Malware and web pages

Hello, computer science student here. Been learning a bit about security. From what I understand, malware needs to be installed on a computer to be of any harm. I have asked some people and they have told me that because malware needs to be installed, visiting a website does not generally install malware. So I asked them why are people afraid of clicking links to google web search results? And someone said that it is because when you visit a website, your browser will download a local copy of it, and it is in this copy of the website that malware can be put into your computer.

Is any of this right? Am I missing some important details?

tl;dr

Can someone put a malicious program in the file of the web page that your web browser downloads when you visit a web page? And does this file need to be installed or anything to activate the malware?

submitted by /u/MeesterMoo74
[link] [comments]

from hacking: security in practice https://ift.tt/MiqKVOR

Comments