Home > Ask the Security Experts > Application Security Questions & Answers > Are desktop gadgets a target for hackers?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Are desktop gadgets a target for hackers?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 March 2007
What are the security risks associated with desktop gadget and widget applications?

>
Client-side Web applications, such as Yahoo Widgets or Google Gadgets, are currently all the rage. Windows Vista's new sidebar, for example, hosts and supports the use of these mini-applications, suggesting that they will be around for some time.

For anyone who hasn't come across them, they are typically self-contained applications that display information often pulled from a remote source. Gadgets, for example, can report the latest weather and real-time stock prices. Some also display local or system information, including laptop battery levels and "To Do" lists.

Throughout the rest of this article, I shall refer to all varieties as gadgets.

These applications have a runtime environment directly built on a Web browser. They're commonly written in scripting languages such as JavaScript, but they can also be written in languages such as C++. Since widgets are client-side applications, which run on the user's machine and not a remote server, they can have access to system data via application programming interface (API) functions. Many of them also support the XMLHttpRequest object, which allows asynchronous data requests over HTTP. These features make the gadgets more like small desktop programs rather than the more familiar plug-ins and applets.

If you recall, Java applets run in a sandboxed environment, allowing a user to run untrusted code safely, since such conditions impose strict controls on what a program can and cannot do. Gadgets, however, face no such restraints. This means that hackers can disguise gadgets as spyware, which could monitor keystrokes or install other malicious software. Attackers could then capture confidential data and send it to a remote system. Gadgets must be particularly appealing to hackers since their support for JavaScript allows the opportunity for cross-platform attacks.

At this early stage in their evolution, you need to exercise a degree of caution when deciding to install a gadget. As the use of gadgets becomes more widespread, hackers will quickly take advantage of them and use them to attack. I would only install gadgets that you know come from reputable sources or are digitally signed. A digitally signed gadget verifies an author's authenticity.

For system administrators, I would seriously consider whether to allow the use of these gadgets. I haven't yet seen any that provide must-have functionality. Some organizations use them to provide constant updates to employees on enterprise data, such as sales levels or support call waiting times. While this type of gadget certainly offers some benefits, I would want to know whether the gadget displays reliable data, doesn't burden the network and is compliant with e-discovery regulations.

More information:

  • In the new Data Protection Security School, Perry Carpenter explains which e-disovery and storage processes are often overlooked.
  • With so many vulnerabilities in client-side applications, it's important to keep an eye on RSS readers as well. Ed Skoudis explains.


  • BROWSE BY TAG
    Application Security,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Application Security,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Application Security
    Do Facebook URL security concerns justify blocking social networks?
    Is there a way to block iPhone widgets that bypass Web filters?
    Should enterprises be concerned with Twitter in the workplace?
    Are there still Google Desktop security problems?
    Can an IP spoofing tool be used to spam SPF servers?
    Will an application usage policy best control network bandwidth?
    How can URL-shortening services be manipulated?
    Is my security program ready for Web application firewall deployment?
    How to ensure the security of a shopping cart application
    When to use the service features of the Metasploit hacking tool

    Web Application Security
    Preventing SQL injection attacks: A network admin's perspective
    Cisco acquires SaaS security vendor ScanSafe
    Web application firewall use goes beyond compliance, company finds
    Gumblar Trojan drive-by exploits spike following Adobe update
    Some Facebook applications lead to Russian attack sites
    Barracuda acquires Purewire expanding Web security reach
    An enterprise strategy for Web application security threats
    Scanning with N-Stalker offers basic Web application security assessment
    Attackers target PDF, DirectShow flaws with malicious banner ads
    New Bahama botnet evades search engines, fuels click fraud

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    anonymous Web surfing  (SearchSecurity.com)
    buffer overflow  (SearchSecurity.com)
    cache cramming  (SearchSecurity.com)
    cookie poisoning  (SearchSecurity.com)
    dictionary attack  (SearchSecurity.com)
    distributed denial-of-service attack  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    National Computer Security Center  (SearchSecurity.com)
    threat modeling  (SearchSecurity.com)
    trigraph  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts