Cuidado al instalar fuentes desde el navegador

in #spanish7 years ago (edited)

Mucho cuidado si una web os pide instalar fuentes tipográficas desde el navegador, es posible que las fuentes incluyan código malicioso ejecutable.

Por ejemplo se está dando el caso de la fuente "Roboto Condensed", que está dirigida a usuarios de Chrome y de Firefox (eso no significa que otros navegadores sean más seguros, yo no tocaría el MSIE ni con un palo). Una vez descargada y ejecutada la supuesta fuente, se pueden instalar distintos malwares dependiendo de qué versión del malware hayas ejecutado, puede ser un minero de criptomonedas, algo que convierta tu ordenador en un bot de spam, un troyano que vea lo que haces en el ordenador, incluyendo las contraseñas, etc.

Cualquier web puede tener un malware de este u otro tipo, un atacante puede haber modificado una web legítima incluyendo el malware sin que el dueño de la web se entere (pasó hace poco en la web del colegio de mis hijos), por lo que no hay que fiarse ni siquiera de webs de confianza.

Yo siempre recomiendo trabajar con máquinas virtuales, con VMWare Player, VirtualBox o similar se pueden crear varias máquinas virtuales, una para guardar las criptomonedas (y en la que no hagas absolutamente nada más), otra para navegar por las webs de los bancos, otra para navegar por webs inseguras, etc. Al mantenerlas separadas, una web maliciosa no podría tener acceso a los monederos. Además es sencillo hacer y restaurar copias de seguridad.

Más información sobre el Roboto Condensed: https://malwarebreakdown.com/2017/08/30/roboto-condensed-social-engineering-attack-targets-both-chrome-and-firefox-users-various-payloads-being-delivered/

https://malwarebreakdown.com/2017/08/30/roboto-condensed-social-engineering-attack-targets-both-chrome-and-firefox-users-various-payloads-being-delivered/
Fuente de la imágen: https://malwarebreakdown.com/2017/08/30/roboto-condensed-social-engineering-attack-targets-both-chrome-and-firefox-users-various-payloads-being-delivered/

Sort:  

This post has been ranked within the top 50 most undervalued posts in the second half of Sep 12. We estimate that this post is undervalued by $23.85 as compared to a scenario in which every voter had an equal say.

See the full rankings and details in The Daily Tribune: Sep 12 - Part II. You can also read about some of our methodology, data analysis and technical details in our initial post.

If you are the author and would prefer not to receive these comments, simply reply "Stop" to this comment.

The @OriginalWorks bot has determined this post by @criptorafa to be original material and upvoted it!

ezgif.com-resize.gif

To call @OriginalWorks, simply reply to any post with @originalworks or !originalworks in your message!

To nominate this post for the daily RESTEEM contest, upvote this comment! The user with the most upvotes on their @OriginalWorks comment will win!

For more information, Click Here!

Congratulations @criptorafa! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

Award for the number of upvotes received

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

This post has received a 45.00 % upvote from @lovejuice thanks to: @criptorafa. They have officially sprayed their dank amps all over your post rewards. GOOD TIMES! Vote for Aggroed!

Este Post ha recibido un Upvote desde la cuenta del King: @dineroconopcion, El cual es un Grupo de Soporte mantenido por 5 personas mas que quieren ayudarte a llegar hacer un Top Autor En Steemit sin tener que invertir en Steem Power. Te Gustaria Ser Parte De Este Projecto?

This Post has been Upvote from the King's Account: @dineroconopcion, It's a Support Group by 5 other people that want to help you be a Top Steemit Author without having to invest into Steem Power. Would You Like To Be Part of this Project?

This post recieved an upvote from minnowpond. If you would like to recieve upvotes from minnowpond on all your posts, simply FOLLOW @minnowpond

This post has received a 29.90 % upvote from thanks to: @criptorafa.
For more information, click here!

This post has received a 1.71 % upvote from @booster thanks to: @criptorafa.

This post has received a 23.95 % upvote from @buildawhale thanks to: @criptorafa. Send 0.100 or more SBD to @buildawhale with a post link in the memo field to bid on the next vote.

To support our curation initiative, please vote on my owner, @themarkymark, as a Steem Witness

Coin Marketplace

STEEM 0.26
TRX 0.11
JST 0.033
BTC 64359.90
ETH 3105.50
USDT 1.00
SBD 3.87