Register and remove the ads

Go Back   Windows Vista Forum | Vista Babble > Windows Vista > Vista Security

Reply
 
LinkBack Thread Tools Display Modes
  #1  
Old 02-15-2007, 11:21 PM
Znod's Avatar
Super Moderator
 
Join Date: Jul 2006
Location: Phoenix AZ
Posts: 3,136
Znod is on a distinguished road
Uh Oh: Browsers Again

Well, here is the latest that I know of on browser vulnerabilities: http://blogs.zdnet.com/security/?p=37&tag=nl.e589. The news in not good, but, still, it is pretty much same ole same ole in a way. I tried the vulnerablilty test for the first flaw mentioned. I passed. Here is the message I got:

"Below should be a copy of your C:\BOOT.INI file. If nothing is
shown, chances are you don't have this file in the first place,
your account has no permission to read that file, you didn't use
a vulnerable browser, or I screwed something up.

=== RECEIVED DATA ==="

Maybe my key-logger defeating keyboard really works.

I did not do so well on the second test. And, I like the concept of No Script, but don't like using it. It seems to get in the way too much. Here are my second-test results:

"Firefox location.hostname vulnerability demo (stage 2)

YOUR BROWSER IS VULNERABLE

The page at *.dione.cc successfully set a test cookie for *.coredump.cx. This means that your authentication cookies can be messed with, and that malicious third party sites might be able to gain influence over how unrelated sites are displayed.

You can confirm the presence of a test cookie by going to Tools -> Options -> Privacy -> Show cookies..., and locating an entry for coredump.cx domain. To protect yourself until patches are available, consider using a NoScript plugin. An interim workaround suggested by Firefox developers is to go to about:config, right-click to add a new string key:

capability.policy.default.Location.hostname.set

...and then to set its value to 'noAccess'.

Comments and questions: Michal Zalewski <lcamtuf@coredump.cx> "

And, yep, the cookie was there.
__________________
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Register and remove the ads

All times are GMT +1. The time now is 04:26 PM.



Page generated in 0.14155 seconds with 9 queries

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23