Welcome, Guest. Please login or register.
November 18, 2008, 01:14:48 PM

Login with username, password and session length

212127 Posts
24513 Topics
57691 Members

Latest Member: Eva

Search:     Advanced search | Tag Cloud
+  Welcome to the Comodo Forum
|-+  General Category
| |-+  Which Product do you want Comodo to develop next?
| | |-+  tool to protect websites and site visitors from drive by script hackers
« previous next »
Pages: [1] 2 Go Down Print
Author Topic: tool to protect websites and site visitors from drive by script hackers  (Read 3924 times)
prazim
Comodo Member
**
Offline Offline

Posts: 47


« on: May 18, 2007, 10:43:23 PM »

I am sure you saw this today and hope you are working ona solution: http://redtape.msnbc.com/2007/05/the_next_net_th.html

Virtual PC does not work for XP Home, so I assume its mention in the article is to compel people to upgrade to it, but that isn't my preference, nor that of many from what I have read.  Green Border offered a form of virtualization but they are not presently distributing their tool, reason unknown.
Thanks,
Sue
Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #1 on: May 19, 2007, 12:00:14 AM »

If your looking for virtualisation, you could look at sandboxie. If you want a full VM, the maybe virtualbox, both free. On the other hand, turn off javascript and activeX for all sites apart from those you trust.
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
prazim
Comodo Member
**
Offline Offline

Posts: 47


« Reply #2 on: May 19, 2007, 12:12:25 AM »

Hi Toggie,
Actually this article mentioned that unsuspecting websites could be hacked and infected with the malicious script.  I actually only visit sites I trust, but my concern is them getting infected.  Also, I am about to launch a site and I don't want it to become infected.

Thanks for the tip about sandboxie.  It will do the trick, but I can't stand the icon that is part of it, so I haven't installed it.

Sue
Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #3 on: May 19, 2007, 12:39:33 AM »

You could always change the icon using something like reshacker Smiley

As for protecting your own site, it's a constant battle, but I have something here some where that may help...I'll get back to you
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
prazim
Comodo Member
**
Offline Offline

Posts: 47


« Reply #4 on: May 19, 2007, 01:09:10 PM »

huh! reshacker.  very interesting!  I am thinking I will email the developer and request he get creative with the icon, so everyone can benefit.

I'm very interested in your ideas concerning protecting websites.  Once mine is up, I'd like to be able to get word to my contacts that it is protected by x technology and therefore drive by script protected.  I will of course also use a hacker resistant password.
Thanks!
Sue
Logged
Toggie
Global Moderator
Comodo's Hero
*****
Offline Offline

Posts: 1256


"Oh, let me have just a little bit of peril"


« Reply #5 on: May 19, 2007, 01:47:06 PM »

Hey sue, (may I call you sue?) I think I may have been little over zealous in my approach. To be honest, all I have is guide to keeping your web site safe...just wish I could find it
Logged

One man alone can be pretty dumb sometimes, but for real bona fide stupidity, there ain't nothin' can beat teamwork.
prazim
Comodo Member
**
Offline Offline

Posts: 47


« Reply #6 on: May 19, 2007, 01:52:57 PM »

Well St. Anthony is very helpful in such matters!  I'll ask him to help you.  In the interim, this area is most certainly another opportunity for Melih and the team at Comodo!

Most definitely, please call me Sue!
Logged
oOeagleOo
Comodo Loves me
****
Offline Offline

Posts: 105


« Reply #7 on: May 28, 2007, 10:12:51 AM »

You could also download IE-Spyad it ads more then 25000 bad pages to your "Restricted Sites List" in IE

if you use Firefox you can use NoScript
Logged

Firewall : Comodo Firewall Pro V3. (With hips)
Anti Virus : Avira Antivir.
Anti Spyware: SUPERAntiSpyware Pro V4.0
Someone
Guest
« Reply #8 on: May 28, 2007, 05:59:52 PM »

Noscript is a must. It's the primary tool to defend against XSS atacks.
A good discussion: http://www.wilderssecurity.com/showthread.php?t=174195

VirtualPC actually DOES work in XP Home, it's only not supported. I have it installed and already tried OpenBSD in it.
I prefer VirtualBox though, or VMware Player/Server.
This for full virtualization (a whole virtual computer).

To isolate the browser, you have SandboxIE, that uses virtualization tech., or GeSWall, DefenseWall, that enforce policy (policy based sandbox).
Or use a program that prevents executables. CFP will do this at the very least.

Quote
Then, while the consumer browses content normally, a computer virus or Trojan horse program is silently installed.
Usually (always?) this envolves an executable to do the job, no matter how it's downloaded (script, spoofed files..)

One rule to read these articles, that i learned recenty, is to identify how the payload is carried. Nothing special in this sentence, but it's really that simple. It's not vodoo. Doesn't matter if it's trojan, rootkit, etc. It matters how it gets in our pc's.

But this is within our computers. XSS is another thing, more about privacy on the web. But it goes beyond the little cookies. I suggest reading the above link, to get solutions, not to be spooked Smiley
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5935



WWW
« Reply #9 on: May 28, 2007, 07:11:06 PM »

The answer is Comodo Firewall v3!

Melih
Logged

prazim
Comodo Member
**
Offline Offline

Posts: 47


« Reply #10 on: May 28, 2007, 09:19:27 PM »

Thanks great news Melih! When will it be available?
Sue
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
*****
Offline Offline

Posts: 5935



WWW
« Reply #11 on: May 29, 2007, 11:23:51 AM »

Thanks great news Melih! When will it be available?
Sue

beta is out on june 7th.. but pls note, this is just the beta....

melih
Logged

Kyle
Computer Security Testing Group
Comodo's Hero
*****
Offline Offline

Posts: 1395



WWW
« Reply #12 on: August 29, 2008, 10:08:26 AM »

beta is out on june 7th.. but pls note, this is just the beta....

melih

Melih, I understand the Webshields help block scripting attacks - With CPF3, do I need a webshield?

Sorry for reviving an old thread, how ever it seemed appropriate to post here.
Logged

*Have been accepted into the Australian army, Rifleman, Full time for 4 years minimum.
Leaving on Feb 2nd.
DarkButterfly
Comodo's Hero
*****
Offline Offline

Posts: 407


« Reply #13 on: August 29, 2008, 05:14:36 PM »

If your looking for virtualisation, you could look at sandboxie. If you want a full VM, the maybe virtualbox, both free. On the other hand, turn off javascript and activeX for all sites apart from those you trust.

The question is: are there any sites we should trust?

I mean, when someone sees security companies web sites getting hijacked, no big trust on trusting trustful sites.
See where I want to get?

Always be suspicious... but not paranoid... Wink
Logged
jeremysbost
Malware Research Group
Comodo's Hero
*****
Offline Offline

Posts: 752


I'm the guide-maker. Please request a guide.


WWW
« Reply #14 on: September 17, 2008, 03:11:25 PM »

The answer is Comodo Firewall v3!

Melih

Is it part of D+ or the Firewall?
Logged

I'm the guide-maker! Please request (using a PM) a guide about CFP or D+ or any other Comodo product.



Vista Home Premium, X32,
Tags:
Pages: [1] 2 Go Up Print 
« previous next »
Jump to:  

SSL Firewall
Page created in -0.695 seconds with 19 queries.
Powered by SMF 1.1.7 | SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by 7dana.com