Follow us on RSS or Twitter for the latest updates.

December 14, 2012

Microsoft Confirms Internet Explorer Security Flaw that allows Hackers Track Mouse Moves


Microsoft is investigating a possible flaw in its Internet Explorer Web browser that allegedly enables attackers to track users' mouse cursor anywhere on the screen, even if the browser window isn't in use.

The alleged flaw, which security firm Spider.io says it discovered a few months ago, compromises the security of virtual keyboards and virtual keypads in all supported versions of the browser since IE6, the security firm reports.

"As long as the page with the exploitative advertiser's ad stays open -- even if you push the page to a background tab or, indeed, even if you minimize Internet Explorer -- your mouse cursor can be tracked across your entire display," the security firm said in a statement.

Even the security-conscious are at risk of having their cursor movements recorded, Spider.io warned. "An attacker can get access to your mouse movements simply by buying a display ad slot on any Web page you visit," the security firm warned, adding that any site from YouTube to The New York Times would be a possible attack vector due to ad exchange activity.

At least two display ad analytics companies are exploiting the suspected vulnerability (see video below demonstrating the issue) to see what people are looking at online, Spider.io said.

The security researcher said it informed Microsoft of the issue on October 1 but that the software giant doesn't appear to be in a hurry to patch the vulnerability.
"Whilst the Microsoft Security Research Center has acknowledged the vulnerability in Internet Explorer, they have also stated that there are no immediate plans to patch this vulnerability in existing versions of the browser," the firm said in a statement. "It is important for users of Internet Explorer to be made aware of this vulnerability and its implications."
Microsoft appeared to downplay the issue, blaming competition between analytics companies.
"From what we know now, the underlying issue has more to do with competition between analytics companies than consumer safety or privacy," Dean Hachamovitch, VP of Internet Explorer, said in a company blog post this afternoon.

"We are actively working to adjust this behavior in IE," he wrote, adding that there are similar capabilities in other browsers. He promised to update the blog when more information becomes available.

Author: dfgdfg,

April 5, 2012

Speed your browser by changing your DNS


Most people use the default DNS settings provided by their ISP, and while they are usually sufficient for most purposes, there are plenty of free options out there, like OpenDNS and Google DNS. Namebench is a free app that checks to see whether your current settings are optimized and, if not, which free option is best for you. Here's how to use it:

Download and install Namebench.

Fire it up and choose your settings. Keep the top two boxes checked. If you're concerned about network censorship, check the third box, and if you want to help the developers, check the last box. You can tweak the rest if you're outside U.S. or want to experiment with different browsers.

NameBench Dns

Click Start Benchmark and wait while Namebench runs its tests. It should take several minutes. A browser tab should pop open when Namebench is done and give you a list of DNS servers and how much faster they are than the one you're currently using, unless yours are already the fastest possible.

Namebench does not change your settings, but it's generally pretty easy to do it yourself. Check with the instructions you got from your ISP to set up your modem and/or router and just substitute the DNS addresses you received from Namebench for the addresses given by your ISP. It's best to do this with your router, as it will assign that DNS address for all the devices attached to it.

That's it! This can dramatically improve your browsing speed, and it's fairly easy to work through.

Author: dfgdfg,

Categories: , , ,

January 6, 2012

Researchers discovers keylogging threats in Mozilla


Firefox-wallpaper.jpg
Security researcher Mario Heiderich reported to the maker of Firefox last year that he had found an unusual vulnerability in the browser and two other Mozilla products that run on the Gecko engine, Thunderbird, and SeaMonkey. Based in the relatively new technology that allows for animated complex vector graphics in the browser, called SVG animation, the vulnerability allowed for a malware writer to detect key strokes even when JavaScript was disabled.

Basically, he found a way to turn innocuous Web pages into keyloggers. Mozilla patched the vulnerability in Firefox 9, Thunderbird 9, and SeaMonkey 2.6. Then, as is standard operating procedure, they announced to the public what the threat was and that it had been fixed. But the real threat may lie in what the threat wasn't: it wasn't based in JavaScript.

"The basic premise of my research currently is scriptless attacks, meaning attack vectors working in a post-XSS world," Heiderich said in an e-mail. He defined a "post-XSS" world as one where the cross-site scripting attack had been more or less minimized by technologies like sandboxed iFrames, Mozilla's e-mail client Thunderbird and Firefox's Content Security Policy, the JavaScript blocking browser add-on NoScript, and Windows 8.

"The desired goal was to do keystroke logging in the browser, doing so without necessitating JavaScript, so even if you turned off JavaScript it would work," said Jeremiah Grossman, Chief Technical Officer at computer security research firm White Hat Security. "All the browser developers are fixing cross-site scripting. What half a dozen researchers are exploring is what you can do attack-wise in a browser without JavaScript. They're discovering that there's still quite a lot you can do in the browser."
This particular SVG keylogging attack was quite nasty, said Chris Eng, vice president of research at Veracode, a computer security research firm. "The way [it] works is that [the bad guy] binds the letter "a" to an action that causes the browser to sliently issue a request for http://evil.com/?a. Pressing "b" would trigger the browser to silently issue a request for http://evil.com/?b. By "silently" I mean that there's no visual cues to the user that anything is happening--if you were monitoring the network you would see the requests. As long as the attacker controls evil.com and can access the web server logs, he can piece together what the victim is typing, one character at a time."

Eng noted that this kind of problem always erupts whenever new standards are rolled out, especially with "extremely detailed and sometimes difficult to understand" attributes. You don't have to go far to find evidence of this, either. Both Mozilla and Google offer hefty bounties for bug-hunters. Eng both cautioned against screaming that the sky was falling and said that this kind of attack was inherently more interesting to researchers.

As unlikely as Eng said it is for an average browser user to fall victim to these atypical but hard to implement attacks, Heiderich warned that it's not anomalous. "The SVG keylogger is just one example of many, and by far not the most impact ridden one," said Heiderich.

Another factor is that the major browser makers, including Google, Mozilla, Microsoft, Apple, and Opera, are all fairly responsive to fixing these threat vectors when discovered, said Grossman. But that doesn't mean that there aren't steps for the home user to take.
One way to minimize the risk from this kind of modern threat is to compartmentalize your risk, he said. "The best way [to protect yourself] is behavior, not product. Whether in Firefox, IE, or Chrome, I would use any one of the major browsers for secure browsing, such as banking or Facebook. For promiscuous browsing, such as news surfing, I use a different browser.

Eng concurred and said that there aren't many defenses against attacks that don't rely on JavaScript. "You usually have to just wait for the browser bugs to be fixed. So my options are more limited--either don't use that browser at all, use a completely separate browser for trusted sites versus untrusted ones, [or] stay off the Internet."

Author: dfgdfg,

August 17, 2011

Mozilla Releases Firefox 6 for Coders


firefox
Mozilla has officially released Firefox 6, offering a new JavaScript editor and several other tools aimed at web developers.

Over the weekend, the open source outfit posted the latest stable version of Firefox to its FTP servers, but the browser wasn't formally released on the web until Tuesday.

Firefox 6 is the second incarnation of the browser released under Mozilla's new quarterly development cycle. Previously, the organization rolled out a new Firefox every eighteen months or so, but then Google upped the ante.

With the latest version, Mozilla says, it has improved the startup time of Panorma, a means of organizing your browser tabs, and it has tweaked the "Awesome Bar" – the Firefox address bar – to make it easier to identify exactly where you are on the web. But the biggest changes are for developers.

Mozilla has added a text editor called Scratchpad that lets developers enter, execute, test, and tweak JavaScript code. The idea to offer an alternative to Firefox's Web Console or the Firebug command line, which are designed around a single-line interface. "Interaction with Scratchpad is quite different. It throws away the 'one line of input gives you a line of output' interaction in favor of a text editor that knows how to run JavaScript," Mozilla says.

But if you prefer the Web Console, Mozilla has updated it as well, improving the auto-complete tool and letting you change where the console is located. In the past, the console was anchored to the top of the browser window, but you can now move it to the bottom or open it in a separate window.

The open source outfit has also added a "Window.matchMedia" API to help developers optimize their site or web app across disparate platforms, and "Prefixed WebSockets" and "server-sent event" APIs, designed to facilitate communication between Firefox and back-end web servers.

Packed with all sorts of additional security and bug fixes, Firefox is available for Windows, Mac, and Linux. You can download it here.

Mozilla also released a new version of Firefox for Android on Tuesday, adding a new welcome screen designed to provide quicker access to various tools, working to improve image rendering, and rolling in a few tools for those building mobile web apps. This includes a "single touch events" API, for detecting screen touches and gestures, and IndexedDB API, which provides local database storage for apps that need to work offline.

The new Firefox for Android is now available from Google's Android Market.

Author: dfgdfg,

June 17, 2011

Google Chrome 13 Gets More Experimental Features


Google Chrome 13
Google has just released Google Chrome 13 to the dev channel and it has a lot of new features which include a working version of Multiple Profile switcher, experimental new tab page and tab grouping. Additionally, Google Chrome 13 also adds a new feature called Compact Navigation and the ability to restrict Google Instant to search.

The new development version also adds an option to enable the Web Audio API and an option to allow "Background Apps" to continue running even when Chrome is shut down.

Background Apps are Google Chrome Apps  which provide users with functionality that quietly runs in the background without intrusion. Background Apps could be apps that regularly check your email or Twitter account and notify you of new updates. The new feature in Google Chrome 13 will allow apps to continue running.

The new "Background Apps" feature is enabled by default, you can disable it by going to "Options -> Under The Hood" and deselect the checkbox next to "Continue running background apps when Google Chrome is closed".

Google Chrome 13 also features a working version of the profile switcher which allows users to use different profiles for different Chrome windows. This will allow users to work with different profiles without having to keep logging in and out. Google Chrome 13 also has the latest Flash player – Version 10.3.181.14.

Google has been working on the experimental new tab page for a while and it looks like things are finally taking shape in Google Chrome 13. When you enable the feature from about:flags, you will see a new tab page which now lists most visited sites and apps in tabs. It also has additional tabs but they don’t have any content. The new tab feature could allow users to create customizable tabs where they can list out different apps, however, there is no option to customize them right now.

Google Chrome 13 also has an option to hide the toolbar which can be done by right click on a tab an selecting "Hide the toolbar" from the menu options. Using this option hides the Omnibox and extension icons. I would prefer to have a keyboard shortcut to enable and disable this feature.  You will need to visit the about:flags page and enable the "Compact Navigation" feature to get this option.

Finally, Google Chrome 13 also adds a new option to restrict Google Instant to only searches. Prior to that, Google Instant would kick in even when you load any webpage. This could get annoying and a feature to disable it is a great addition. You will have to enable this feature in about:flags too.

Overall, it looks like Google Chrome 13 is shaping out really well. Some of the features like multiple profiles and new tab page are really exciting. Hopefully, these changes should hit the beta and stable channels soon.

Author: dfgdfg,

June 13, 2011

Firefox 5 Gets Faster Connections, Up Next: Memory Improvements


Firefox 5 is a week away from being released as a final version. The browser is expected to be released as final on June 21. When you look at the changelog you will notice quite a few under the hood improvements that have not been talked about yet. HTTP Transactions sorted by CWND is one of those features. Most users probably wouldn’t associate a faster browser with that feature in particular, but the explanation on the Bugzilla site might change that.

What really distinguishes different connections to the same server is the size of the sending congestion window (CWND) on the server. If the window is large enough to support the next response document then it can all be transferred (by definition) in 1 RTT.
It basically means that Firefox may load resources faster if connection handling and priorities are changed.
I’ve done an experiment to show the best case – a link to a 25KB resource off of a page that contains a mixture of small and large content. In both cases the 25KB resource is loaded with an idle persistent connection. In the historic case it reuses a connection that had loaded a small image previously and it takes 3RTT (793ms) to transfer it.. in the case of sorting by cwnd the window is large enough to accommodate the entire resource and it is all complete in 1 RTT (363ms). Cool!
Even better, the worst case scenario is the status quo of Firefox 4. Users who are interested in a longer, more technical explanation, can visit the Bitsup blog for a taste of that.

Firefox 4 transfer


Firefox 5 transfer


The guys over at HTTPWatch have tested the new feature and found the “the performance benefit [to be] substantial”.

In other news: Firefox has a bad reputation for excessive memory usage, and related to this slow downs especially on startup or when closing the browser window. While that is certainly not the perception of all Firefox users, many perceive Firefox as a browser that uses to much memory.

The MemShrink project aims to optimize Firefox’s memory consumption. The developers list speed, stability and perception as the three core benefits of optimizing the memory usage of the Mozilla Firefox web browser.

The project members will analyze memory leak reports and prioritize them based on numbers of affected users and their default priority.

The developers have created a new website called Are We Slim Yet which tracks the process of cutting down on Firefox’s memory usage.

If things go forward as planned, we might see considerable memory footprint reductions in coming versions of the browser.

Author: dfgdfg,