<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>InfoSec Tools, Tips &#38; Thoughts &#187; Browsers</title>
	<atom:link href="http://infosec3t.com/category/applications/browsers/feed/" rel="self" type="application/rss+xml" />
	<link>http://infosec3t.com</link>
	<description>Exploring topics in InfoSec and Cyber Security   including  practical approaches to risk management.</description>
	<lastBuildDate>Sat, 12 May 2012 03:05:50 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<meta xmlns="http://www.w3.org/1999/xhtml" name="robots" content="noindex,follow" />
		<item>
		<title>Google to Microsoft-&#8221; Don&#8217;t let the door hit ya,&#8230;!&#8221;</title>
		<link>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/</link>
		<comments>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/#comments</comments>
		<pubDate>Tue, 01 Jun 2010 17:13:22 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Systems]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=2231</guid>
		<description><![CDATA[Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun telling new employees that they are no longer able to request Windows PCs, giving them the choice of Mac or Linux systems. Google has long offered its employees their choice of work operating system but [...]]]></description>
			<content:encoded><![CDATA[<p><em> </em><img class="alignright size-full wp-image-2230" title="microsoft_piss" src="http://infosec3t.com/wp-content/uploads/2010/06/microsoft_piss.jpeg" alt="" width="127" height="114" />Talk about throwing out the baby with the bath water. The Financial Times reported on Monday that Google has begun  telling new employees that they are no longer able to request Windows  PCs, giving them the choice of <a href="http://infosec3t.com/tag/mac/" class="st_tag internal_tag" rel="tag" title="Posts tagged with MAC">Mac</a> or Linux systems. Google has long  offered its employees their choice of work operating system but will no  longer do so. According to a Google employee, any exceptions will require will require CIO approval. [ <em>I find that assertion questionable though</em> ].</p>
<p>Google is apparently making this decision in response to the hacking attacks on late last year in China. The attackers  used vulnerabilities  in <a href="http://infosec3t.com/tag/microsoft/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Microsoft">Microsoft</a>&#8217;s <a href="http://infosec3t.com/tag/internet-explorer/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Internet Explorer">Internet Explorer</a> 6 to go after Google&#8217;s intellectual property, believed to be source code.  One could argue that if they had updated their browsers, the attacker would have had to find other vectors for attacks.</p>
<p>Could this be a strategic move by Google to prove that an Enterprise can survive WITHOUT Microsoft? With Google&#8217;s Chrome OS on the horizon, this may just be the warm-up act.</p>
<p>Source: <a href="http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html" target="_blank">http://www.ft.com/cms/s/2/d2f3f04e-6ccf-11df-91c8-00144feab49a.html</a></p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
<li><a href='http://infosec3t.com/2010/03/02/microsoft-says-do-not-call-for-help/' rel='bookmark' title='Microsoft says Do Not Call for Help!'>Microsoft says Do Not Call for Help!</a> <small>If it sounds like a horror movie&#8230;.well, that&#8217;s because is...</small></li>
<li><a href='http://infosec3t.com/2009/12/20/use-google-apps-or-gmail-avoid-getting-hacked/' rel='bookmark' title='Use Google Apps or Gmail? Avoid getting hacked!'>Use Google Apps or Gmail? Avoid getting hacked!</a> <small>It can happen to the best of us. Blogger and...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/06/01/google-to-microsoft-dont-let-the-door-hit-ya/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Does the musical browser approach work?</title>
		<link>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/</link>
		<comments>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/#comments</comments>
		<pubDate>Mon, 22 Mar 2010 18:42:50 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Software]]></category>
		<category><![CDATA[warning]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1976</guid>
		<description><![CDATA[German&#8217;s official cyber-security response team is advising surfers not to use Firefox pending the release of a patch to defend against a critical unpatched vulnerability. This is the second time in two months that Germany has taken such a step. Earlier in January, the German government issued a similar warning to IE users. I did [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1979" title="firefox" src="http://infosec3t.com/wp-content/uploads/2010/03/firefoxpostvotbox17090_.jpg" alt="" width="170" height="90" />German&#8217;s official cyber-security response team is advising surfers not to use <a href="http://infosec3t.com/tag/firefox/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Firefox">Firefox</a> pending the release of a patch to defend against a critical unpatched vulnerability. This is the second time in two months that Germany has taken such a step. Earlier in January, the German government issued a similar warning to IE users. I did a post about it titled <em><a rel="bookmark" href="../2010/01/19/france-germany-warn-users-against-internet-explorer/">Germany warn users against Internet Explorer.<br />
</a></em></p>
<p>The zero-day vulnerability in the latest full version 3.6 of Firefox was discovered by security researcher Evgeny Legerov last month.  Legerov controversially offered to sell exploit code he developed.  Mozilla <a href="http://blog.mozilla.com/security/2010/03/18/update-on-secunia-advisory-sa38608" target="_blank">acknowledged</a> the security vulnerability on Thursday and promised the the next version of 3.6.2, due at the end of the month, would plug the hole.</p>
<p>I have to applaud the German government for taking such a proactive approach to online security of it&#8217;s citizens. I have to wonder what would be the response to such an approach my the US government here. As to the advice given, I&#8217;m of two minds really. Whereas home users are at liberty to switch browsers as often as their underpants, corporate users may not have that luxury. Whole scale <a href="http://infosec3t.com/tag/software/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Software">software</a> migrations in a corporate setting is no small undertaking. Ig it were, I doubt Google would have gotten hacked for using IE6.</p>
<p>Vulnerabilities in all browsers are discovered over time. Corporate users, does the musical browser approach really work even if it were possible? I think not. My advice: Test and Upgrade as soon as is feasible.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
<li><a href='http://infosec3t.com/2010/02/01/google-and-china-a-dysfunctional-marriage/' rel='bookmark' title='Google and China: A Dysfunctional Marriage'>Google and China: A Dysfunctional Marriage</a> <small>Since making it&#8217;s search engine available to Chinese users in...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/22/does-the-musical-browser-approach-work/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upgrade your Safari browser now!</title>
		<link>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/</link>
		<comments>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/#comments</comments>
		<pubDate>Wed, 17 Mar 2010 22:49:37 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Applications]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Mac OS]]></category>
		<category><![CDATA[safari]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=1931</guid>
		<description><![CDATA[The newly released Safari 4.0.5 reportedly fixes a number of security issues on the Windows and Mac OSX platform versions of its browser, and includes remediations for a total of 16 security vulnerabilities. Some of these vulnerabilities allows your system to be compromised simply by browsing a page with an infected image file so upgrade [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-full wp-image-1932" title="apple_safari" src="http://infosec3t.com/wp-content/uploads/2010/03/apple_safari.jpg" alt="" width="144" height="144" />The newly released <a href="http://www.apple.com/safari/" target="_blank">Safari 4.0.5 </a> reportedly fixes a number of <a href="http://infosec3t.com/tag/security/" class="st_tag internal_tag" rel="tag" title="Posts tagged with security">security</a> issues on the <a href="http://infosec3t.com/tag/windows/" class="st_tag internal_tag" rel="tag" title="Posts tagged with Windows">Windows</a> and Mac OSX platform versions of its browser, and includes remediations for a total of 16 security vulnerabilities.</p>
<p>Some of these vulnerabilities allows your system to be compromised simply by browsing a page with an infected image file so upgrade without delay.</p>
<p>According to Brian Cluley of Sophos , &#8220;It doesn&#8217;t matter whether you own a Mac or PC, if you run <a href="http://infosec3t.com/tag/safari/" class="st_tag internal_tag" rel="tag" title="Posts tagged with safari">Safari</a> the message is clear: It&#8217;s time to update your browser and ensure that you are protected against hackers exploiting the security holes detailed in the security advisory on Apple&#8217;s website&#8221;</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2009/12/09/more-on-forensics/' rel='bookmark' title='More on Forensics&#8230;'>More on Forensics&#8230;</a> <small>Follow what the NOVA Information Assurance Strike Team is up...</small></li>
<li><a href='http://infosec3t.com/2010/06/06/pentagon-and-congress-wants-control-of-your-network-during-cyberattack/' rel='bookmark' title='Pentagon and Congress wants control of your network during cyberattack'>Pentagon and Congress wants control of your network during cyberattack</a> <small>There has been a lot of chatter in the news...</small></li>
<li><a href='http://infosec3t.com/2010/01/26/2010-cybersecurity-watch-survey/' rel='bookmark' title='2010 CyberSecurity Watch Survey'>2010 CyberSecurity Watch Survey</a> <small>Cybercrime threats posed to targeted organizations are increasing faster than...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/03/17/upgrade-your-safari-browser-now/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Don&#039;t ignore this warning!</title>
		<link>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/</link>
		<comments>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/#comments</comments>
		<pubDate>Thu, 07 Jan 2010 02:05:40 +0000</pubDate>
		<dc:creator>William McBorrough, MSIA, CISSP, CISA, CRISC, CEH</dc:creator>
				<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Internet Explorer]]></category>

		<guid isPermaLink="false">http://infosec3t.com/?p=598</guid>
		<description><![CDATA[Following up on yesterday&#8217;s post, the advice was to ascertain the legitimacy of the web site by verifying the digital certificate. So what is a web site really? It&#8217;s just files located on a server somewhere. As you &#8220;browse the web&#8221;, your browser connects to the web server where those files are stored, downloads and [...]]]></description>
			<content:encoded><![CDATA[<p>Following up on yesterday&#8217;s <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/" target="_blank">post</a>, the advice was to ascertain the legitimacy of the web site by verifying the digital certificate. So what is a web site really? It&#8217;s just files located on a server somewhere. As you &#8220;browse the web&#8221;, your browser connects to the web server where those files are stored, downloads and displays them to you. The digital certificate resides on the web server and is transferred to your browser when you connect to a web site using https. The certificate contains two important items: the identification information of the web server and the encryption key that allows your browser to create an encrypted tunnel to the web server. The encrypted tunnel protects  your web traffic from attackers.</p>
<p>So https indicates your communications to the web site is encrypted. Clicking on the <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/" target="_blank">golden lock</a> displays the digital certificate and identity information. But what if your browsers decides it doesn&#8217;t like the certificate? Well it warns you. Ever seen these before:</p>
<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2.png"></a><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41.png"><img class="aligncenter size-medium wp-image-604" title="Internet Explorer Certificate Error" src="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41-300x168.png" alt="" width="300" height="168" /></a><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-41.png"></a></p>
<p><a href="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2.png"><img class="aligncenter size-medium wp-image-601" title="Firefox Certificate Error" src="http://infosec3t.com/wp-content/uploads/2010/01/Picture-2-300x158.png" alt="Firefox Certificate Error" width="300" height="158" /></a></p>
<p>If you have spent any amount of time on the web, you will have eventually come across these warnings. What do you generally do? Flee for your life? Read the details? Continue on to the web site anyway? Well, don&#8217;t just ignore this <a href="http://infosec3t.com/tag/warning/" class="st_tag internal_tag" rel="tag" title="Posts tagged with warning">warning</a>! There are multiple reasons why your browser might balk at pproceeding to the requested web site.</p>
<p>Certificates are generally issued by companies like <a title="Verisign" href="http://www.verisign.com/" target="_blank">Verisign</a> and <a title="Thawte" href="http://www.thawte.com/" target="_blank">Thawte</a> after the entity requesting the certificate has verified its identity. The certificates are digitally connected to a root certificate located at the issuer. Browsers are pre-configured with a number of more popular root certificates. That is why, when you access your online bank account, your browsers automatically recognizes the certificate and allows you to proceed without issue. The certificates are valid for a specified period of time and require renewal. If the certificate has expired, your browser will detect it and you will see the warning displayed  above. If your browser does not recognize the source of the certificate ( i.e no connection to a known root certificate), you will see the error message as well. This is the case when web site owners decide not to purchase a certificate issued by one of the aforementioned third-parties and create their own certificate which still provides the same functions: claims an identify and enable encryption.</p>
<p>This last point is key. <strong>Anyone can create a certificate</strong>. I can create a certificate in seconds claiming my laptop to be <strong>https</strong>://www.your-online-bank.com. Tools that enable a man-in-the-middle attack mentioned in yesterday&#8217;s <a title="Beware of Free Internet Connections" href="http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/">post</a> automatically do this.  Now, as your browser will recognize the lack of digital connection between my fake web site certificate and the real root certificate, it will warn you with one of the  errors displayed above. Beware that you don&#8217;t make it a habit of clicking to continue without giving it a second thought.</p>
<p>Related posts:<ol>
<li><a href='http://infosec3t.com/2010/02/16/1533/' rel='bookmark' title='Enter the Dragon browser, the more secure Google Chrome'>Enter the Dragon browser, the more secure Google Chrome</a> <small>The open source engine that forms the basis for Google&#8217;s...</small></li>
<li><a href='http://infosec3t.com/2010/01/05/beware-of-free-internet-connections/' rel='bookmark' title='Beware of Free Internet Connections'>Beware of Free Internet Connections</a> <small>Many hotels,coffee shops and other such establishments  offer free wireless...</small></li>
<li><a href='http://infosec3t.com/2010/03/08/sahi-%e2%80%93-web-automation-application-security-testing-tool/' rel='bookmark' title='SAHI – Web Automation &amp; Application Security Testing Tool'>SAHI – Web Automation &amp; Application Security Testing Tool</a> <small>Sahi is an automation tool to test web applications. Sahi...</small></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://infosec3t.com/2010/01/06/dont-ingore-this-warning/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

