Posts

Showing posts from January, 2006

Beware: Yahoo Games - Zuma

Today, I accidentally hit upon Yahoo Games where I saw an offering to download some games, one of them Zuma, is a very addictive and well done bubble shooting game. The Deluxa version of this game was offered for free download and I decided to take the offer. After installing the program successfully, the program did two things that are considered very bad from security perspective: It called home -- the Windows Firewall poped up asking me to allow the program to access the network (which I did not, playing a game locally should not need network access). It immediately crashed. The reason being that my machine has DEP (Data Execution Protection) turned on, preventing programs from changing their code while running. DEP is a relatively new protection again worms and viruses that get in via the network using buffer overflow techniques. Zuma is the first software thus far that triggered DEP exceptions and crashed on my machine. I am not willing to risk the security of my machine so I am n...