Results 1 to 8 of 8

Thread: JavaScript opens doors to browser-based attacks

  1. #1
    infoseeker's Avatar

    Fear me!!! PLEASSSSEEE..

    Join Date
    Feb 2006
    Location
    Lanang Candaba Pampanga Philippines
    Posts
    568

    JavaScript opens doors to browser-based attacks

    as another way of hacking.......

    Security researchers have found a way to use JavaScript to map a home or corporate network and attack connected servers or devices, such as routers or printers.

    The malicious JavaScript can be embedded in a Web page and will run without warning when the page is viewed in any ordinary browser, the researchers said. It will bypass security measures such as a firewall because it runs through the user's browser, they said.

    "We have discovered a technique to scan a network, fingerprint all the Web-enabled devices found and send attacks or commands to those devices," said Billy Hoffman, lead engineer at Web security specialist SPI Dynamics. "This technique can scan networks protected behind firewalls such as corporate networks."
    READ HERE
    suck utorrent/bittorrent

  2. #2

    Resident Goth

    Join Date
    Sep 2004
    Location
    Central US
    Posts
    142
    Quote Originally Posted by infoseeker
    Security researchers have found a way to use JavaScript to map a home or corporate network and attack connected servers or devices, such as routers or printers.

    The malicious JavaScript can be embedded in a Web page and will run without warning when the page is viewed in any ordinary browser, the researchers said. It will bypass security measures such as a firewall because it runs through the user's browser, they said.

    "We have discovered a technique to scan a network, fingerprint all the Web-enabled devices found and send attacks or commands to those devices," said Billy Hoffman, lead engineer at Web security specialist SPI Dynamics. "This technique can scan networks protected behind firewalls such as corporate networks."
    READ HERE
    You don't say..... How long did it take them to "Research" this? I don't mean to sound rude, but i have seen this happen and I have a few friends that know how to do these things. JavaScript has been around for a long time. It seems that all these software developers keep not only opening, but CREATING doors for attackers to come in. It kinda dissappoints me to hear how vulnerable you can be with most software.

    heh....but it does not surprise me.....lol
    «¤SðréVèXéФ» 490

    Faithful WinMX User

    I shall forever be in the service of rebels.

    Government is just another way to say: "Better than you." Don't let them control you.

    "At the same moment that two people sat down around a fire in the forest, there was another out there who felt better in the dark." - Andrew Wachess

  3. #3
    black_magiic's Avatar

    Zeropaid Noob

    Join Date
    Aug 2003
    Location
    Coolsville
    Posts
    2,344
    that's why using the no-script firefox extension is a good idea

  4. #4

    Resident Goth

    Join Date
    Sep 2004
    Location
    Central US
    Posts
    142
    another fine example fo solid programing id say. i use firefox on linux for home computer usage. i just dont like taking un-nesisary risks.

    (bad spelling)
    «¤SðréVèXéФ» 490

    Faithful WinMX User

    I shall forever be in the service of rebels.

    Government is just another way to say: "Better than you." Don't let them control you.

    "At the same moment that two people sat down around a fire in the forest, there was another out there who felt better in the dark." - Andrew Wachess

  5. #5
    Boomer The Dog's Avatar

    Anthropomorphic

    Join Date
    Jun 2005
    Location
    Pittsburgh PA
    Posts
    539
    I have Firefox with NoScript on it too. Almost every site works woof without scripts, but sometimes submit buttons won't activate without scripts on. If I really need it, like to order something, I just turn scripts on for that session.

    The biggest problem is when friends come over to use my computer. They seem to brilliantly find every site that will break because of no Javascript, and I have to keep apologizing for my poor computer!

  6. #6
    phalkon30's Avatar

    Jay Leno Geek

    Join Date
    Nov 2002
    Location
    Lacrosse, Wi.
    Posts
    4,214
    I know the feeling, I use the Proxomitron for web filtering. It works on almost every site I visit, except when friends use it and I have to bypass it for them.
    Help save lives by doing cancer research! Click here to see the Zeropaid.com UD member page. Please take a few minutes to sign up for our UD cancer research program, it uses idle cpu cycles to help fight cancer by helping to find new drugs. This thread has more info, or you can PM me with questions/comments. I hope to finish the guide on how to start using UD soon

  7. #7
    Boomer The Dog's Avatar

    Anthropomorphic

    Join Date
    Jun 2005
    Location
    Pittsburgh PA
    Posts
    539
    I also have Proxomitron, Naoko 4.5, and I was using it for filtering before I had Firefox, mainly for pop-ups, which used to be such a menace on the net, and I wasn't having fun surfing because of them.

    A friend comes over and wants to check Paypal or something, it's like, 'See that little green triangle, click it and bypass all filters.'

    Well you know that Prox supports different configs, so we could set one up with only light filtering, called 'Friends.cfg'

  8. #8
    phalkon30's Avatar

    Jay Leno Geek

    Join Date
    Nov 2002
    Location
    Lacrosse, Wi.
    Posts
    4,214
    I don't think I'd ever bother switching configs when a friend sits down (and I don't do multiple user accounts). I usually just add sites to the bypass.txt file, it still removes the ads, but leaves the main site alone for the most part.
    Help save lives by doing cancer research! Click here to see the Zeropaid.com UD member page. Please take a few minutes to sign up for our UD cancer research program, it uses idle cpu cycles to help fight cancer by helping to find new drugs. This thread has more info, or you can PM me with questions/comments. I hope to finish the guide on how to start using UD soon

Similar Threads

  1. Browser Speed Comparisons
    By g-smooth2k in forum General Computing
    Replies: 47
    Last Post: July 7th, 2005, 07:38 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •