![]() |
|
#1
|
||||
|
||||
|
Quote:
|
|
#2
|
|||
|
|||
|
Another FF 0 day lolz
|
|
#3
|
||||
|
||||
|
I luv IE9.
![]()
__________________
Webroot SecureAnywhere |
|
#4
|
||||
|
||||
|
Quote:
but what about their offer giving away 10 grands for anyone can find a 0day exploit in FF |
|
#5
|
||||
|
||||
|
Quote:
lol, payable through here I hope. ![]()
__________________
Webroot SecureAnywhere |
|
#6
|
||||
|
||||
|
Quote:
Good malware writers with sufficient resources at their disposal can easily earn that amount in a day or less by maliciously exploiting the bug in the wild instead of reporting it to Mozilla. |
|
#7
|
|||
|
|||
|
Quote:
http://blog.mozilla.com/security/201...d-firefox-3-6/ |
|
#8
|
||||
|
||||
|
Quote:
Does it come with a spelling checker? ![]() |
|
#9
|
||||
|
||||
|
Who has managed to hack the Nobel Site ??
I'm not going there to check, but what servers are they on, what OS and what other pages hosted ?? There is little doubt if I had visited I would have likely allowed scripts to run. Nasty. Any detection for this mal ?? Anyone know if the usual tools would have blocked this ? Quote:
__________________
Don't confuse me with someone who actually knows what they are talking about. Linux Registered user 469135 Please, support Medecins Sans Frontieres Last edited by Longboard : October 27th, 2010 at 07:56 AM. |
|
#10
|
||||
|
||||
|
Quote:
![]()
__________________
If it ain't broke... fix it until it is. CIS 5 user... |
|
#11
|
||||
|
||||
|
Quote:
|
|
#12
|
||||
|
||||
|
Yep, but I don't cripple anything. Default deny, that's it.
__________________
If it ain't broke... fix it until it is. CIS 5 user... |
|
#13
|
|||
|
|||
|
It'd be nice if mozilla (and others when this happens) would say which OS-native security protections their various memory mismanagement exploits bypass.
Does this just affect people too dumb to enable DEP? Or is it bypassing every EMET trick in the book from SEHOP to ASLR? Doesn't seem likely. A buffer overflow in 500,000 lines of C code isn't news. Nobody expects a programming language designed in the 1970s to not be a horrible pile of crap. Breaking 21st century security mitigations is however, news. |
|
#14
|
||||
|
||||
|
Quote:
You can achieve fine grain script control in IE just fine, even without installing an extension, without requiring to cripple your browsing experience. Quote:
Not yet, a big ![]() Fingers crossed for beta 2.... or maybe the spellcheck plugin will be updated.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#15
|
||||
|
||||
|
Quote:
__________________
|
|
#16
|
||||
|
||||
|
Quote:
|
|
#17
|
|||
|
|||
|
A default-deny policy should stop this cold.
|
|
#18
|
||||
|
||||
|
Quote:
Efficient coding. You're better off checking the OS in the script rather than downloading the malware and performing the check, assuming the malware doesn't run properly on later systems. Educated guess...
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#19
|
||||
|
||||
|
Quote:
|
|
#20
|
||||
|
||||
|
Quote:
I don't see what backwards compatability has to do with new technologies in Windows 7 that prevent such attacks.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#21
|
||||
|
||||
|
Quote:
|
|
#22
|
||||
|
||||
|
Quote:
My signature elaborates.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#23
|
||||
|
||||
|
Quote:
So, as I was asking, which technologies, exactly? |
|
#24
|
||||
|
||||
|
Quote:
Err, what? There is no evidence that the trojan doesn't use them, so what point are you trying to make? Are you seriously trying to make an argument out of my guess? With 0 factual information from either of us? Quote:
My signature elaborates.
__________________
OpenDNS with DNSCrypt SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere |
|
#25
|
||||
|
||||
|
Quote:
Quote:
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|