Author Topic: Start panicking, got this link!  (Read 4626 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Start panicking, got this link!
« on: May 08, 2009, 11:18:32 PM »
Hi malware fighters,

Got this link from NoScript's Giorgio Maone: http://startpanic.com/
What obfuscated script can do, well like to hear your comments?

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Start panicking, got this link!
« Reply #1 on: May 08, 2009, 11:25:10 PM »
No problem here, Firefox and NoScript ;D

Seriously I don't waste much time worrying about any of this stuff, there is little point.

Ensure you have a robust back-up and recovery strategy (plus a few pro-active measures) and you can laugh in the face of adversity ;D

If you fail to plan, then you plan to fail.
If you have a back-up and recovery plan, you can recover from anything in minutes, not hours or days.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

CharleyO

  • Guest
Re: Start panicking, got this link!
« Reply #2 on: May 08, 2009, 11:29:47 PM »
***

Interesting ... I've been to hundreds of sites in the last few days yet the list only had 5; one of which was startpanic. Of the 4 others, 2 of them I had not been to in more than a week.

OK ... so, those 4 sites I need to be more careful with and I need to check the source codes.


***

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Start panicking, got this link!
« Reply #3 on: May 08, 2009, 11:41:20 PM »
Well, if you visit this site in GoogleChrome, you easily can get up to 40 sites visited, in Fx with NoScript none,

pol
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Start panicking, got this link!
« Reply #4 on: May 08, 2009, 11:42:39 PM »
I enabled the site to see what it gathered (previously zero), same here only show the last 5 (different domains), which I presume is the intention or the scan could take ages, it took some time just to gather that.

I don't believe it has nothing to do with the sites you visit, but your browser storing browser history. Firefox also has the infamous Amazing address bar, that tries to save you having to type all the URL but to give predictive options based on sites you have visited (presumably from your bookmarks). This information, I dare say could also along with browser history be retrieved, personally I don't give a stuff who knows where I have been :P
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33900
  • malware fighter
Re: Start panicking, got this link!
« Reply #5 on: May 09, 2009, 12:06:24 AM »
Hi DavidR,

Well NoScript can protect partially against this POC fully when performed with javascript and there is also a slower version via a CSS hack where one need not use javascript, but the real true protection against this is SafeHistory or StartPrivateBrowsing, so Ctrl + Shft + P that I have inside Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1b5pre) Gecko/20090508 Shiretoko/3.5b5pre ID:20090508043756
So one can imagine how secure some online proxies were (they were not),
In Mozilla this is at the crux of it:
http://doxygen.db48x.net/mozilla-full/html/d5/dc9/interfacensIContentViewer.html
But they are already working on a patch - and there is the above mentioned solution for users of Fx,

polonus
« Last Edit: May 09, 2009, 12:18:01 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

John2009

  • Guest
Re: Start panicking, got this link!
« Reply #6 on: May 09, 2009, 12:36:17 AM »
Im confused, what does this do?

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89058
  • No support PMs thanks
Re: Start panicking, got this link!
« Reply #7 on: May 09, 2009, 01:05:37 AM »
IMHO, nothing to start panicking about ;D

Whilst this example is about privacy, it is possible to do more than simply see what a users browsing habits are.

So measures to protect you from harm are more important than any privacy concerns.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

lee16

  • Guest
Re: Start panicking, got this link!
« Reply #8 on: May 09, 2009, 10:19:31 PM »
Although i agree everyone should have security on there PC (and a backup) there is such a thing as to much security (it simply bloats up and slows the PC).
FUD sites create money, simple as that.

--lee

Offline Dwarden

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1793
  • Ideas, that's ocean without borders!
    • Bohemia Interactive
Re: Start panicking, got this link!
« Reply #9 on: May 10, 2009, 05:19:02 PM »
i rofled when i checked with IE8 ... it obviously shows all sites in like last 1-3 days history
https://twitter.com/FoltynD , Tech. Community, Online Services & Distribution manager of Bohemia Interactive

drhayden1

  • Guest
Re: Start panicking, got this link!
« Reply #10 on: May 10, 2009, 08:58:44 PM »
Quote
nothing to start panicking about
Never have-just practice safe browsing habits and such ;)
Firefox 3.0.10 showed 7 sites :o
« Last Edit: May 11, 2009, 03:10:59 AM by drhayden1 »

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Start panicking, got this link!
« Reply #11 on: May 10, 2009, 09:50:11 PM »
With IE8 on Windows 7 with InPrivate filtering on by default- 4

With InPrivate browsing-0
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline .: Mac :.

  • Avast Überevangelist
  • Ultra Poster
  • *****
  • Posts: 5093
Re: Start panicking, got this link!
« Reply #12 on: May 10, 2009, 11:56:44 PM »
Firefox 3.0.10 showed 4 sites. Safari 4.0 beta crashed within 15 seconds.
"People who are really serious about software should make their own hardware." - Alan Kay