Schneier on Security's Journal
 
[Most Recent Entries] [Calendar View]

Friday, August 15th, 2025

    Time Event
    1:18p
    Trojans Embedded in .svg Files

    Porn sites are hiding code in .svg files:

    Unpacking the attack took work because much of the JavaScript in the .svg images was heavily obscured using a custom version of “JSFuck,” a technique that uses only a handful of character types to encode JavaScript into a camouflaged wall of text.

    Once decoded, the script causes the browser to download a chain of additional obfuscated JavaScript. The final payload, a known malicious script called Trojan.JS.Likejack, induces the browser to like a specified Facebook post as long as a user has their account open.

    “This Trojan, also written in Javascript, silently clicks a ‘Like’ button for a Facebook page without the user’s knowledge or consent, in this case the adult posts we found above,” Malwarebytes researcher Pieter Arntz wrote. “The user will have to be logged in on Facebook for this to work, but we know many people keep Facebook open for easy access.”

    This isn’t a new trick. We’ve seen Trojaned .svg files before.

    11:33p
    Friday Squid Blogging: Squid-Shaped UFO Spotted Over Texas

    Here’s the story. The commenters on X (formerly Twitter) are unimpressed.

    As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.

    Blog moderation policy.

    << Previous Day 2025/08/15
    [Calendar]
    Next Day >>

Schneier on Security   About LJ.Rossia.org