john-heasman

A picture may be worth a thousand logins

Alaska Miller · 08/04/08 04:40PM

Hackers will reveal a new way to steal user accounts with pictures later this week, at the Black Hat security conference in Las Vegas. The method uses hybrid files that are read as photos by some programs and as code by others These hybrid files can have code, such as Java, embedded in them, and then be uploaded to websites such as Facebook, MySpace, or eBay where they can skirt security measures to do harm.