Re: Browser security was Re: [Full-Disclosure] MDKSA-2004:021 - Updated mozilla packages fix multiple vulnerabilities

From: Nick FitzGerald (nick_at_virus-l.demon.co.uk)
Date: 03/11/04

  • Next message: Jos Osborne: "RE: [Full-Disclosure] Comcast using IPS to protect the Internet from their home user clients?"
    To: full-disclosure@lists.netsys.com
    Date: Thu, 11 Mar 2004 22:17:28 +1300
    
    

    Gary Flynn <flynngn@jmu.edu> wrote:

    <<snip>>
    > What I'd like to see personally is a right-click "temporarily
    > disable/enable risky functionality for this site" option so this
    > functionality can be turned on and off easily for those users
    > willing to put up with the discomfort of day to day web "browsing"
    > without scripts but not willing to put up with having to go
    > through three or more configuration screens for a temporary site
    > visit. ...

    Hear, hear!!

    > ... Yeah, I know, make it too easy and you get the email attachment
    > syndrome but I think the feature would overall encourage more people
    > to try browing in a safer default configuration than today's
    > mechanism. ...

    Or maybe not.

    Regardless though, why make it so fricking difficult for those who _do_
    want to use your browser "safely", rather than with some developer
    amalgam "convenient average" setting?

    > ... You fight human nature and you lose. ...

    8-)

    > ... It could always be
    > disabled by a master switch in an organizational policy. Shoot,
    > even security vendors make use of script on their web pages
    > and I think most of us would have to admit having to go to a site
    > requiring script and forgetting to turn it back off at least
    > once. :)

    Of course, solving more or less the same problem set was the intended
    aim of IE's security zones. The big problem there is MS never went to
    any trouble to make it at all clear to the user what the point was,
    never made it easy to drop a site into the "Trusted Sites" zone and, of
    course (we are talking about Redmond after all), defaulted "world plus
    dog" into the "Internet" zone with laughably pathetic security settings
    so "everything would work out of the box" (especailly all the
    inevitable security exploits) so no-one with less than a truckload of
    clue would ever have any motivation to even _think_ about the very
    important issues underlying it all... (Kinda makes you wonder why they
    even bothered devising the secuirty zones from the outset and
    implementing all the infrastructure thereunder, but I'm sure the
    shipping configuration was yet another win for marketing over technical
    nouse.)

    -- 
    Nick FitzGerald
    Computer Virus Consulting Ltd.
    Ph/FAX: +64 3 3529854
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Jos Osborne: "RE: [Full-Disclosure] Comcast using IPS to protect the Internet from their home user clients?"

    Relevant Pages

    • [UNIX] PHP fopen() Warning Cross-Site Scripting Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... PHP's fopenfunction warning output has been found to inadequately ... PHP's default configuration is to display error output in the browser. ... If your system is running a default PHP configuration, this script will ...
      (Securiteam)
    • SUMMARY WAS: OT? Philosophical Question on SA responsibilities
      ... helpful for managers interested in hiring new administrators. ... Would you go thru the 14,600 messages in root and admin ... If I was a new SA I would if encountering a security hole, ... I can see some use for the passwd -s part of the crontab script, ...
      (SunManagers)
    • Re: Clarification-Win2k Netstat sockets interpretation
      ... snip.. ... Before I could manually download every security upate and servicepack from MS.com but now...they send you a bit of Cop-code that fails to run unless ALL defences are down ... Are you sure the script from ntsvcfg is benign in addition to being useful? ... You are absolutely correct there HAL, er ah, Sebastian. ...
      (alt.computer.security)
    • [NT] Flaw in Windows Script Engine Could Allow Code Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... The Windows Script Engine provides Windows operating systems with the ... blocked by Outlook Express 6.0 and Outlook 2002 in their default ...
      (Securiteam)
    • Re: BUG with RES/SCRIPT/XP-SP2
      ... I consider JavaScript (known to security people as JavaVirus) as one of the Really Top ... to have a bad script cause damage to my machine. ... This security feature is called the "Local Machine Zone Lockdown". ... Tags, and the CDHtmlDialog class in this forum, and got no response. ...
      (microsoft.public.vc.mfc)