Script Defender for Chrome

Discussion in 'other software & services' started by ichito, Oct 31, 2013.

Thread Status:
Not open for further replies.
  1. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    It messed up my whitelist.
     
  2. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    Yes, I'm very much aware of this, trust me, I'm using my NoScript, BitDefender Trafficlight, Adblock plus and WebofTrust and Publicfox for Firefox-and trust me it's extremely powerful combo.
    The only difference in Chrome is that Webof Trust cannot be used to block websites with poor reputation-said, but I also still have Script Defender, Adblock Plus and Bitdefender trafficlight-it's awesome, really.
    I don't worry to much now because of those kernel-level exploits on my windows xp exactly because of these truly helpful extensions/plugins.
     
    Last edited: Nov 7, 2013
  3. CoolWebSearch

    CoolWebSearch Registered Member

    Joined:
    Sep 30, 2007
    Posts:
    1,247
    And I still don't know how can the last test actually prove that Chrome has superior implementation than SBIE4, since you can use tight configuration to block anything you want-in this case I don't mean on my windows xp vulnerabilities/kernel-level exploits, but on installation malware/exploit/drive-by downloads that are trying to install themselves on my computer (like from malware domain list and similar black lists of websites and all other similar things).

    So I guess no matter what security application (AppGuard, Sandboxie, DefenseWall, Chrome, SBIE or whatever) I use it's always a russian roulette to go to the internet.
    It doesn't matter if I know use Google Chrome or SBIE4 with configuration-it all depends how many vulnerablities my OS has.

    So, I have a question how do those experts (http://labs.bromium.com/2013/07/23/application-sandboxes-a-pen-testers-perspective/) know that Google Chrome has far superior implementation or whatever, did they actually try to use tightly configured SBIE3 or SBIE4 against Google Chrome to see what the results are going to be?
    I'm not talking about kernel-exploits of any OS, but simply blocking ability of malware (including kernel-level malware, exploits) that is trying to install on your computer?
    How do they know SBIE3 or SBIE4 is not better than Chrome, if Chrome cannot block installation of anything, while SBIE4 can plus with that tight configuration how can Chrome match this?
     
    Last edited: Nov 7, 2013
  4. tlu

    tlu Guest

    I'm having problems to see how the sandbox can protect against the various types of XSS. If it really did, the built-in XSSAuditor would be superfluous, IMHO. Could you elaborate?

    Doesn't that contradict your statement regarding the Chrome javascript renderer above?

    EDIT: The document "The Security Architecture of the Chromium Browser" explicitly says:

     
    Last edited by a moderator: Nov 7, 2013
  5. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    Guys, can you check if you see youtube comments?
    Despite allowing everything on that page, I cannot see them. Thanks.
     
  6. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Same problem here, and I can't come up with a fix for it; i tried adding youtube.com to the whitelist but no difference. This is what i mean about this extension exhibiting some buggy behaviour, but at least it results in blocking too much as opposed to too little :doubt:
     
  7. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    I tried almost everything, the only way to see the comments is to pause it.
     
  8. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Same here, but of course that's not a very good option :(
     
  9. guest

    guest Guest

    @dogbite and wat0114
    Whitelist s.ytimg.com or *.ytimg.com. Or allow it from third party script control menu.

    BTW, just dropped this extension. It's too strong for my liking, blocked some YouTube videos and smileys in SMF-based forum.
     
  10. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    i noticed i was still logged in websites after closing chrome with the new update.

    anyway, back to NS for the moment.

    SD is pretty good but still needs a bit of work.
     
  11. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    Thanks, but still not working.
     
  12. guest

    guest Guest

    Did you also allow third party/external scripts to run in the setting? Alternatively, you can allow it via the drop-down menu.
     
  13. OuterLimits

    OuterLimits Registered Member

    Joined:
    Nov 13, 2009
    Posts:
    66
  14. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
    Thanks, but that didn't work for me either. Like you, I also dropped it, at least for now, but I'll keep an eye on its progress and try it again a bit later.
     
  15. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    I allowed all and now it works.
     
  16. Romagnolo1973

    Romagnolo1973 Registered Member

    Joined:
    Feb 17, 2009
    Posts:
    565
    Location:
    Italy - Ravenna
    is interesting, I tried it but if active Lastpass seems not working, I'm trying some setting but I don't solve
     
  17. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    Updated today to 3.5.

    Again, some whitelist messing up. I had to re-allow Wilders, for example.
     
  18. OuterLimits

    OuterLimits Registered Member

    Joined:
    Nov 13, 2009
    Posts:
    66
    I've been using this all night and just a while ago all sites lost their settings.

    Probably the update but if this keeps happening its not worth it.
     
  19. dogbite

    dogbite Registered Member

    Joined:
    Dec 13, 2012
    Posts:
    1,290
    Location:
    EU
    Also it's impossible to contact the developer to report those bugs, unless to write it in a review in the Chrome store.
     
  20. tlu

    tlu Guest

    I just tested HTTP Switchboard on those sites - and JS was blocked on all of them :thumb:

    I still have to test it thorougly to get a definitive judgement. It could be a good alternative for ScriptDefender or ScriptBlock. Has anyone tried it?

    EDIT: 1. There's a Quick Tour for HTTP Switchboard.
    2. Clicking the info button opens a site that shows statistics and reveals that several blacklists are included in HTTP Switchboard (similar to ScriptSafe). Very interesting!


    EDIT 2: Unfortunately it's buggy. I had allowed cookies, script and XHR for wilderssecurity.com - but after restarting Chrome it had forgotten my decisions. Very sad since otherwise it looks rather promising ...
     
    Last edited by a moderator: Nov 9, 2013
  21. moontan

    moontan Registered Member

    Joined:
    Sep 11, 2010
    Posts:
    3,931
    Location:
    Québec
    tnx for the find! :thumb:

    it works fine here.
    click on wilderssecurity to make it turn green, then a padlock icon will appear.
    click on the padlock to make the changes permanent.

    i like it, it seems to work pretty good.
    ----
    EDIT:
    there are padlocks for all the cells, not just the sites.
    so you can permanently and selectively allow/blocks plugins, cookies, scripts etc
     
    Last edited: Nov 9, 2013
  22. tlu

    tlu Guest

    You're abolutely right, moontan - thanks for noticing that :thumb:
     
  23. OuterLimits

    OuterLimits Registered Member

    Joined:
    Nov 13, 2009
    Posts:
    66
    Okay if I'm on a site which uses Facebook for posting and I want to use that only for that site how do I set the cookies, etc? I'm not getting that through my thick skull but I figure it must be possible.

    Way more comprehensive, it seems, than Script Defender. It looks like I could remove 'Disconnect' with this.
     
  24. wat0114

    wat0114 Registered Member

    Joined:
    Aug 5, 2012
    Posts:
    4,065
    Location:
    Canada
  25. Acadia

    Acadia Registered Member

    Joined:
    Sep 8, 2002
    Posts:
    4,332
    Location:
    US
    Ok, so I am getting confused here although I must admit that I do not use Chrome that often. I was all ready to install ScriptDefender based upon the early enthusiasm for this extension, now some of you have uninstalled it and are now recommending the http thingie?

    Thanks,
    Acadia
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.