republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Uniqs:
4295
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
page: 1 · 2 · 3
AuthorAll Replies

DSHIELD

join:2006-05-27
Micmac, NS

Browser Security Test

»webtest.scanit.be/bcheck/index.php


dadkins
Can you do Blu?
Premium,MVM
join:2003-09-26
Hercules, CA
kudos:18

Click for full size
As usual...


poppster
Tell the truth and then run.
Premium
join:2003-12-23
Midwest
kudos:1

reply to DSHIELD

Click for full size
Opera 9.10


cocothebean
You Are My Nightmare
Premium
join:2002-11-16
Carson City, NV

reply to DSHIELD
Can't believe that site is still around!!!



poppster
Tell the truth and then run.
Premium
join:2003-12-23
Midwest
kudos:1

1 edit

said by cocothebean:

Can't believe that site is still around!!!
I've never heard of it, which doesn't mean anything...

Is it an old site, whose results are meaningless?
--
What else would you do?
--
There is hope!


cocothebean
You Are My Nightmare
Premium
join:2002-11-16
Carson City, NV

said by poppster:

said by cocothebean:

Can't believe that site is still around!!!
I've never heard of it, which doesn't mean anything...

Is it an old site, whose results are meaningless?
I'm sure they keep it updated.
Its just that I haven't seen it in a few years.


poppster
Tell the truth and then run.
Premium
join:2003-12-23
Midwest
kudos:1

I see.....I guess I don't get out much!



ABL1

join:2005-12-20

reply to DSHIELD

Click for full size
IE7 came up clean also.


Qorum

@uu.net

reply to DSHIELD

High Risk Vulnerabilities
Internet Explorer Modal Dialog Argument Caching Cross-Domain Scripting Vulnerability (jel20040607)
Description
This bug allows a malicious web page to execute any programs on your computer. A malicious hacker can take complete control over your computer using this bug. The bug can be exploited by a web page you browse or HTML email mesage you open.

This bug was discovered "in the wild" and is used by malicious web sites to install adware on visitors' computers.

Technical Details
This cross-domain scripting vulnerability allows executing JavaScript code in the context of any domain. Combined with other Internet Explorer vulnerabilities it allows executing code in Local Computer security zone, leading to installation and execution of arbitrary programs.

First a malicious page creates an IFRAME pointing that redirects to a page in the target domain (or Local Computer zone). Then a modal dialog is created and the reference to the IFRAME is passed to the dialog in dialogArguments parameter of showModalDialog function.

The modal dialog caches the reference to the IFRAME and waits until IFRAME's domain changes due to the redirect. Then the dialog page closes itself and returns the cached reference.

The original page receives the window reference from the modal dialog and changes the location of this window to a javascript: URL. The JavaScript code gets executed in the context of the domain to which the IFRAME was redirected.


Disabled IFrame. It's all good now.


ABL1

join:2005-12-20

That was on version 7? My version 7 is on default settings and passed.



Qorum

@uu.net

said by ABL1:

That was on version 7? My version 7 is on default settings and passed.
Yup...IE7. Is default IFrame set to prompt?


Qorum

@uu.net

reply to ABL1
I think the reason a IFrame vulnerablity was returned is because I selected 'Okay' in stead of closing the prompt dialogue box.

I'll run the test later and check it out.


Mele20
Premium
join:2001-06-05
Hilo, HI
kudos:4

reply to cocothebean
Considering that the results page makes a big thing of pointing out that the test does not test for WMF...I'd say this isn't kept up very well. It is a VERY old test.

Fx 2.0 passed.

Fx 1.5.0.9 has renamed itself. It announces that is version 1.9. The test site says it has never heard of this version of Fx and cannot test it. LOL
--
"If you want to do DRM on a PC then you need to treat the user as the enemy." Ross Anderson in "`Trusted Computing' Frequently Asked Questions"

»www.msfirefox.com/



MarkAW
Barry White
Premium
join:2001-08-27
Canada
kudos:16

1 edit

reply to DSHIELD

Click for full size
Click for full size
Locked down IE6
Nothing New.


nakedland

join:2002-05-18
Friday Harbor, WA

reply to Qorum
Mine was good except Iframe. You said you disabled, how does one do that? What is the purpose of Iframe and what conflickts would disabling cause, if any? Thank you
--
"My son defends our freedom in the USAF"



jaykaykay
4 Ever Young
Premium,MVM
join:2000-04-13
Scottsdale, AZ
kudos:19
Reviews:
·Speakeasy

1 edit

reply to DSHIELD

Click for full size
It's been a long time since I have seen this one. Just for the heck of it, ran it since I had nothing to loose. Interestingly enough, it did set off my Zone Alarm Suite with 2 "error" readings.


magicjimmy

join:2006-03-23
Tucson, AZ

reply to DSHIELD

Click for full size
IE7 Fully Patched - Default Settings


AB
Premium
join:2006-04-04
Leesburg, VA
kudos:3
Reviews:
·Verizon Online DSL

reply to nakedland

said by nakedland:

Mine was good except Iframe. You said you disabled, how does one do that? What is the purpose of Iframe and what conflickts would disabling cause, if any? Thank you
DSLR uses IFrames sometimes. I suspect disabling it would give you less functionality on this site, among others. It's a browser function that has been used for security exploits at times.
Your choices are in Control Panel - Internet Options - Security - Zones.


Buddel
If it ain't broke, don't fix it.
Premium
join:2004-03-06
EU
kudos:3

reply to DSHIELD

Click for full size
IE 6 - the browser you can trust!


AB
Premium
join:2006-04-04
Leesburg, VA
kudos:3
Reviews:
·Verizon Online DSL

said by Buddel:

IE 6 - the browser you can trust!
What's curious about this is one must enable javascripting (a security issue) in order to take the test.
So, in essence, by merely being able to be tested, one is not fully secure.
I'd love to see a vulnerability listed there- "javascripting is enabled."

Saturday, 11-Feb 18:50:40 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 12.5 years online! © 1999-2012 dslreports.com.
Most commented news this week
Hot Topics