Author Topic: Vulnerability - Oscars awarded (Pwine 2010)  (Read 5745 times)

0 Members and 1 Guest are viewing this topic.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Vulnerability - Oscars awarded (Pwine 2010)
« on: July 30, 2010, 12:09:52 PM »
The Pwine Awards 2010...
http://pwnies.com/winners/
asyn
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #1 on: July 30, 2010, 12:16:11 PM »
That one is rather funny...!! ;D
Go here for further info: http://p42.us/ie8xss/
asyn


Pwnie for Most Epic FAIL

Sometimes giving 110% just makes your FAIL that much more epic. And what use would the Internet be if it wasn't there to document this FAIL for all time?

This award is to honor a person or company's spectacularly epic FAIL.

- Microsoft Internet Explorer 8 XSS filter

Internet Explorer 8 was released with built in cross-site scripting filters which, for nearly a year after release, enabled cross-site scripting on otherwise secure sites. Ironic. Epic. Fail.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #2 on: July 30, 2010, 02:16:06 PM »
What is Epic FAIL ???
I've heard of an Epic Failure ???
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #3 on: July 30, 2010, 11:23:43 PM »
Hi bob3160,

We can discuss if it was related to the verb fail (epic fail moment), because Microsoft failed and because the results were ironically miserable, the IE8 XSS-filter made that secure sites that were not vulnerable before the filter became vulnerable through implementing the filter, and that was the epic part to grant the award. And it was a MS failure also because the intention was good but the end result was miserable, so they got the award both for an epic fail on an XSS filter that was a failure,
by the way the XSS filter of NS has not been beaten and firekeeper is also a very reasonable filter in this respect,

polonus

Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Dch48

  • Guest
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #4 on: August 01, 2010, 12:40:21 AM »
Hi bob3160,

We can discuss if it was related to the verb fail (epic fail moment), because Microsoft failed and because the results were ironically miserable, the IE8 XSS-filter made that secure sites that were not vulnerable before the filter became vulnerable through implementing the filter, and that was the epic part to grant the award. And it was a MS failure also because the intention was good but the end result was miserable, so they got the award both for an epic fail on an XSS filter that was a failure,
by the way the XSS filter of NS has not been beaten and firekeeper is also a very reasonable filter in this respect,

polonus


I don't see where the end result was "miserable" the article clearly states that the filter was effective in the great majority of instances and that the exploits were rare. It is also a fact that this problem has been resolved.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #5 on: August 01, 2010, 01:05:08 AM »
Hi Dch48,

I cannot see why else MS got the award, certainly not because they did a particular good job there. And it is patched, but I said above it was a fail moment. But we should keep MS on the ball else they lean back and think of other issues than security related ones, and you also get situations you want to avoid like official recommendations from UK government officials that they will not dump IE6 because of software compatibility issues and  tax-payer cost-effectiveness. I rather would start to do this now as when it becomes inevitable then they will have really serious problems arising, that will create greater costs to the taxpayer then hanging in with a less-secure IE6. Well there are folks in that country there that still taking their Fortran course to keep official software going, stemming way back from before the days of Windows NT4 when I did the official MS admin training "together with the kernel" round the days of the change of the Millennium, (so I am MS trained)

polonus
« Last Edit: August 01, 2010, 01:07:09 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Dch48

  • Guest
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #6 on: August 01, 2010, 02:30:03 AM »
Keeping IE6 is ridiculous as well as training people in Fortran but cost effectiveness is a factor. I just always take criticisms of MS and other industry leaders like Symantec with a large dose of salt because of the "Bring down the big guy" syndrome. I completely trust anything by either MS or Symantec and will use them over other offerings if possible and cost effective. Norton is no longer cost effective for me but it's still a fine product. The only MS product I have ever tried and had problems with was MSE. I'm sure they will get it ironed out though.

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #7 on: August 01, 2010, 05:02:35 AM »
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #8 on: August 01, 2010, 11:10:13 AM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48567
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #9 on: August 01, 2010, 05:19:25 PM »
Quote
I completely trust anything by either MS or Symantec
Unfortunately trusting anything created and controlled by humans, will sooner or later result in disappointment.  :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #10 on: August 01, 2010, 10:08:15 PM »
+1
and most time that's why we contribute to these forums, to help alleviate the disappointments
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33904
  • malware fighter
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #11 on: August 01, 2010, 10:29:56 PM »
Hi mkis,

But sometimes it can also be turned into the opposite of what you say, and I for instance also like to add to a user's feeling of satisfaction, software can also bring joy and sometimes do the little extra beyond what you expect of it,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline mkis

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1618
Re: Vulnerability - Oscars awarded (Pwine 2010)
« Reply #12 on: August 01, 2010, 11:54:05 PM »
 :)
Avast7 Free, MBAM (on demand), MVPS Hosts

Intel DG41TY, Windows 7 Ultimate, IE9, Google Chrome, 4 GB ram, Secunia PSI, ccleaner, Foxit Reader, Faststone Image viewer, MWSnap.