Friday, November 09, 2007

Browser Exploit Prevention

NoScript for Firefox.

Experts agree that Firefox is safer with the NoScript Firefox extension, which provides extra protection for Firefox, and other mozilla-based browsers.

This is a free open source addon makes Firefox which allows JavaScript and Java execution only for trusted domains of your choice and made even safer through preemptive whitelist-based JavaScript/Java/Plugins blocking.

You have the option to block Flash and other potentially harmful plugins.

Click for larger image

It offers many useful features which you have complete control over.

Browser based anti-XSS - Cross-Site Scripting vulnerabilities allow someone to insert their own malicious code from one site into another, which can lead to identity theft etc.

You have the ability to enable or disable Java/Javascript for Trusted Sitesusing either the NoScript status bar or the contextual menu.

There is an installation video that is well worth watching before considering deploying this tool.

Watch the video here.

Download NoScript here

http://noscript.net/faq covers general FAQ, installing, uninstalling, migrating, updates, troubleshooting, XSS, tips and tricks

LinkScanner Lite

When you start to install this utility, you have the option to use the full Pro version for 15 days, after this it will revert to the Lite version.

Also on the installation window there is the option to participate in the Community Intelligence Network. This is optional and is explained on the install window.

The installation adds a BHO (Browser Helper Object)which is necessary for the program to function.

After installation it is necessary to reboot your computer.


The Pro version gives you Websearch results inspection, On-demand url scanning, Always-on exploit blocking, Internet connectivity monitor and Real-time site risk analysis. The Lite version will give you Websearch results inspection and On-demand url scanning.

This program analyzes sites in real time to detect a wide range of online threats including malicious content, phishing, social engineering and targeted software exploits.

You have the Link Scanner Console which resides in the Taskbar, simply right click the icon and you can open the Console.

Enter a URL, checkmark the ‘Automatically advance to the page if it is Safe’ and scan.

Exploit Prevention Labs say that LinkScanner Lite and LinkScanner Pro scan individual pages in real time, knowing that malicious hackers can hop from site to site, temporarily infecting them.
LinkScanner integrates with Google, Yahoo and MSN to check the search results and can warn you of exploits, hacked pages, malicious sites and phishing/fraud scams.

Enter a search term into a search engine and the results displayed will have symbols beside them.

Hold your cursor over the icons and a description will appear, click the icon and you will be taken to a definition page giving further information about the site and the reason for the rating.

The simplest method to check any link is to right-click the link and select Quickscan with LinkScanner. You will get a full report as to whether the site is safe or not.

NoScript and LinkScanner also bolster your Firewall defences.

Download LinkScanner Lite here

Comprehensive User Guide here

No comments: