Kyran Wrote:
-------------------------------------------------------
> Yeah. It is rather disappointing that the browser community either doesn't understand the implications of XSS or just doesn't care. Also, with persistant XSS, no one is safe. Since all anti-phishing toolbars currently do is check the domain against a list.
yeah, i have a hard time explaining to ppl the difference bt type 2 attacks and joe-blow XSS
> I would browse inside from a virtual machine, but if it's a virus, I will reformat. If it's XSS, my info is gone anyways.
[
www.getspyblock.com] indicates that there are several attacks that this method would protect against. i'm looking into it. my next step will be to determine how to easily get Windows-in-Windows up and running (and easily repeatable) without a lot of work. i would assume that slipstreaming XP into VMWare Player is the base goal (or maybe a bootable ISO with Firefox and SpyBlock, et al - BartPE could work for this).
> 0-day XSS exploits? Hah. XSS is everywhere. Hardly a rare thing like remote code execution/file inclusion.
yah, i was joking hehe. although i'm sure ppl do come here trolling for sploits which was the bad part of that joke
rsnake Wrote:
-------------------------------------------------------
> ntp, yah, I wish both conversations had gone better. My only saving grace was that I was in the very very earliest talks with Mozilla to get an anti-phishing filter built in and it looks like very soon they'll finally have it, Netscape already had one and IE was in the process of building it into IE7.0. But you're right, that certainly won't protect you from most things, and most of the anti-phishing is using blacklists not heuristics, so it wouldn't help you anyway if each URL was different.
Firefox 2.0rc3 -> Tools -> Options -> Security -> Tell me if the site I'm visiting is a suspected forgery
also has radio buttons for "Check using a downloaded list of suspected sites" OR "Check by asking [FORM] about each site I visit". The only thing in "FORM" right now is Google.
Edited 1 time(s). Last edit at 10/11/2006 08:13PM by ntp.