Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old January 17th, 2004, 02:47 PM
yabbseq
 
Posts: n/a
Default forum

hi, i was just wondering, if i log onto any forum [not this one of course ], is it possible for that forum to infect me and remotely access my computer or snoop on me? i'm paranoid, so i want to know if the chances are totally zero. i have not downloaded any files from the forum at all, but is it possible that there is some embedded activex control or some malicious script? i'm running zonealarm at the moment, but i don't know if that will protect me against those types of attacks that are in webpages as i'm a newbie at this stuff. thanks
  #2  
Old January 18th, 2004, 01:36 AM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,601
Default Re:forum

have a look at the link it will explain how a webpage can infect your machine I don't know if a forum is going to do this but it wouldn't be that hard with the right tools.


http://www.wilderssecurity.com/showthread.php?t=19784
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #3  
Old January 18th, 2004, 11:13 AM
LowWaterMark LowWaterMark is offline
Administrator
 
Join Date: Aug 2002
Location: New England
Posts: 15,521
Default Re:forum

The amount of access any website has to your system (and online forums like this are really still just a type of website) depends entirely upon how you access it.

It comes down to the browser used, it's security settings and trust level granted to that site in question, and of course the potential for exploits within that browser.

Often when people like (and trust) a website or forum they put the site name into their trusted zone. I do that myself but I'm careful what sites I do trust. Now for this YaBB SE forum, adding the site to the IE trusted sites list is actually overkill. It is more access than is really needed.

For example, just to reconfirm this for this post, I'm using IE6 here with this forum in the trusted sites list, however I've just changed all the security settings in that zone. ActiveX (all 5 items) are now disabled. Java VM is disabled. All the Misc sections settings (except "Submit nonencrypted form data") are disabled. Only "Active scripting" is enabled (just the first item in that section, not the next two - those are also disabled). With these tighter settings, and allowing first-party cookies from wilderssecurity.com this forum software works normally.

The potential for exploit with the settings I just described are probably those simply related to known IE active scripting exploits (but only the ones that actually work without also needing ActiveX enabled).

Technically the best way to approach security is the "least privilege" concept. Grant only the absolute minimum access and trust levels required to make the site work, and no more than that! Back that up with effective filtering or proxy tools (that scan and strip out malicious items, popups and other such things) and you are as secure as you can hope to be.

Obviously, browser choice and security tool selection is very important, but following it up with a lot of common sense and watching where you click is also really important.
  #4  
Old January 18th, 2004, 01:51 PM
yabbseq
 
Posts: n/a
Default Re:forum

wow that was a great response. however i AM a total newbie in this area and i would like to disable scripting. initially i had thought that since i have "signed activex controls" set to prompt, that would protect me, but i guess i was wrong. another problem is that i don't have java vm from microsoft. this is because i am on windows xp and this version doesn't carry it, so i have to stick with sun java sdk 1.4.2. now i went into the security settings for IE 6, and i am wondering, what is "meta refresh" and "allow data sources across domains" and "allow mixed content" etc? These are all options under security. to be completely honest i really would like to play it safe and disable a lot of stuff (and you're right, one forum in particular IS yabb se, hence, the nickname ). now my question is, if i have certain things set to "prompt" am i in any danger? i almost always click no when it comes to that. what do you think?
  #5  
Old January 18th, 2004, 02:15 PM
snowbound snowbound is offline
Retired Moderator
 
Join Date: Feb 2003
Location: The Big Smoke
Posts: 8,727
Default Re:forum

Hi yabbseq

Here is a thread i think will help,

http://www.wilderssecurity.com/showthread.php?t=18245;start=msg112494#msg112494

In this thread i asked similiar questions. I actually use LowWaterMark's settings with little problems. I just get prompted for activex, then i have to decide whether to allow or not.

Hope this helps




snowbound


 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:24 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums