The Register® — Biting the hand that feeds IT

McAfee spies malware in legit JavaScript apps

Anonymous Coward

Sandbox 

allegedly a safe place to play ... ahah ... the Java crap is to be blamed, not McAfee. Sandbox without a proper tarp end up filled with cat pooh. Can't blame McAfee trying to pick one pooh too many.

Morely Dotes

Please! 

Alert

Do not confuse Java with Javascript. The only evident relationship between the two is the four letters in "java."

I'm not entirely certain that anything calling Friendster "malware" is incorrect, however. It seems to me to be a bit less dangerous than a bio-engineered version of anthrax, and a bit more malicious than a kiss from your auntie; somewhere in between, but leaning towards anthrax.

David Eddleman

Sandbox... 

Is not always effective. Do you know just how much software they'd need to test? Many different versions of Java, Flash, etc. -- and that's just counting the "popular" software.

Glenn

SCREAMING SCRIPT 

Dead Vulture

javaSCRIPT is unrelated to java and never gets into the (cat-turded) sandbox.

Anonymous Coward

No such thing as heuristic detection 

and they copy each others signatures.