[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Apple 2 ebay 3rd party checkout, security risk?



In article <1179201989.388738.209720@n59g2000hsh.googlegroups.com>,
John  <zzzjoki@yahoo.com> wrote:

>> If you are truly paranoid about your DNS setting getting hacked then
>> you should get off the internet NOW because you are at a much higher
>> risk of picking up a virus that targets eBay users by simply browsing
>> a listing than you are by going through icensed eBay partner's checkout
>> site.
>
> How could that be done? Could they embed malicious Javascript code, or
> something, into an ebay listing page?

There are lots of things they could do indeed....


Otoh there's an easy way to avoid this: DO NOT USE AN ACCOUNT WITH
ADMINISTRATOR'S RIGHTS UNESS YOU REALLY HAVE TO (e.g. when installing
new software).  And particularly when you're surfing the Web, you
should *not*, repeat, *not* do that from an account with administrator's
rights!

That simple rule is obeyed quite well in the Unix world, but it's being
violated so many times, over and over and over and over again, in the
Windows world, for two reasons: ignorance and laziness.  But those who
do it due to laziness are really shooting themselves in the foot:
having to reformat your harddrive and reinstall all your apps twice
a year or so is a lot of work!

Changing your DNS settings requires administrator's rights in the
account you're logged into and running your web browser from.
Modifying system files requires administrator's rights too.  If you
instead log on to an account with more limited User's rights, and if
you should visit a web page containing malicious code trying to do
nasty things, the OS will prevent it from doing that.  But if you're
logged on to an account with administrator's rights when that happen,
the OS will "say" to the malicious code: "So you want to change the
DNS settings?  And modify this critical system file?  Fine with me -
you're an administrator, so go right ahead!" -- and then that
malicious code you loaded into your computer is allowed to perform its
evil deed.

You're locking the front door to your house, don't you?  You don't allow
anyone to enter your house and just *hope* they won't do anything nasty,
right?  Likewise, you should lock up your computer a bit more, and not
allow any unknown code to run with administrator's rights!!!   Right?

If you do this, you can continue surfing the Web without being worried
about malicious code changing your DNS settings, or infecting critical
system files.  Wouldn't that be nice?

-- 
----------------------------------------------------------------
Paul Schlyter,  Grev Turegatan 40,  SE-114 38 Stockholm,  SWEDEN
e-mail:  pausch at stockholm dot bostream dot se
WWW:     http://stjarnhimlen.se/