![]() |
|
#1
|
||||
|
||||
|
This site was designed to show how the new IE9 protects users from a web based attack.
https://ie.microsoft.com/testdrive/b.../woodgrove.htm Now I didn't want to test my browser, I wanted to test SOL (HTTPS)and it failed. I was using IE8, and allowed mixed content after receiving a warning from IE8. Win7 64Bit Prevx v3.0.5.217 Last edited by overangry : October 26th, 2010 at 11:40 PM. |
|
#2
|
||||
|
||||
|
Very interesting!
TH
__________________
Triple Helix - Microsoft® MVP Consumer Security 2012/14 VIP Member Of ASAP - (Alliance of Security Analysis Professionals™) Webroot® SecureAnywhere™ Complete 2013 Closed Beta Tester v8.0.2.155 - VoodooShield 1.08 - Windows 7 Ultimate 64bit and all Windows OS's from XP to Win 8 on VM's. |
|
#3
|
||||
|
||||
|
Big Time Fail - Yuck
![]()
__________________
Sent From My New "ipod killer" - the Samsung Galaxy Media Player 5.0
|
|
#4
|
||||
|
||||
|
strange, even keyscrambler fails it
![]()
__________________
Windows 7 x64 - Windows Defender: Disabled - UAC: Disabled Real-Time: Avast Free / Zemana Free / WinPatrol On-Demand: HitmanPro / MBAM |
|
#5
|
||||
|
||||
|
At the moment, this type of attack is very browser-specific and outside the scope of SafeOnline. Stopping this function within the browser inadvertently will cause several major browser features to break so unfortunately this will likely be exclusively up to the browser manufacturers (and Microsoft appears to be doing so with IE9).
SafeOnline could potentially handle cases like this but it would likely cause far more complaints than actual benefits whereas it is able to circumvent any malware running on the PC from affecting the browser. There have been no real attacks which use this technique but if there is one, we will be adding blacklisting for the domains affected. Let me know if you have any questions! |
|
#6
|
|||
|
|||
|
I passed the test in IE 8, but failed in Firefox. Both are protected by Prevx SafeOnline. Is it man-in-the-middle attack?
__________________
Windows 8 Pro x64 + Kaspersky Internet Security 2013 + Shadow Defender 1.2.0.376 + Sandboxie 3.76 |
|
#7
|
||||
|
||||
|
Quote:
Just one more quick question, I uninstalled IE9 because SOL doesn't support beta browsers, using SOL, is IE9 safer than IE8? |
|
#8
|
|||
|
|||
|
Some more info:
https://ie.microsoft.com/testdrive/b.../mixedcontent/ At least most Wilders visitors and other people with computer knowledge would notice an attack like this, as Firefox doesn't show the green or blue icon from a secure HTTPS page as not everything is in HTTPS. A lot of banking sites I know, also ask the user to check if there is a lock icon, blue/green icon or whatever the user's browser shows on a secure HTTPS connection. The secure version of the Hotmail login page had this for quite a while, as one picture was loaded in HTTP, however you can use AdBlock Plus to select all HTTP content and block it so you will have a confirmed secure connection. It would be nice though if Firefox could incorporate this like IE9. |
|
#9
|
|||
|
|||
|
NoScript initially appeared to prevent it - but certainly failed when MS was allowed.
How on earth would we even know this was happening for real ? |
|
#10
|
||||
|
||||
|
even keyscrambler pro failed it.. I am about to turn off the internet and go to sleep
![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
#11
|
||||
|
||||
|
IE8 showed this
you pass if you click yes you failed if you click no
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
#12
|
||||
|
||||
|
avast was very silent too
![]() ![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
#13
|
||||
|
||||
|
Quote:
__________________
Eset |
|
#14
|
||||
|
||||
|
Not good
See here for other apps etc also failing - http://www.wilderssecurity.com/showt...98#post1773998 Quote:
I don't see why, as i expect PSOL, at least, to protect ALL such attacks ! That's it's MO surely ? Quote:
Not yet maybe, but we Don't want to wait to find out, thanks Quote:
Too late by then !
__________________
. Malware = You don't scare me A different perspective https://rt.com - https://rt.com/on-air |
|
#15
|
||||
|
||||
|
Quote:
Originally Posted by Kernelwars avast was very silent too doesnt matter, IE 9 did what it was suppose to for me. Going to be a very good browser. __________________ indeed I hope so.. it will be really scary opening up any page and have to use login information knowing I am not protected by the products I pay for or trust. ![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
#16
|
||||
|
||||
|
IE 9 in action
__________________
Eset |
|
#17
|
||||
|
||||
|
Quote:
is browser specific? I thought its suppose to help protect users when browsing.. ![]()
__________________
Sandboxie | WinPatrol | CCE | MBAM | OpenDns with DnsCrypt |
|
#18
|
|||
|
|||
|
You can set Firefox to warn for HTTPS sites showing HTTP content, but you cannot set it to load only the HTTPS content. To let it show a warning go to about:config and set security.warn_viewing_mixed to True.
|
|
#19
|
||||
|
||||
|
Quote:
....atleast now i would keep the mixed content setting in IE8 disabled
__________________
Last night I lay in my bed looking up at the stars in the sky and I thought; Where the heck is my ceiling?! |
|
#20
|
||||
|
||||
|
there are other online tests http://ie.microsoft.com/testdrive/vi...s/default.html
i got the red skull and crossbones in Google Chrome ..... didtnt block but at least it warns i was just wondering what if this link was just set up to fit IE9 ..i mean like advertising ...all other products supposed to fail only IE9 pass !!!
__________________
Analyzing scareware, junkware, crimeware, damnware, crapware ....... and all $h!tware |
|
#21
|
||||
|
||||
|
this made me think HTTP is soooooooooo very unsecure...
can someone explain me why most websites use HTTP instead of HTTPS? ![]()
__________________
Win7PRO64bit | SUA | SRP | UAC | EMET | SpywareBlaster | MVPSHOST | OpenDNS | SandboxIE | Privoxy | Windows Image Backup . built-in security + sandboxing fag. |
|
#22
|
||||
|
||||
|
Most web addresses begin with "HTTP," which is an acronym for "Hyper Text Transfer Protocol." It's the protocol used to allow you to communicate with web sites.
"HTTPS" stands for "Hyper Text Transfer Protocol Secure." It means that information exchanged between you and a web site is encrypted and cannot be hijacked by someone who might want to electronically eavesdrop when you type a credit card number, a password, a social security number, or any other person information.
__________________
Eset |
|
#23
|
||||
|
||||
|
IE9 blocked the "dangerous" content.
PrevxHelp: Quote:
protection has to come from behavior analysis or heuristic. signature based protection is not worth much, IMO
__________________
| Xubuntu || NoScript || Image for Linux + BootIt Bare Metal | Last edited by moontan : October 27th, 2010 at 07:41 AM. |
|
#24
|
||||
|
||||
|
Quote:
The reason why SafeOnline and all other security products fail this test is because it is virtually impossible to pass from an application outside of the browser without potentially breaking substantial amounts of browser functionality. By far the best approach here is to disable mixed content. |
|
#25
|
||||
|
||||
|
Disable javascript.
|
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|