[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Apple 2 ebay 3rd party checkout, security risk?
On May 14, 11:42 pm, pau...@saaf.se (Paul Schlyter) wrote:
> In article <1179201989.388738.209...@n59g2000hsh.googlegroups.com>,
>
> John <zzzj...@yahoo.com> wrote:
> >> If you are truly paranoid about your DNS setting getting hacked then
> >> you should get off the internet NOW because you are at a much higher
> >> risk of picking up a virus that targets eBay users by simply browsing
> >> a listing than you are by going through icensed eBay partner's checkout
> >> site.
>
> > How could that be done? Could they embed malicious Javascript code, or
> > something, into an ebay listing page?
>
> There are lots of things they could do indeed....
>
> Otoh there's an easy way to avoid this: DO NOT USE AN ACCOUNT WITH
> ADMINISTRATOR'S RIGHTS UNESS YOU REALLY HAVE TO (e.g. when installing
> new software). And particularly when you're surfing the Web, you
> should *not*, repeat, *not* do that from an account with administrator's
> rights!
>
> That simple rule is obeyed quite well in the Unix world, but it's being
> violated so many times, over and over and over and over again, in the
> Windows world, for two reasons: ignorance and laziness. But those who
> do it due to laziness are really shooting themselves in the foot:
> having to reformat your harddrive and reinstall all your apps twice
> a year or so is a lot of work!
>
> Changing your DNS settings requires administrator's rights in the
> account you're logged into and running your web browser from.
> Modifying system files requires administrator's rights too. If you
> instead log on to an account with more limited User's rights, and if
> you should visit a web page containing malicious code trying to do
> nasty things, the OS will prevent it from doing that. But if you're
> logged on to an account with administrator's rights when that happen,
> the OS will "say" to the malicious code: "So you want to change the
> DNS settings? And modify this critical system file? Fine with me -
> you're an administrator, so go right ahead!" -- and then that
> malicious code you loaded into your computer is allowed to perform its
> evil deed.
>
> You're locking the front door to your house, don't you? You don't allow
> anyone to enter your house and just *hope* they won't do anything nasty,
> right? Likewise, you should lock up your computer a bit more, and not
> allow any unknown code to run with administrator's rights!!! Right?
>
> If you do this, you can continue surfing the Web without being worried
> about malicious code changing your DNS settings, or infecting critical
> system files. Wouldn't that be nice?
>
> --
> ----------------------------------------------------------------
> Paul Schlyter, Grev Turegatan 40, SE-114 38 Stockholm, SWEDEN
> e-mail: pausch at stockholm dot bostream dot se
> WWW: http://stjarnhimlen.se/
Thanks Paul. Good advice and well explained.