Showing posts with label javascript. Show all posts
Showing posts with label javascript. Show all posts

Friday, November 09, 2007

Browser Exploit Prevention

NoScript for Firefox.

Experts agree that Firefox is safer with the NoScript Firefox extension, which provides extra protection for Firefox, and other mozilla-based browsers.

This is a free open source addon makes Firefox which allows JavaScript and Java execution only for trusted domains of your choice and made even safer through preemptive whitelist-based JavaScript/Java/Plugins blocking.

You have the option to block Flash and other potentially harmful plugins.

Click for larger image

It offers many useful features which you have complete control over.

Browser based anti-XSS - Cross-Site Scripting vulnerabilities allow someone to insert their own malicious code from one site into another, which can lead to identity theft etc.

You have the ability to enable or disable Java/Javascript for Trusted Sitesusing either the NoScript status bar or the contextual menu.

There is an installation video that is well worth watching before considering deploying this tool.

Watch the video here.

Download NoScript here

http://noscript.net/faq covers general FAQ, installing, uninstalling, migrating, updates, troubleshooting, XSS, tips and tricks

LinkScanner Lite

When you start to install this utility, you have the option to use the full Pro version for 15 days, after this it will revert to the Lite version.

Also on the installation window there is the option to participate in the Community Intelligence Network. This is optional and is explained on the install window.

The installation adds a BHO (Browser Helper Object)which is necessary for the program to function.

After installation it is necessary to reboot your computer.


The Pro version gives you Websearch results inspection, On-demand url scanning, Always-on exploit blocking, Internet connectivity monitor and Real-time site risk analysis. The Lite version will give you Websearch results inspection and On-demand url scanning.

This program analyzes sites in real time to detect a wide range of online threats including malicious content, phishing, social engineering and targeted software exploits.

You have the Link Scanner Console which resides in the Taskbar, simply right click the icon and you can open the Console.

Enter a URL, checkmark the ‘Automatically advance to the page if it is Safe’ and scan.

Exploit Prevention Labs say that LinkScanner Lite and LinkScanner Pro scan individual pages in real time, knowing that malicious hackers can hop from site to site, temporarily infecting them.
LinkScanner integrates with Google, Yahoo and MSN to check the search results and can warn you of exploits, hacked pages, malicious sites and phishing/fraud scams.

Enter a search term into a search engine and the results displayed will have symbols beside them.

Hold your cursor over the icons and a description will appear, click the icon and you will be taken to a definition page giving further information about the site and the reason for the rating.

The simplest method to check any link is to right-click the link and select Quickscan with LinkScanner. You will get a full report as to whether the site is safe or not.

NoScript and LinkScanner also bolster your Firewall defences.

Download LinkScanner Lite here

Comprehensive User Guide here

Tuesday, May 08, 2007

Securing Your Browser

Securing Your Browser
The way that your Web browser is configured provides a
front line to secure Web surfing. Though many of the
security features that relate to your browser are described
in other tutorials, these tutorials step you through a
complete assessment of your browser's security settings.

Important Note:
Make sure you back-up your system or create a Restore
Point before making any changes

Checking IE Connection Types

Step 1: Open Internet Options
Many of the security features of the Internet Explorer
browser can be set from the Internet Options window. To
open the Internet Options window, click on Tools, Internet
Options from the Internet Explorer window.

Step 2: Select Advanced Tab
The different types of secure connections that can be used
with Internet Explorer are configured on the Advanced tab
of the Internet Options window. Click on the Advanced tab,
then scroll down to the Security heading.

Step 3: Check Fortezza Connections
On the Internet Options, Advanced tab, if the Use Fortezza
box is checked it means that Internet Explorer is
configured to allow secure connections to Web sites that
support Fortezza cryptography connections. Fortezza is used
by the U.S. Department of Defense a Fortezza Crypto Card
reader, a Fortezza Crypto Card, and related software
drivers. Needless to say, this is a rather specialized type
of connection, though it doesn't hurt to have it turned on.

Step 4: Check PCT Connections
The Private Communications Technology (PCT) protocol is
developed by Microsoft to provide secure connections to
sites that support that protocol. SSL is much more widely
used than PCT, so there is generally no reason to select
this protocol. Click on the Use PCT 1.0 box if you want to
allow secure PCT connections from Internet Explorer.

Step 5: Check SSL Connections
Because most secure connections on the Web rely on Secure
Socket Layer (SSL) protocols, you should select both Use
SSL 2.0 and Use SSL 3.0 options on the Advanced tab of the
Internet Options window. SSL was a protocol that was
developed by Netscape Communications.

Step 6: Check TLS Connections
The Transport Layer Security protocol is an open standard
that is much like the SSL protocol. To allow connections
using TLS, click on the Use TLS 1.0 button.

Step 7: Apply Changes
After you have selected the secure connection types that
your browser supports, click on the Apply button to have
the changes applied to your browser.

Checking IE Cache Settings

Step 1: Open Internet Options
As you browse the Web, your browser will typically store
the pages you have visited on your hard disk. This can
speed up your browsing by having data ready immediately
when you step backward and forward among the pages you
visit. The potential security risk is that if others are
using your browser they may be able to see the stored
content later. You can clear stored pages by setting an
option on the Internet Options page. From IE, click on
Tools, Internet Options.

Step 2: Select Advanced Tab
Options for deleting stored Web surfing content in
Internet Explorer are configured on the Advanced tab of the
Internet Options window. Click on the Advanced tab, then
scroll down to the Security heading

Step 3: Check Save Encrypted Pages
Presumably, data that has been encrypted during
communication between your browser and a Web site will tend
to be more sensitive. For example, data is encrypted during
online shopping and other financial transactions. To
prevent any encrypted data from being saved to your disk,
select the "Do not save encrypted pages to disk" check box
on the Advanced tab of the Internet Options window.

Step 4: Check Empty Temporary Files
You can have all the Web content that is temporarily
stored on your hard disk be removed when you close your
browser. Click on the "Empty Temporary Internet Files
folder when browser is closed" check box to enable that
feature.

Step 5: Apply Changes
After you have selected the secure connection types that
your browser supports, click on the Apply button to have
the changes applied to your browser.

Setting IE Security Zones

Step 1: Open Internet Options
Internet Explorer allows you to set groups of Web sites to
have similar levels of security. These groups are referred
to as "Web Content Zones." You can set up these content
zones from the Internet Options page. From IE, click on
Tools, Internet Options.

Step 2: Select Security Tab
Options for setting content zones in Internet Explorer are
configured on the Security tab of the Internet Options
window. Click on the Security tab to begin setting these
options.

Step 3: Select Web Content Zone
There are four pre-defined Web content zones: Local
Intranet (for sites within your organization), Trusted
Sites (for sites you know are secure), Restricted sites
(for sites that are not secure) and Internet (for all other
Web sites). Click on one of those sites to set the level
and define the sites for that zone.

Step 4: Select a Security Level
Click on the slider bar on the Security tab to set the
security level for zone you have selected. You can set the
security zone to Low, Medium-low, Medium, or High. Each
level is described when you select that level on the slider
bar. If you try to change to a less secure level than the
default for the zone, you will be warned.

Step 5: Customize Security Level
If you want to fine tune any of the four preset security
levels, you can do so by clicking on the Custom Level
button. The Security Settings window appears. From that
window, you can select how different types of content are
handled (such as ActiveX controls, plug-ins, cookies, file
downloads, Java, etc.) when you try to download or start
that type of content. Click on OK when you are satisfied
with your settings.

Step 6: Apply Changes
Click on the Apply button to apply the changes you made to
the Web content zones.

Enabling Content in Netscape

Step 1: Open Preferences
Some types of content can pose a potential security risk
as you browse the Web. You can allow or disallow certain
types of content from the Netscape Preferences window. To
access this window, click on Edit, Preferences from the
Netscape window.

Step 2: Select Advanced Preferences
From the Preferences window, click on the Advanced title
in the left column. Preferences that relate to the kinds of
content that can be displayed in Netscape and the ways that
cookies may (or may not) be accepted are displayed

Step 3: Allow Java/JavaScript
By default, Java applets (small programs) and JavaScripts
(a series of commands) run in your browser when they are
encountered on the Web. Because these scripts can pose some
small security threat (and can also slow your browser), you
can choose to disallow these types of programs. Click on
the associated check boxes to turn off those features.
(Warning: some Web sites will not work with Java disabled.)

Step 4: Enabling Cookies
Cookies are small files that a Web site stores on your
hard disk so it can identify you (and possibly your
personal information) the next time you visit the site.
Some people dislike Web sites knowing too much about them
and choose to turn cookies off (click on Disable Cookies).
Rather than accept all cookies, however, you can limit a
cookie's use to the originating server or to be warned
before a cookie is accepted. (Warning: some sites won't
work with cookies off.)

Step 5: Applying Changes
Once you have changed the setting the way you want, click
on OK to have the changes take effect.

Setting Netscape Security

Step 1: Open the Security Window
From the Netscape window, you can open a Security Info
window to find security information about the current Web
page. It can also be used to define how Netscape behaves
when it encounters potentially insecure situations. To open
the Security Info window from Netscape, click on the
Security icon in the toolbar (it looks like a small padlock).

Step 2: Verify Web Page Security
When the Security Info page first appears, it tells you
two pieces of information about the current Web page. First
it tells you weather or not the page was encrypted and
second it verifies the Web address of the page you have
opened. To view details about the page, click on the Open
Page Info button.

Step 3: View Page Information
When the Page Info page appears, you can view detailed
security information relating to the current Web page. If
it is a secure Web page, you can see the type of security
that is used with the page and who owns the certificate
that verifies the authenticity of the page. When you are
done viewing this information, close the page by clicking
on the X in the upper right corner of the window.

Step 4: Set Security Warnings
If you are about to enter information about yourself into
a Web site, you probably want to make sure that the site is
secure. From the Security Info page, you can set Netscape
to warn when you enter or leave a secure site, as well as
when you view a page with some encrypted data or send
unencrypted information. (These features are on by
default.) To check these settings, click on Navigator in
the left column, then check how the values are set.

Step 5: Apply Changes
To apply any changes you made to the Security Info page,
click on the OK button.


Add to Technorati Favorites

Monday, April 23, 2007

Securing Your Computer System

Today, more and more people are using their computers for
everything from communication to online banking and
investing to shopping. As we do these things on a more
regular basis, we open ourselves up to potential hackers,
attackers and crackers. While some may be looking to phish
your personal information and identity for resale, others
simply just want to use your computer as a platform from
which to attack other unknowing targets. Below are a few
easy, cost-effective steps you can take to make your
computer more secure.

1. Always make backups of important information and store
in a safe place separate from your computer.

2. Update and patch your operating system, web browser and
software frequently. If you have a Windows operating
system, start by going to www.windowsupdate.microsoft.com
and running the update wizard. This program will help you
find the latest patches for your Windows computer. Also go
to www.officeupdate.microsoft.com to locate possible
patches for your Office programs.

3. Install a firewall. Without a good firewall, viruses,
worms, Trojans, malware and adware can all easily access
your computer from the Internet. Consideration should be
given to the benefits and differences between hardware and
software based firewall programs.

4. Review your browser and email settings for optimum
security. Why should you do this? Active-X and JavaScript
are often used by hackers to plant malicious programs into
your computers. While cookies are relatively harmless in
terms of security concerns, they do still track your
movements on the Internet to build a profile of you. At a
minimum set your security setting for the “internet zone”
to High, and your “trusted sites zone” to Medium Low.

5. Install antivirus software and set for automatic
updates so that you receive the most current versions.

6. Do not open unknown email attachments. It is simply
not enough that you may recognize the address from which it
originates because many viruses can spread from a familiar
address.

7. Do not run programs from unknown origins. Also, do not
send these types of programs to friends and coworkers
because they contain funny or amusing stories or jokes.
They may contain a Trojans horse waiting to infect a
computer.

8. Disable hidden filename extensions. By default, the
Windows operating system is set to “hide file extensions
for known file types”. Disable this option so that file
extensions display in Windows. Some file extensions will,
by default, continue to remain hidden, but you are more
likely to see any unusual file extensions that do not
belong.

9. Turn off your computer and disconnect from the network
when not using the computer. A hacker can not attack your
computer when you are disconnected from the network or the
computer is off.

10. Consider making a boot disk on a floppy disk in case
your computer is damaged or compromised by a malicious
program. Obviously, you need to take this step before you
experience a hostile breach of your system.

To your safety and security online

cotojo

Add to Technorati Favorites

Monday, April 16, 2007

Surfing the Web Anonymously

Surfing the Web Anonymously – Questions to Ask

When you surf the web it is possible to learn information about you
even when you don’t want to advertise who you are. This is true even
if your system contains no virus or malware software. Specifically
information that is easily available online includes your IP address,
your country (and often more location information based on IP
address), what computer system you are on, what browser you use, your
browser history, and other information. It gets worse. People can
get your computer’s name and even find out your name if your machine
supports programs like finger or identd. Also, cookies can track your
habits as you move from machine to machine.

How do people get this basic information about you?

When you visit another web site, information about you can be
retrieved. Basically, information is intercepted and used by others
to track your Internet activities.

How do you stop this from happening?

First of all, it is possible to surf the web anonymously and thereby
stop leaving a trail for others to find. Note that this is not fool-
proof, but it makes it much harder for people to know who you are.
There are products called anonymous proxy servers that help protect
you. The anonymous proxy server replaces your Internet address for
its own. This has the effect of hiding your IP address and making it
much harder for people to track you.

How do I get an anonymous proxy server?

There are many vendors who sell anonymous proxy servers. There are
also free proxy servers available to you. Two such products are
ShadowSurf and Guardster. Guardster (http://www.guardster.com/)
offers various services for anonymous and secure access to the web,
some paid as well as a free service. ShadowSurf
(http://www.shadowsurf.com/) ShadowSurf provides anonymous surfing at
their site for free. Go to it and you will find a box to enter a URL
that you want no one to track. There are many others, but here are
two that are frequently used.

Another interesting product, given the recent news about the Google
search engine filtering its findings for the Chinese government, is
Anonymizer (http://www.anonymizer.com). This company, among others,
recently (Feb 1st, 2006) pressed that it “is developing a new anti-
censorship solution that will enable Chinese citizens to safely
access the entire Internet filter free”
(http://www.anonymyzer.com/consumer/media/press_releases/02012006.html
).

Does an anonymous proxy server make you 100% safe?

No. Still, you are much better off if you use such technology.

What other things should I be concerned about when trying to keep my
private information private?

Three other items come to mind when trying to keep your information
private. First, you can use an encrypted connection to hide your
surfing. This article does not go into detail on this, but search the
web and you will find a lot of information on this. Secondly, delete
cookies after each session. Third, you can configure your browser to
remove JavaScript, Java, and active content. This actually leads to
limitations, so you need to think about the cost/benefit of this
course of action.

Anything else?

Wishing you happy and safe surfing!

Add to Technorati Favorites