Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
May 21, 2013, 08:06:49 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
663371
Posts
70524
Topics
145179
Members
Latest Member:
seij_25
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Security Products & Services
Comodo Internet Security - CIS
News / Announcements / Feedback - CIS
How to block Firefox extension installs with CIS
« previous
next »
Pages:
1
[
2
]
Author
Topic: How to block Firefox extension installs with CIS (Read 11196 times)
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #15 on:
June 23, 2009, 06:39:07 PM »
Sandboxie is awesome. But you don't need parent lock down features. If you have your browser forced to always start Sandboxed then no changes can ever be made to your browser unless you run them outside of a Sandbox. Its very easy. More easy then what your suggesting.
http://www.sandboxie.com/
«
Last Edit: June 23, 2009, 06:40:54 PM by Vakko
»
Logged
SilentMusic7
Comodo's Hero
Offline
Posts: 310
Re: How to block Firefox extension installs with CIS
«
Reply #16 on:
June 24, 2009, 09:53:04 AM »
Quote from: Vakko on June 23, 2009, 06:39:07 PM
Sandboxie is awesome. But you don't need parent lock down features. If you have your browser forced to always start Sandboxed then no changes can ever be made to your browser unless you run them outside of a Sandbox. Its very easy. More easy then what your suggesting.
http://www.sandboxie.com/
If I understand correctly, Sandboxie doesn't prevent installing a Firefox extension by the user -- it makes Firefox effectively forget changes when Firefox is closed. This allows a user to install a malicious extension and get their identity stolen. Also, the inexperienced user is not able to save their bookmarks update between sessions.
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #17 on:
June 24, 2009, 04:16:05 PM »
No you are completely wrong. Please read the Sandboxie site. It tells you everything. And how did we go from Extensions to Identity theft? If you browse under a Sandbox then any changes you make such as extensions or themes will never be installed cause they never actually did get installed. Think of Sandboxie as a virtual machine. Try it yourself if you don't believe me. You can also install programs under a sandbox. As soon as you empty the sandbox then the program is gone cause it never really got installed. It was never written to the hard drive. Yes bookmarks can be saved. There is the option to do so in Sandboxie settings.
Logged
SilentMusic7
Comodo's Hero
Offline
Posts: 310
Re: How to block Firefox extension installs with CIS
«
Reply #18 on:
June 24, 2009, 05:49:48 PM »
I did spend a few hours reading the Sandboxie site. My understanding is that, from the (inexperienced) user's point of view, they can install an extension under Sandboxie. But when they restart Firefox (new sandbox), the new extension is gone.
Quote from: Vakko on June 24, 2009, 04:16:05 PM
And how did we go from Extensions to Identity theft?
I used identity theft (phishing, etc.) as an example of possible results of malicious extensions -- even those that are not permanently installed (because of a sandbox).
Quote from: Vakko on June 23, 2009, 05:06:03 PM
Simply use Sandboxie and no changes to your browser will be made.
The topic of this thread is to help parents and others prevent Firefox installs by a child or another inexperienced user. Someone who investigates the Comodo forum to find this thread likely is already familiar with CIS and wants to learn more about it. I don't understand how adding Sandboxie to CIS is simpler than the CIS configuration I suggested for this audience. I suspect that learning Sandboxie and CIS takes longer than only learning CIS, especially since new versions of Firefox may require Sandboxie updates and investigation. Also, Sandboxie requires extra memory and CPU resources when supplementing CIS than CIS alone, which I cannot afford on one of my PCs. Finally, other posts in this forum mention unresolved security flaws and/or bugs with Sandboxie. For an experienced user that doesn't share their PC, I understand Sandboxie's appeal.
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #19 on:
June 24, 2009, 06:31:26 PM »
WOW.....you are completely not reading the site. Sandboxie is free. It takes 2 seconds to install it and by default needs no tweaking unlike CIS. Also you are not adding Sandboxie to CIS. Your adding it to your browser. To install CIS and configure like your saying will take well over 15 minutes and some knowledge. A newbie can install Sandboxie within 2-3 secs and be under way. I have ran Sandboxie successfully with CIS and Online Armor. It also works with Outpost. You really do not understand what the term "sandboxed" means. Heck there are tons of people who use Sandboxie as there only means of security. BTW I have been a Firefox users for well over 5 years now and I have never seen an extension that requires my personally information.
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #20 on:
June 24, 2009, 06:33:05 PM »
I want you to look through this link and tell me where you find a malicious add on.
https://addons.mozilla.org/en-US/firefox/
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #21 on:
June 24, 2009, 06:38:59 PM »
I do not understand your point about all this anyways. I have seen well over 1,000 infected pc's through my years of fixing them and I have never seen 1 malware infection caused by a Firefox extension. Not one.
Logged
Toggie
Guest
Re: How to block Firefox extension installs with CIS
«
Reply #22 on:
June 24, 2009, 07:30:13 PM »
heise Security UK » Firefox add-on contains malware
News - Trojan spoofs Firefox extension, steals IDs
Internet-security-blogs | Exploits Spy
Microsoft quietly installs a massive security vulnerability in ...
Seek and ye shall find...
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #23 on:
June 24, 2009, 10:22:11 PM »
Most of those articles are old and out dated but again you missed my point. From the list of official add ons I posted please point out a malicious one. There is NONE. Installing a language pack is not an official add on and Microsoft screwing up Firefox is not an official add on . Did you even read those links you posted?
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #24 on:
June 24, 2009, 10:23:23 PM »
Users have discovered malware in a Vietnamese language pack add-on for Firefox on the servers of the Mozilla project. The developers do not know how many users downloaded the infected add-on.
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #25 on:
June 24, 2009, 10:25:44 PM »
Normally, Firefox extensions -- which in Windows have the .xpi file extension -- display a confirmation dialog that the user must acknowledge before the add-on installs. The bogus Numberedlinks, however, skips that.
If you took the time to read then you would have seen that there is no alert from Firefox for this one and the article is from 2006. Also a good anti keylogger would have stopped this.
Logged
Vakko
Comodo Member
Offline
Posts: 28
Re: How to block Firefox extension installs with CIS
«
Reply #26 on:
June 24, 2009, 10:28:42 PM »
This article says nothing.
http://newexploits.com/tag/internet-security-blogs/
Logged
Toggie
Guest
Re: How to block Firefox extension installs with CIS
«
Reply #27 on:
June 24, 2009, 10:40:28 PM »
I'm sorry you missed the point...
Logged
HeffeD
Global Moderator
Comodo's Hero
Offline
Posts: 6568
Re: How to block Firefox extension installs with CIS
«
Reply #28 on:
June 24, 2009, 11:05:39 PM »
I guess you missed all the recent hullabaloo about an author of a popular "security" extension that effectively patched another very popular extension to ignore the authors websites?
Slighty OT to what is being discussed, but don't buy into the "there are no malicious extensions" argument...
Logged
Please read the
Forum Policy
!
Breast Cancer Awareness
American Cancer Society
Endymion
Comodo's Hero
Offline
Posts: 1362
Reality is subordinate to perception.
Re: How to block Firefox extension installs with CIS
«
Reply #29 on:
June 25, 2009, 03:16:14 AM »
Quote from: HeffeD on June 24, 2009, 11:05:39 PM
I guess you missed all the recent hullabaloo about an author of a popular "security" extension that effectively patched another very popular extension to ignore the authors websites?
Slighty OT to what is being discussed, but don't buy into the "there are no malicious extensions" argument...
There is an
Addon policy
meant to guarantee safety whenever there have been two cases that pointed out the possibility of loopholes (NS Vs ADP hullabaloo included:
No Surprises << Mozilla Add-ons Blog
).
Apparently there were less strict checks for well known components although this do not mean that no step was taken to address this.
But assuming that malicious components are actually featured on mozilla and are not detected by any AV could potentially cause unwarranted concerns to any users willing to manually install addons featured on mozilla.org (
Mozilla: For the Record >> Blog Archive >> Vietnamese Language Pack FAQ
) .
Although outside mozilla.org there is a possibility of unauthorized parties attempting to tamper firefox folder and silently configure FF to run an extension (without using built-in Frefox installer),
in case of Microsoft .NET Framework Assistant (
ClickOnce
) though, the possibility was apparently leveraged to provide the same support to .net that is featured by IE (interoperability and support are often crucial factors) although such approach was opposed by many Firefox users who ran
.NET 3.5 SP1 framework setup
,
whereas in 2006 an IE specific web exploit and/or a downloaded were seemingly involved:
FormSpy malicious Firefox extension
«
Last Edit: June 25, 2009, 04:51:58 AM by Endymion
»
Logged
I have learnt silence from the talkative, toleration from the intolerant, and kindness from the unkind; yet strange, I am ungrateful to these teachers.
Kahlil Gibran (1883 - 1931)
Tags:
Pages:
1
[
2
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> How Can I Help Comodo? (Please We Need You!)
===> Report Comodo Forum / Web Site Issues
===> Please Tell Us Your Views and Vote Here!
===> Help Spread the Word - Banners and Logos
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Security Products & Services
-----------------------------
=> Comodo Internet Security - CIS
===> News / Announcements / Feedback - CIS
=====> Wishlist - CIS
===> Help - CIS
=====> Guides - CIS
=====> AntiVirus Help - CIS
=======> AntiVirus FAQ - CIS
=====> Firewall Help - CIS
=======> Firewall FAQ - CIS
=====> Defense+ / Sandbox Help - CIS
=======> Defense+ / Sandbox FAQ - CIS
=====> Install / Setup / Configuration Help - CIS
=======> Install / Setup / Configuration FAQ - CIS
===> Bug Reports - CIS
===> AV False Positive/Negative Detection Reporting
=> Comodo Cleaning Essentials + KillSwitch & Autoruns - CCE
===> News / Announcements / Feedback - CCE
=====> Wishlist - CCE
===> Help - CCE
===> Bug Reports - CCE
=> Comodo Antivirus for Mac OS X - CAVM
=> Comodo Antivirus for Linux - CAVL
=> Comodo Mobile Security - CMS
=> Comodo Time Machine - CTM
===> News / Announcements / Feedback - CTM
===> Help - CTM
=====> FAQ - CTM
===> Bug Reports - CTM
=> Comodo Dragon - CD
===> News / Announcements / Feedback - CD
=====> Wishlist - CD
===> Help - CD
=====> FAQ - CD
===> Bug Reports - CD
=> COMODO IceDragon - CID
===> News / Announcements / Feedback – CID
=====> Wishlist - CID
===> Help – CID
===> Bug Reports - CID
===> Beta Corner – CID
=> Comodo LoginPRO
=> Comodo Disk Encryption - CDE
===> News / Announcements / Feedback - CDE
=====> Wishlist - CDE
===> Help - CDE
=====> FAQ - CDE
===> Bug Reports - CDE
=> Comodo Secure DNS - DNS
===> News / Announcements / Feedback - DNS
===> Help - DNS
=> Comodo Unite (EasyVPN) - CUnite
===> News / Announcements / Feedback - CUnite
===> Help - CUnite
=====> FAQ - CUnite
===> Bug reports - CUnite
=> Comodo TrustConnect - CTC
=> Comodo SiteInspector - CSI
=> Comodo Valkyrie - FLS
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Rescue Disk - CRD
-----------------------------
Desktop Utilities & Services
-----------------------------
=> Comodo System Utilities - CSU
===> News / Announcements / Feedback - CSU
===> Help - CSU
=====> FAQ - CSU
===> Wishlist - CSU
=> Comodo Backup - CB
===> News / Announcements / Feedback - CB
===> Comodo Cloud
===> Help - CB
=====> FAQ - CB
===> Wishlist - CB
=> Comodo Programs Manager - CPM
===> News / Announcements / Feedback – CPM
===> Help - CPM
===> Wishlist - CPM
=> GeekBuddy & Live PC Support
=> GeekBuddy PC Health Check - PCHC
===> News/ Announcements / Feedback – PCHC
===> Help - PCHC
-----------------------------
Business / Enterprise Security Products & Services
-----------------------------
=> Digital Certificates
===> Code Signing Certificate
===> Content Verification Certificate
===> Email Certificate
===> SSL Certificate
=> PCI DSS Compliance
=> Comodo Endpoint Security Manager
===> Endpoint Security Manager 1.6
===> Endpoint Security Manager 2.0 Business Edition
===> Endpoint Security Manager 2.1
===> Endpoint Security Manager 3.0
=====> CESM 3.0 Beta
===> ESM Console for Windows Phone
===> Earlier versions of CESM
=> Two Factor Authentication for Web Applications
=> Trustlogo
=> Hacker Guardian
=> Comodo Network Center - CNC
=> Comodo AntiSpam Gateway - Hosted Anti Spam Service
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> General Security Questions and Comments
=> Virus/Malware Removal Assistance
=> Leak Testing/Attacks/Vulnerability Research
=> Digital Certificates, Encryption and Digital Signing
=> Other Security Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Česky / Czech
===> Dansk / Danish
===> Nederlands / Dutch
===> Suomi / Finnish
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> Română / Romanian
===> По-русски / Russian
=====> News & FAQ
=====> Оффтоп (OFFTOP)
=====> Архив / Archive
===> Slovenský / Slovak
===> Slovenščina / Slovenian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> Việt / Vietnamese
===> Estonian
===> Arabic
-----------------------------
Archived Boards
-----------------------------
=> Discontinued Products
===> Comodo Web Application Firewall - CWAF
===> Comodo HopSurf - CHS
===> Comodo AntiSpam - CAS
=====> Help - CAS
=======> FAQ - CAS
=====> News / Announcements / Feedback - CAS
=======> Wishlist - CAS
=====> Bug Reports - CAS
===> Verification Engine - CVE
===> Comodo Secure Email - CSE
=====> News / Announcements / Feedback - CSE
=====> Help - CSE
=======> FAQ - CSE
=====> Bug Reports - CSE
===> Comodo Cloud Scanner - CCS
=====> News / Announcements / Feedback - CCS
=====> FAQ - CCS
=====> Beta Corner - CCS
=====> Wishlist - CCS
===> Comodo Anti-Viruspyware (CAVS)
=====> Help for Comodo AntiVirus
=====> FAQ for Comodo Anti-ViruSpyware
=====> Feedback/Comments/Announcements/News about CAVS
=====> CAVS BETA Corner
=====> Announcements
=====> Comodo BOClean Anti-Malware FAQ
===> Comodo Diskshield
===> Comodo Firewall
=====> Feedback/Comments/Announcements/News
=====> Help for v3
=====> Help for v2
=====> Frequently Asked Questions (FAQ) for Comodo firewall
=====> CFP BETA Corner
=======> 32 bit bug reports
=======> 64 bit bug reports
=====> Comodo Firewall Translations
=====> Bug Reports
===> i-Vault
===> Launch Pad (Discontinued)
===> Comodo Meet (Web Conferencing Product) (Discontinued)
===> Comodo Memory Firewall(Buffer Overflow Protection)
=====> Comodo Memory Firewall Beta Corner
=====> Help
=====> Frequently Asked Questions (Comodo Memory Firewall)
=====> Feedback/Comments/Announcements/News
===> Safesurf
===> Trusttoolbar (Discontinued)
===> Trustfax (online faxing)
===> Trustix Enterprise Firewall
===> User Anywhere (Remote Access product) (Discontinued)
===> UserTrust - First Independent Website Rating - Empowering our users!
===> Comodo Vulnerability Analyzer - CVA
===> ZTL
=> Comodo Wiki Project
Page created in 0.059 seconds with 21 queries.
Powered by SMF 1.1.18
|
SMF © 2006, Simple Machines
Design by
7dana.com