Third-Party JavaScript Leads to Malware on Web Sites

Third-Party JavaScript Leads to Malware on Web Sites

Do you know what’s running on your website?

A new report from security firm Dasient concludes that the majority of websites are running third-party JavaScript somewhere on their sites, which could be putting them at risk.

The Dasient report comes ahead of the company’s scheduled talk at the Black Hat security conference this week, where Dasient cofounder Neil Daswani is set to detail the problem and one potential solution.

[login]Dasient’s research demonstrated that the problem of third-party JavaScript usage is widespread. According to Dasient, 75 percent of websites use third-party JavaScript in some form, which represents a potential risk to their security.

Dasient found that the level of third-party JavaScript usage varies somewhat based on the market segment. For instance, 94 percent of high-tech vendors and 89 percent of financial institutions use widgets on their websites that were developed by third parties.

“Businesses need to realize that they are dependent on third parties in order for their sites to be secured and at the same time they don’t have direct control over those third-party resources,” Daswani told InternetNews.com.

Third-party JavaScript can take many different forms, ranging from ad server code to content widgets. The way that the JavaScript code is embedded within a website also varies.

“Third-party widgets either take form of third party JavaScript or third-party iFrames ,” Daswani said. “A few years ago there was trend away from iFrame use, but the reality of the way the Web has evolved is that iFrames have become a regular part of the Web business.”

Daswani believes that functionality has won out over security when it comes to modern website development. The challenge now is about how to mitigate the risk that the usage of third-party JavaScript resources may have on websites.

“The web is all interconnected and the amount of code being used from different places is also interconnected,” Daswani said. “As a result, it’s important for enterprises to mitigate their risk, and not necessarily by eliminating the third-party JavaScript, because that may not be possible from a business perspective.”

One solution to the issue is Dasient’s website malware monitoring service, which first debuted last year. Daswani will be speaking at Black Hat specifically about the architecture of the firm’s Mod anti-malware technology, which aims to help prevent malware infection on websites.

Browser vendors have also tried to help mitigate the risk through a number of different techniques. Multiple browser vendors including, Microsoft and Mozilla, have domain-origin policies for their browsers, which are intended to restrict the ability of third-party scripts to execute functions.

“The same origin and domain security policies that are used by the browser are indeed helpful,” Daswani said. “But there are still some problems.”

For example, Daswani said that if an iFrame is used that is pulling in third-party content, the origin policies would restrict the iFrame content from impacting anything else on the specific page. He added that while origin policies are helpful, if the iFrame were to pull in a malicious PDF that invoked the PDF plugin and triggered a buffer overflow, for instance, the attacker could still take control of the PC.

Other issues that can affect third-party JavaScript usage include the errant disclosure of information disclosure by way of a cross-site scripting (XSS) vulnerability. Daswani noted that in the case of data theft that’s a different threat than malware, which could be served via a third-party JavaScript widget.

“I’d love for Mod anti-malware to solve all the world’s problems, but at the same time I think it’s important to have different categories of defense coming from different places,” Daswani said. “It is important to look at website malware monitoring as part of a defense-in-depth strategy that works with other complementary services.”

Suggested Tags: malware, Dasient, Black Hat, security, JavaScript

devx-admin

devx-admin

Share the Post:
Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security.

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like

Bold Evolution

Intel’s Bold Comeback

Intel, a leading figure in the semiconductor industry, has underperformed in the stock market over the past five years, with shares dropping by 4% as opposed to the 176% return

Semiconductor market

Semiconductor Slump: Rebound on the Horizon

In recent years, the semiconductor sector has faced a slump due to decreasing PC and smartphone sales, especially in 2022 and 2023. Nonetheless, as 2024 approaches, the industry seems to

Elevated Content Deals

Elevate Your Content Creation with Amazing Deals

The latest Tech Deals cater to creators of different levels and budgets, featuring a variety of computer accessories and tools designed specifically for content creation. Enhance your technological setup with

Learn Web Security

An Easy Way to Learn Web Security

The Web Security Academy has recently introduced new educational courses designed to offer a comprehensible and straightforward journey through the intricate realm of web security. These carefully designed learning courses

Military Drones Revolution

Military Drones: New Mobile Command Centers

The Air Force Special Operations Command (AFSOC) is currently working on a pioneering project that aims to transform MQ-9 Reaper drones into mobile command centers to better manage smaller unmanned

Tech Partnership

US and Vietnam: The Next Tech Leaders?

The US and Vietnam have entered into a series of multi-billion-dollar business deals, marking a significant leap forward in their cooperation in vital sectors like artificial intelligence (AI), semiconductors, and

Huge Savings

Score Massive Savings on Portable Gaming

This week in tech bargains, a well-known firm has considerably reduced the price of its portable gaming device, cutting costs by as much as 20 percent, which matches the lowest

Cloudfare Protection

Unbreakable: Cloudflare One Data Protection Suite

Recently, Cloudflare introduced its One Data Protection Suite, an extensive collection of sophisticated security tools designed to protect data in various environments, including web, private, and SaaS applications. The suite

Drone Revolution

Cool Drone Tech Unveiled at London Event

At the DSEI defense event in London, Israeli defense firms exhibited cutting-edge drone technology featuring vertical-takeoff-and-landing (VTOL) abilities while launching two innovative systems that have already been acquired by clients.

2D Semiconductor Revolution

Disrupting Electronics with 2D Semiconductors

The rapid development in electronic devices has created an increasing demand for advanced semiconductors. While silicon has traditionally been the go-to material for such applications, it suffers from certain limitations.

Cisco Growth

Cisco Cuts Jobs To Optimize Growth

Tech giant Cisco Systems Inc. recently unveiled plans to reduce its workforce in two Californian cities, with the goal of optimizing the company’s cost structure. The company has decided to

FAA Authorization

FAA Approves Drone Deliveries

In a significant development for the US drone industry, drone delivery company Zipline has gained Federal Aviation Administration (FAA) authorization, permitting them to operate drones beyond the visual line of

Mortgage Rate Challenges

Prop-Tech Firms Face Mortgage Rate Challenges

The surge in mortgage rates and a subsequent decrease in home buying have presented challenges for prop-tech firms like Divvy Homes, a rent-to-own start-up company. With a previous valuation of

Lighthouse Updates

Microsoft 365 Lighthouse: Powerful Updates

Microsoft has introduced a new update to Microsoft 365 Lighthouse, which includes support for alerts and notifications. This update is designed to give Managed Service Providers (MSPs) increased control and

Website Lock

Mysterious Website Blockage Sparks Concern

Recently, visitors of a well-known resource website encountered a message blocking their access, resulting in disappointment and frustration among its users. While the reason for this limitation remains uncertain, specialists

AI Tool

Unleashing AI Power with Microsoft 365 Copilot

Microsoft has recently unveiled the initial list of Australian clients who will benefit from Microsoft 365 (M365) Copilot through the exclusive invitation-only global Early Access Program. Prominent organizations participating in

Microsoft Egnyte Collaboration

Microsoft and Egnyte Collaboration

Microsoft has revealed a collaboration with Egnyte, a prominent platform for content cooperation and governance, with the goal of improving real-time collaboration features within Microsoft 365 and Microsoft Teams. This

Best Laptops

Top Programming Laptops of 2023

In 2023, many developers prioritize finding the best laptop for programming, whether at home, in the workplace, or on the go. A high-performing, portable, and user-friendly laptop could significantly influence

Renaissance Gaming Magic

AI Unleashes A Gaming Renaissance

In recent times, artificial intelligence has achieved remarkable progress, with resources like ChatGPT becoming more sophisticated and readily available. Pietro Schirano, the design lead at Brex, has explored the capabilities

New Apple Watch

The New Apple Watch Ultra 2 is Awesome

Apple is making waves in the smartwatch market with the introduction of the highly anticipated Apple Watch Ultra 2. This revolutionary device promises exceptional performance, robust design, and a myriad

Truth Unveiling

Unveiling Truths in Bowen’s SMR Controversy

Tony Wood from the Grattan Institute has voiced his concerns over Climate and Energy Minister Chris Bowen’s critique of the Coalition’s support for small modular nuclear reactors (SMRs). Wood points

Avoiding Crisis

Racing to Defy Looming Financial Crisis

Chinese property developer Country Garden is facing a liquidity challenge as it approaches a deadline to pay $15 million in interest associated with an offshore bond. With a 30-day grace

Open-Source Development

Open-Source Software Development is King

The increasingly digital world has led to the emergence of open-source software as a critical factor in modern software development, with more than 70% of the infrastructure, products, and services

Home Savings

Sensational Savings on Smart Home Security

For a limited time only, Amazon is offering massive discounts on a variety of intelligent home devices, including products from its Ring security range. Running until October 2 or while

Apple Unleashed

A Deep Dive into the iPhone 15 Pro Max

Apple recently unveiled its groundbreaking iPhone 15 Pro and iPhone 15 Pro Max models, featuring a revolutionary design, extraordinary display technology, and unrivaled performance. These new models are the first