Browser Security

Discussion in 'Software' started by Adrynalyne, Aug 1, 2004.

  1. Adrynalyne

    Adrynalyne Guest

    http://bcheck.scanit.be/bcheck/sid-f1fc38e2e6252ba0550a6d85a1de0ecb/

    I've tested the latest version of K-meleon, Firefox, Opera, and IE 6 SP2.

    IE6 failed for me.

    When you run this, make sure you turn off all popup stoppers.

    Enabling the pop blocker allowed IE to pass the test, but IMO, thats a joke.

    IE6sp1 shows the same vulnerability.
     
  2. Adrynalyne

    Adrynalyne Guest

    Technical Details
    "This cross-domain scripting vulnerability allows executing JavaScript code
    in the context of any domain. Combined with other Internet Explorer
    vulnerabilities it allows executing code in Local Computer security zone,
    leading to installation and execution of arbitrary programs.
    First a malicious page creates an IFRAME pointing that redirects to a page
    in the target domain (or Local Computer zone). Then a modal dialog is
    created and the reference to the IFRAME is passed to the dialog in
    dialogArguments parameter of showModalDialog function.
    The modal dialog caches the reference to the IFRAME and waits until IFRAME's
    domain changes due to the redirect. Then the dialog page closes itself and
    returns the cached reference.
    The original page receives the window reference from the modal dialog and
    changes the location of this window to a javascript: URL. The JavaScript
    code gets executed in the context of the domain to which the IFRAME was
    redirected.

    Recommendations
    There is no patch currently available to fix this problem. Updating your
    antivirus software with latest signatures can limit the consequences of a
    successful exploit."
     
  3. billH

    billH Master Sergeant

    Opera seems to do okay.
    The Browser Security Test is finished. Please find the results below:
    High Risk Vulnerabilities 0
    Medium Risk Vulnerabilities 0
    Low Risk Vulnerabilities 0
     
  4. Adrynalyne

    Adrynalyne Guest

    Yeah, Opera was OK for me too. Just not IE.
     
  5. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

    My IE must be safe, it locked up somewhere around the quicktime plugins ;)
     
  6. Adrynalyne

    Adrynalyne Guest

    LOL, that works too :D :D
     
  7. da chicken

    da chicken MajorGeek

    It's not a bug, it's a feature!

    I'm trying IE with Bug Off v1.0 on, and the test dies on test 20/20.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds