Cross-Site Scripting (XSS) attacks have been a scourge on the Web, including well-known and popular websites. Mozilla has the last year on a technology for these attacks to stop: Content Security Policy
Cross-site scripting attacks are possible because all browsers JavaScript code and other content on a webpage in the same security context execution. The Content Security Policy (CSP) Mozilla provides a mechanism for sites to tell the browser what content is legitimate. Any script that is not accepted by the website, is blocked by the browser.
Mozilla's proposal requires that all JavaScript on a web page to external files to be moved, CSP can not be distinguished from legitimate scripts injected or modified JavaScript code in the page. Inline scripts, Javascript urls and HTML attributes that will handle events CSP therefore ignored. Only JavaScript code via a tag referring to a url on a host that has been approved by the site will be carried out. A protected website can also display a warning if a CSP XSS attack is blocked. A detailed description of the possibilities can be found in the CSP specification.
While websites should therefore be adapted to support CSP, it may happen in stages. The Mozilla Security Team has many sites and proved to be no site met that could not be adjusted. There will be documentation of best practices for a site to migrate to CSP. A reassurance that the policy is also fully backwards compatible: it has no effect on websites or web browsers that do not support the specification.
Jul 7, 2009
Mozilla wants to XSS vulnerabilities-block
Jul 2, 2009
Firefox 3.5 is available
This is the day for the Mozilla Foundation. After a few weeks late and online three Release Candidate, Firefox 3.5 final version is already available for all people or all languages.
Evolution of the major red panda, this new version is expected to meet the offensive of Microsoft with its Internet Explorer 8 or 4 Safari and Opera 10.
HTML5
The innovations announced are many (even if they concern primarily the engine of the browser and not necessarily the user functions):
Firefox 3.5 is expected to be faster with TraceMonkey JavaScript engine to boost including navigation and viewing of web 2.0 applications. The application will also propose a new HTML rendering engine (Gecko 1.9.1), again allowing more speed.
JSON and Web Workers will be supported natively. Furthermore, this new version will include audio and video tags from the HTML5.
From the user side, no significant changes noted on aesthetics but the integration of a navigation mode that will allow private surfing without leaving a trace (a function already present in IE8). Firefox 3.5 also offers "floating tabs" that allow you to switch easily from one window to another and managing favorite rewritten.
Jun 26, 2009
Thunderbird fix seven security flaws
The Mozilla developers have a new release of the Thunderbird e-mail delivered. It is a security update that resolves seven holes, most of them in the recent update of Firefox 3.0.11 are solved. Thunderbird 2.0.0.22 solves first an error on which the developers a large impact. When a user multipart / alternative e-mail sites with a text / enhanced component may Thunderbird crash, possibly operating as a result. Furthermore, there are four errors resolved with an average impact. There were two errors that JavaScript code on a page with higher privileges running. By default, Thunderbird is not vulnerable unless the user is an add-on installed and JavaScript enabled in e-mails has. Two other errors also abuse of JavaScript and the e-mail program to crash, potentially exploitable to. The last two errors have a low impact, according to Mozilla. Users who have configured a proxy and JavaScript enabled, so the victim of malicious code when an SSL connection. Finally, an Adobe Flash file via the view-source schema is loaded circumvent restrictions. But that only works if the user has plugins enabled in e-mails. The Mozilla developers advise users of Thunderbird strongly to upgrade to version 2.0.0.22. The release notes show a list of changes. In Thunderbird 1.5.0 is no longer supported and contains known security flaws version. A general council that the developers give is never JavaScript in Thunderbird on.
For more visit - Anti Spyware Support
Blog Archive
-
▼
2011
(23)
-
▼
September
(7)
- Computer Help on Web Browsers
- FireFox Crashes - Stop Crashes on FireFox for Good
- The Mobile Phone Browser, Mozilla Fennec
- How to Find My Download List on Mozilla FirefoxMoz...
- Reasons Why Firefox Mozilla Outweighs the Other We...
- Use Configuration Tweaks to Eliminate Mozilla Fire...
- Mozilla's New Security Tool
-
▼
September
(7)