[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Apple 2 ebay 3rd party checkout, security risk?



On May 14, 11:42 pm, pau...@saaf.se (Paul Schlyter) wrote:
> In article <1179201989.388738.209...@n59g2000hsh.googlegroups.com>,
>
> John  <zzzj...@yahoo.com> wrote:
> >> If you are truly paranoid about your DNS setting getting hacked then
> >> you should get off the internet NOW because you are at a much higher
> >> risk of picking up a virus that targets eBay users by simply browsing
> >> a listing than you are by going through icensed eBay partner's checkout
> >> site.
>
> > How could that be done? Could they embed malicious Javascript code, or
> > something, into an ebay listing page?
>
> There are lots of things they could do indeed....
>
> Otoh there's an easy way to avoid this: DO NOT USE AN ACCOUNT WITH
> ADMINISTRATOR'S RIGHTS UNESS YOU REALLY HAVE TO (e.g. when installing
> new software).  And particularly when you're surfing the Web, you
> should *not*, repeat, *not* do that from an account with administrator's
> rights!
>
> That simple rule is obeyed quite well in the Unix world, but it's being
> violated so many times, over and over and over and over again, in the
> Windows world, for two reasons: ignorance and laziness.  But those who
> do it due to laziness are really shooting themselves in the foot:
> having to reformat your harddrive and reinstall all your apps twice
> a year or so is a lot of work!
>
> Changing your DNS settings requires administrator's rights in the
> account you're logged into and running your web browser from.
> Modifying system files requires administrator's rights too.  If you
> instead log on to an account with more limited User's rights, and if
> you should visit a web page containing malicious code trying to do
> nasty things, the OS will prevent it from doing that.  But if you're
> logged on to an account with administrator's rights when that happen,
> the OS will "say" to the malicious code: "So you want to change the
> DNS settings?  And modify this critical system file?  Fine with me -
> you're an administrator, so go right ahead!" -- and then that
> malicious code you loaded into your computer is allowed to perform its
> evil deed.
>
> You're locking the front door to your house, don't you?  You don't allow
> anyone to enter your house and just *hope* they won't do anything nasty,
> right?  Likewise, you should lock up your computer a bit more, and not
> allow any unknown code to run with administrator's rights!!!   Right?
>
> If you do this, you can continue surfing the Web without being worried
> about malicious code changing your DNS settings, or infecting critical
> system files.  Wouldn't that be nice?
>
> --
> ----------------------------------------------------------------
> Paul Schlyter,  Grev Turegatan 40,  SE-114 38 Stockholm,  SWEDEN
> e-mail:  pausch at stockholm dot bostream dot se
> WWW:    http://stjarnhimlen.se/


Thanks Paul. Good advice and well explained.