Author Topic: How many failed in your browser?  (Read 7579 times)

0 Members and 1 Guest are viewing this topic.

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67235
Re: How many failed in your browser?
« Reply #15 on: August 29, 2010, 09:18:53 PM »
Polonus, can you explain to us? Thanks.
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33486
  • malware fighter
Re: How many failed in your browser?
« Reply #16 on: August 29, 2010, 09:52:08 PM »
Hi Tech,

This is a test for vulnerabilities that can be explored in a browser or with a browser or are design related and it could be very hard to explore these. As the developers of the scan say:
Quote
all common browsers fail anywhere from 10 to 30 of less significant tests due to various design decisions (most of which bear some privacy considerations by making it to fingerprint simultaneously open pages).  
So 14 as with Flock is a very reasonable number. There always could be some danger when a malcreant can run their own code in a browser or on a browser site. The attack is carried out on the data loaded in the browser's DOM. For this reason, it is highly advisable to make sure you don't have more than one window open when using a website of a confidential in nature. Re for such an exploit: http://blog.stevepoland.com/exploit-knowing-the-websites-your-visitors-visit/
Fuzzers can be used to find abusable exploits: http://browserfun.blogspot.com/
Know that as DavidR also said in this thread that the NoScript extensions makes this a non-issue because it fully protects. A general issue for various browsers (patched for Fx and Flock): http://www.g-sec.lu/crash/select.html

polonus
« Last Edit: August 29, 2010, 10:00:26 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67235
Re: How many failed in your browser?
« Reply #17 on: August 29, 2010, 10:03:20 PM »
The attack is carried out on the data loaded in the browser's DOM. For this reason, it is highly advisable to make sure you don't have more than one window open when using a website of a confidential in nature.
Do you mean it could be dangerous to be running in more than one tab? Or just another IE window?
Confidential is banking here?
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33486
  • malware fighter
Re: How many failed in your browser?
« Reply #18 on: August 29, 2010, 11:34:48 PM »
Hi Tech,

Just as I tell it, with NoScript installed no sweat. On a banking site yes, only one window open in any browser to execute what you have to do there for optimal safety. In Chrome this could be different because every tab/window open is handled as a separate process. I think eventually all browsers will have that for security reasons,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67235
Re: How many failed in your browser?
« Reply #19 on: August 29, 2010, 11:37:14 PM »
Thanks Polonus. I'll stop using IE while banking. Sometimes I have some issues with Firefox + NoScript.
The best things in life are free.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33486
  • malware fighter
Re: How many failed in your browser?
« Reply #20 on: August 29, 2010, 11:45:02 PM »
Hi Tech,

Join us at the one and only NoScript forum run by the extension's developer, Giorgio Maone, and we certainly can help to solve these issues: http://noscript.net/forum
My nick there is "luntrus",

Damian
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline jadinolf

  • Avast Evangelist
  • Advanced Poster
  • ***
  • Posts: 1090
Re: How many failed in your browser?
« Reply #21 on: August 30, 2010, 01:54:19 AM »
There is soooo much that we must know that it's getting scary. ::)
printed on 100% recycled bytes

Offline Lisandro

  • Avast team
  • Certainly Bot
  • *
  • Posts: 67235
Re: How many failed in your browser?
« Reply #22 on: August 30, 2010, 03:03:02 AM »
Hi Tech,

Join us at the one and only NoScript forum run by the extension's developer, Giorgio Maone, and we certainly can help to solve these issues: http://noscript.net/forum
My nick there is "luntrus",

Damian
Thanks for the offer. I need to consider other forum... When I enter one I do not leave ;D
The best things in life are free.

YoKenny

  • Guest
Re: How many failed in your browser?
« Reply #23 on: August 30, 2010, 12:41:52 PM »
Hi Tech,

Just as I tell it, with NoScript installed no sweat. On a banking site yes, only one window open in any browser to execute what you have to do there for optimal safety. In Chrome this could be different because every tab/window open is handled as a separate process. I think eventually all browsers will have that for security reasons,

polonus
IE8 opens every tab in a new process.

Enhanced tabbed browsing
http://www.microsoft.com/windows/internet-explorer/features/easier.aspx