![]() |
|
#1
|
|||
|
|||
|
Dror Shalev and I have built a browser test page, and am looking to roll this out as a consumer browser test page. The target audience is non-technical users. This was a challenge because what's technically cool is boring to non-techies. And what's cool to non-techies is lame to techies. But before I roll it out and apply a few updates, I want to get feedback from this knowlegeable group.
The animation needs updating (waiting on my consultant for that), so the test doesn't do as much as the animation displays. There are currently five checks which the test performs:
The scan is located here: http://www.greenborder.com/scan The engine of the scan are javascript and wscript run in an .hta, any HIDS should protect the system against files launched from a browser. Please let me what you think. Thanks, Bill |
|
#2
|
|||
|
|||
|
Hello,
I guess this is directed at IE users? Mrk
__________________
http://www.dedoimedo.com All your base are belong to us Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA |
|
#3
|
||||
|
||||
|
Quote:
FF does nothing ( get text file with code visible)with scripts allowed or not IE trys to dl the same file heh: not idiot proof enough for me ![]() or is that a "pass" by mistake?
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#4
|
||||
|
||||
|
Quote:
from the link Bill@Greenborder placed above: Quote:
Bubba |
|
#5
|
||||
|
||||
|
Test seems fine to me Bill. Of course using GreenBorder I passed
![]() Thanks, Chris |
|
#6
|
|||
|
|||
|
Good feedback guys.
At one time I had the start button grayed out until the checkmark was selected, but our web gui guys wanted an image there. I'll have to talk to them about that. |
|
#7
|
|||
|
|||
|
Just for info.I ran the test 4 times without making any changes to my browser settings. Each time I failed the Spying on Keystrokes and twice I failed the Stealing Files. Even when it reckoned I had passed the Stealing Files, the Stolen Files folder appeared on my desktop. So I failed but it said I had passed.
|
|
#8
|
||||
|
||||
|
All I do when I run the test is see the source code. This is with opera 9, nothing disabled. Same thing happens on both linux and windows. So it is definately too mild here(--edit---my bad, I didn't notice it was for IE only, sorry)
Cheers, Alphalutra1 Last edited by Alphalutra1 : October 18th, 2006 at 04:06 PM. Reason: Revealing Revelations |
|
#9
|
||||
|
||||
|
Very interesting.
IE passed all (running, as always, under DropMyRights). Failed ALL except "Steal Passwords" running w/o DMR. So it's true what they say about running browsers with Admin privileges! Thanx Bill |
|
#10
|
||||
|
||||
|
Just one little 'bug' Bill. If you do not select the tick box
Quote:
and click on the green 'start' button, after the warning appears which reminds one to check the box, this box diasappears: http://www.greenborder.com/scan/scannerIdle.gif To get it back you have to refresh the page. This is on IE6 fully patched. |
|
#11
|
||||
|
||||
|
Tried with GesWall but failed to get any scan results with many tries.
May be GesWall is not allowing the file to run.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#12
|
||||
|
||||
|
I saved the file and run it after that and got the following results. It failed on stealing and searching files but that is expected as GesWall only protects the confidential file folder it puts in my documents.
Failed with keylogger that was not good, even snoopfree did not gave any warning. It showed failed against system corruption but as u can see Disk amnagement tool was launched but failed to open so that was infact passed. BTW, test looks cool.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#13
|
||||
|
||||
|
Ok got it
NAV picked it up first as malicious script: wanted to block. Failed the first two PrevX gave no warnings ( unless they have some database of benign tests that was bad.) E-mail to them. Thanks Bill. Back to db again for more tools PG looking better all the time.
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#14
|
|||
|
|||
|
~suddenly feeling so old~
(more or less cross posted elsewhere too) Why on earth would anybody in his/her right mind want to run an .HTA file (index.hta in this case) from a site? Did we really forget about the warnings from PCHelp long ago (about scrap files in general)? http://www.pc-help.org/security/scrap.htm Does anybody here remember PCHelp at all (well, I know Paul does )?Did anybody here read the warnings at the IEClean site: http://www.nsclean.com/ieclean.html It may be old, but here you go: Quote:
Does anybody here remember WormGuard? Did you see this setting in WG: http://www.diamondcs.com.au/wormguar...0List%20Editor I'm sure that there are more examples to give. |
|
#15
|
||||
|
||||
|
Hey FanJ:
Quote:
I wanted to see what would happen in general with this test and if this got behind AV Disturbingly: Neither BO Clean or PrevX caught or warned about this !! Ran the test in a special FDISR snapshot ie sandbox type setup Not always as stupid as I sound. Not really interested in exploiting IE: anyone can do that LOL More interested in other "security" utilities Heh have to test now with PG: maybe PG is still the topgun. Regards. OT: Ps I am finding it very interesting how many well known exploits/ leak tests are bypassing PrevX: not entirely sure how to interpret that: many e-mails being sent. Be interesting to see what other "safety nets" will do SSM, DefenceWall, OA, ANtiHook etc, etc.
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres Last edited by Longboard : October 19th, 2006 at 01:30 AM. |
|
#16
|
||||
|
||||
|
Tried DefenceWall and failed all except 4th one.
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
|
#17
|
||||
|
||||
|
Ok Bill: it's a set-up?
Quote:
Quote:
Quote:
Quote:
Where do I sign up? ![]()
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#18
|
|||
|
|||
|
Quote:
Confirm- hta script runes by trusted svchost, not by browser. Hm, it was really surprise for me! Already fixed, will be released with the next version. Need to check out other staff... |
|
#19
|
||||
|
||||
|
Hi
Neat test. Passed all except the Stealing Files test. What action is required to plug that gap?
__________________
Cheers Jon |
|
#20
|
||||
|
||||
|
Having done these tests it appears something has been left behind?
Each reboot the "system 32" directory is on the desktop What is this? Not happy? A fix?
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres |
|
#21
|
||||
|
||||
|
Quote:
Found in c:\documents settings\all users\start menu\programs\startup: desktop.ini & browserscan.txt Made them go away. |
|
#22
|
||||
|
||||
|
Quote:
Just ran it on my work desktop, and on this it said Test 1 Passed but like SpikeyB, there is a Stolen Files folder on the desktop. Any comments on that, and again how do I stop that security vulnerability?
__________________
Cheers Jon |
|
#23
|
||||
|
||||
|
Would you please so kind and tell us which traces this Browser test leaves behind. There are some registry entries which provoke explorer to show up at startup of the PC with the system32 folder. Also some ugly startup entries are made. Please list them all as they don't eliminate themselve after the test is finished.
__________________
Ciao Tommy Member of ASAP System: Windows XP SP2 | Vaio Laptop Security Setup: Avira Premium | Jetico 2 |
|
#24
|
|||
|
|||
|
Thanks guys!
Looks like I have a bit of tuning to do. I decided to use publicly visible code for easy code review and to show I'm not doing anything that detects our product or any other competing products. Plus visible code is less threatening than an executable.
The reason I used an .hta was because I wanted auditable scripts, and any software which protects your system from your browser should also protect what the browser launches. Other files which we all open such as pdf, doc, xls, gif, flash, mov, and other files may contain either accidental infections or intentially malicious scripts. For those who are concerned that AV and AS are not stopping some of these, I have one more example which I think is a bit over the line. It displays passwords from protected storage and writes them to a text file in your startup folder. It's a four line script which will download a known hacktool (password revealer) to your computer, and launch the hacktool before your AV can stop it. Maybe since it's a known hacktool it's not over the line, however I would like to obscure the passwords and reveal just enough to show it really is extracting your saved passwords. Hi Ilya, glad I could help. We talked about this some time before, and your requirement was that the scripts of the test could be audited, and there you go. |
|
#25
|
||||
|
||||
|
Quote:
So how we can use it?
__________________
Ubuntu 12.10 AX64 Time Machine, Comodo FW & Defence Plus, |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|