Mechanism which will enable users to quickly and easily update our software. The cause of this lies in the fact that they were intended and created at the time when the problem of security just did not occur. And even so called "update services" were not intended to allow millions of users to protect themselves against a threat. It just happened that most of the discovered errors concern security. Trying to eliminate this defect users have to use 3 rd party software anti-viruses, firewalls and anti-spyware. Installation of such software can produce a fake impression of security. The user must remember that this means of protection is not a magic wand but software, just like the OS. It also can contain errors and be weak. The author of these reports shows critical vulnerabilities, by using which a malicious program can not only block the work of anti-virus software but also perform malicious code at the user computer. Designing Arovax Shield we have face a technical problem which, if solved in a wrong way, could cause vulnerabilities in our product. Our research has shown that many producers either don't pay notice to this problem at all or use a very insecure variant. It’s enough to run the program with the "/u" key. And these producers claim that one of the key features of their software is perfect real-time protection. Just imagine, any malicious program can simply execute the command superantispyware.exe /u and then do whatever it wants. Due to active investigations of security tools' own security and discovering vulnerabilities in them many manufacturers create their own "update services" for their products.



Reply With Quote
Copyright Techfuels
Bookmarks