mac developers through a drive-by attack.
Malware injected into legitimate JavaScript code on legitimate websites
SophosLabs has observed a trend of hackers inserting their malicious code into legitimate JavaScript hosted on legitimate compromised websites.
Learn more about what our experts have seen, and ensure that you have protection in place.
Java is not JavaScript - tell your friends!
Some people are worried that turning off Java also turns off JavaScript.
Despite their names, Java and JavaScript are completely different, and turning off Java will not turn off JavaScript.
Firefox 18 brings TURKTRUST update, Retina support, faster JavaScript - oh, and 20 other security fixes
Firefox 18 has landed: 2917 bugs patched, 21 security fixes, 12 critical.
Also with a brand-new JavaScript compiler and support for Retina displays on the groovier sorts of Mac.
Sophos Techknow - All about Java
Java brings with it some significant risks, yet for many people, it's "just there on my computer."
In this episode, Duck and Chet tell you All about Java, and help you to make an informed decision in balancing its risks and rewards at work and at home.
Vote in our poll: is Google's fine of $22.5 million enough to buy privacy?
Google will cough up $22.5 million for putting sneaky code into its web pages, even after agreeing that it would get "comprehensive" about privacy.
But are financial sanctions enough?
Have your say in our poll...
Facebook explains pornographic shock spam, hints at browser vulnerability
Facebook has released a statement about the fast spreading offensive messages that have been posted to many users walls. They claim there is a browser vulnerability that allowed users to paste malicious JavaScript into their web browsers and post the offensive messages.
You practice safe computing, so why do you still see malware?
Think you are a security aware computer user, but still get occasional security alerts and pop-ups? Follow these tips to help keep your Mac or PC clean as a whistle.
WordPress plugins Trojanised, spotted, fixed
WordPress just announced that the source code for three plugins for its popular blog-hosting platform had been Trojanised. Fortunately, the malicious changes have now been removed. Find out what happened and how to fix it.
Profile Stalkers on Facebook? Check out the viral scam that's spreading
Will you really see who views your Facebook profile? Will you really discover who your top profile stalkers on Facebook are?
Maybe it's time for a reality check.
Why are you tagged in this video? It's a viral Facebook scam
Facebook users have been hit by another fast-spreading scam today, pretending to be a link to a YouTube video that they have been tagged in.
Facebook announces new security features - but do they go far enough?
Facebook has just published an article entitled Keeping You Safe from Scams and Spam. It's all about improving security on its network.
Paul Ducklin reports on the good, the bad and the missing.
Facebook scam with a difference - Social Tagging Worldwide avoids rogue apps
Sick of reading about rogue apps on Facebook? Here's a Facebook scam with a difference.
A "profile viewer" scam under the name Social Tagging Worldwide tricks you via the clipboard, not via the usual rogue app.
SSCC 53 - RSA advice, RIM advises on JavaScript and Chrome patches Flash before Adobe
This week's Chet Chat discusses the recent breach of RSA Security, advice from RIM on securing your BlackBerries post Pwn2Own and Google's speedy security updates to their Chrome web browser. Settle in for 10 minutes and keep up on the latest security news,
Large US hosting provider hit in web attack
In this post I take a look into what at first sight appeared to be a widespread web attack, with malicious JavaScript injected into hundreds of legitimate web sites. Closer inspection revealed the attack to be a little less widespread than expected, potentially targeting just a single hosting provider.


















