Author Topic: Then check DOM inside your browser..  (Read 8992 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Then check DOM inside your browser..
« on: May 13, 2010, 10:29:08 PM »
Hi malware fighters,

Check DOM issues: http://lcamtuf.coredump.cx/dom_checker/

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Then check DOM inside your browser..
« Reply #1 on: May 14, 2010, 12:47:14 AM »
Opera = Failed checks: 60
IE8    = Failed checks: 39
« Last Edit: May 14, 2010, 12:49:26 AM by Pondus »

YoKenny

  • Guest
Re: Then check DOM inside your browser..
« Reply #2 on: May 14, 2010, 03:38:07 AM »
The sky is falling said Chicken Little.

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Then check DOM inside your browser..
« Reply #3 on: May 14, 2010, 03:47:58 AM »
Had to get rid of all firefox security add-ons (NoScript, RequestPolicy) to get it to even work ;)

Then only 14 errors (image1), though I did get a warning displayed (image2) during the test, haven't a clue what it is ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Dch48

  • Guest
Re: Then check DOM inside your browser..
« Reply #4 on: May 14, 2010, 03:59:00 AM »
40 failed checks in IE8 but guess what---I'm not worried.

PapaSmurf

  • Guest
Re: Then check DOM inside your browser..
« Reply #5 on: May 14, 2010, 05:16:14 AM »
The only time this works is if I allow it to by turning off my firefox addons.
So, since I do not use internet explody...I guess I am good :)

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Then check DOM inside your browser..
« Reply #6 on: May 14, 2010, 12:37:09 PM »
Thanks but no thanks. I don't have java.

Scott's cool. 8)

nmb

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Then check DOM inside your browser..
« Reply #7 on: May 14, 2010, 02:58:53 PM »
It doesn't use JAVA to run the test, but requires javascript, entirely different.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Then check DOM inside your browser..
« Reply #8 on: May 14, 2010, 03:40:03 PM »
Hi DavidR,

There were 43 security issues with Browzar used on XP SP3
to mention a few here:
CHECK FAILED : open() frame name lookup is possible!
CHECK FAILED : for (e in (third-party)) iterator is possible!
CHECK FAILED : (third-party).frames[0] probe [value: [object]] is possible!
CHECK FAILED : (third-party).frames.length read [value: 2] is possible!
CHECK FAILED : for (e in (third-party).frames) iterator is possible!
CHECK FAILED : (third-party).onresize write (readback) is possible!
CHECK FAILED : (third-party).onhashchange write (readback) is possible!
CHECK FAILED : (blank).onunload write (readback) is possible!
CHECK FAILED : (blank).onafterprint write (readback) is possible!

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Then check DOM inside your browser..
« Reply #9 on: May 14, 2010, 03:45:20 PM »
It doesn't use JAVA to run the test, but requires javascript, entirely different.

Are you sure, sir? It asks me to install java (firefox)

nmb

spg SCOTT

  • Guest
Re: Then check DOM inside your browser..
« Reply #10 on: May 14, 2010, 03:50:08 PM »
I got the error too David,

I win this game (firefox):
Quote
Failed checks: 459
Oh wait, that's not right is it?  ;D

It doesn't use JAVA to run the test, but requires javascript, entirely different.

Are you sure, sir? It asks me to install java (firefox)

nmb

I didn't get asked this... ???

-Scott-

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Then check DOM inside your browser..
« Reply #11 on: May 14, 2010, 03:57:15 PM »
Hi scott,

I mean this (see pic) : when I visit the site, it asks me to install jre. Which i dont want to.

spg SCOTT

  • Guest
Re: Then check DOM inside your browser..
« Reply #12 on: May 14, 2010, 04:04:50 PM »
Hi nmb,

I see what you mean now...

Initially I didn't allow the two iframes at the bottom in NS, so I didn't see this...It is the iframe that points here:

hXXp://213.134.128.25/lcamtuf/dom_target_page.html

When you allow this, the install plugins thing pops up...at which point I say no... :)

-Scott-




Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89032
  • No support PMs thanks
Re: Then check DOM inside your browser..
« Reply #13 on: May 14, 2010, 04:22:12 PM »
When JAVA is running you should see the JAVA icon in the system tray.

The iframe tags are used to retrieve the data of the tests into the actual page and iframe is blocked by the Firefox, Options, Embeddings Forbid iframe if you checked this option, like I have.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

spg SCOTT

  • Guest
Re: Then check DOM inside your browser..
« Reply #14 on: May 14, 2010, 04:24:49 PM »
When JAVA is running you should see the JAVA icon in the system tray.
Java can't run on my system, it asks to install...

Quote
The iframe tags are used to retrieve the data of the tests into the actual page and iframe is blocked by the Firefox, Options, Embeddings Forbid iframe if you checked this option, like I have.

Maybe that is why mine failed so horribly...but then IE doesn't have any trouble without JAVA...I don't know...
I do have that setting checked in NS...