|
There are two types of codec-style exploits:
The one that microsoft mentions, which uses either a malformed wmv file or similar, which is a true security exploit, and the "you need a codec" sites that are using pure social engineering to get installed.
The social engineering approach is the hardest one to stop, because human nature is "install stuff to see video". It is the same reason why people foolishly install things like Zango. They think they are going to see a video or play a game. They don't realize that they will be installing a spyware piece of shit that is going to pop shit all over their screens when they surf. If they knew that, they would never do it.
The only reasons any of this stuff works is because programs are willing to pay money for the traffic generated from it. Pure economics says that if nobody was paying, nobody would do it.
Then again, Zango forced Lars to do it. I wonder how many other people have been forced?
|