Re: How many personal firewalls in a system?



Don Kelloway <usenet@xxxxxxxxxxxx> wrote:
http://secunia.com/product/11/#advisories

19 unpatched and 10 only partially patched advisories are in Secunia's
list. Among them are advisories regarding Phishing, writing arbitrary
files on user's hard disk, spoofing dialog boxes, FTP command injection
and Mail relaying, spoofing content of other Windows in other websites,
trick users to download malicious files, compromize users system (only
partially fixed since 2004-07-13!), cross-side scripting ("This makes it
possible for script code in a frame associated with one domain to
interact with certain events like keystrokes typed in a frame associated
with a different domain", that means: do not use Internet Exploder for
Internet Banking or the other window will listen YOUR pin), exploring
your system, executing arbitrary scripting code (only partially fixed
since 2003-06-17!).

And where were you last week when I explained that all of the above
insecurities can be mitigated if IE has been configured appropriately?

For example, you could switch off ActiveScripting and ActiveX. Then you
have a browser, which not only is totally unusable (no JavaScript, no
AJAX based sites, no Flash, ...), but also infamous for letting attacks
come true in spite of having switched off the feature, like with
switched off ActiveX and in spite of this fact the exploit with
"scripting safe" COM objects.

Really great.

There are people, who want to use their browser. And they want this for
using web sites. Surprised? Of course, if you don't want to use most of
the common web sites securely, then you may use Internet Exploder. If you
trust in a browser, which repeatedly had security problems with features,
which were switched off, of course.

I think, your own postings here show, that you're not trusting in
Internet Explorer, too:

| The good thing about MS Antispyware is that it prevents
| malware from being installed; it pops up a huge red box warning you and also
| allows you to see any browser "helpers" that have been or are trying to be
| installed.

If you're trusting in your browser, you don't need such features.

Yours,
VB.
--
At first there was the word. And the word was Content-type: text/plain
.



Relevant Pages

  • Re: CONVERTED PAGE to 2007 and now title image is blurry!
    ... And no...don't switch, even the way the links would be written ... good luck and thanks again for posting back. ... As a result of your advice I have also decided not to use Publisher 2007 ... then it will enjoy good cross browser compatibility with ...
    (microsoft.public.publisher.webdesign)
  • OT: MS evil empire
    ... The only browser that does not support scalar vector graphics is ... internet exploder. ... the full gasket set for his model bike, plus I had a new set of STD ...
    (rec.motorcycles.dirt)
  • Re: [Full-Disclosure] (IE/SCOB) Switching Software Because of Bugs: Some Facts About Software and Se
    ... I have told many people to switch to something, ... I often recommend Mozilla. ... factors other than a true assessment of security of the software ... everything under the sun within their web browser. ...
    (Full-Disclosure)
  • Re: Help with long term network problem
    ... Are all Ethernet connections made to the switch, ... All connections Ethernet were via switch. ... Services and found that the browser had stopped. ... Let's see what happens when you connect the computers to the router. ...
    (microsoft.public.windowsxp.network_web)
  • Re: Browser Compatibilities
    ... there are too few that don't switch to consider. ... It is not so much a matter of compatibility between browsers, ... DOM implements which feature, maybe originating in another DOM, to what ... Anyone who slaps a 'this page is best viewed with Browser X' label on ...
    (comp.lang.javascript)