Re: [opensuse] OpenSuse 11



On Monday 11 February 2008 13:11, Wolfgang Woehl wrote:
... For example all of web2.0 is one huge
stress-test suite for a browser infrastructure. ...

This is true. It is an entirely different class of potential
vulnerabilities and exploits. Many of them are of the cross-site
scripting variety or injection exploits.

But these are all fundamentally different in their means of execution
and the locus of vulnerability. A browser that is 100% secure from
buffer-overflow exploits including those in any plug-ins or other
dynamically linked extensions and which has a perfect JavaScript
implementation including the browser sandbox model can still expose one
to these attacks.

It is also the case that many of these vulnerabilities are equally
present on Linux and Windows, since they originate in poorly crafted
Web applications (either on the server side or in client-side
JavaScript). There is virtually nothing an end user can do to protect
against such exploits other than refrain from using that class of
services (and that class includes all sorts of today's shiny new fun
stuff on the Web, from Amazon.com and eBay to FaceBook, MySpace and
Flickr and more).

If I read between your lines to say "we ain't seen the half of the
catastrophes Web 2.0 software will ultimately cause," I'm afraid you're
right.


...

Wolfgang


Randall Schulz
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: BIND update?
    ... ask to resolve www.google.com, the answer does not mean "www.google.com is on the network at 74.125.19.104." ... Yes, yes, DNS makes no security guarantees, it's always been vulnerable, this is old old news. ... what's at issue is that you're choosing to let unknown and untrusted sites inject arbitrary data into your web browser. ... check old CERT advisories, attackers have been exploiting DNS cache vulnerabilities in home/soho routers/WAPs/firewalls for a while now. ...
    (FreeBSD-Security)
  • Re: Just venting (totally OT)
    ... If you can point out better free anti virus, firewall, anti ... Malware authors write their nasties to exploit vulnerabilities in MS IE ... Using your logic if Opera had many more vulnerabilities than IE the bad guys would write their nasties to exploit Opera instead of focusing on IE even though Opera has a very small % of the browser market. ...
    (uk.people.support.depression)
  • Re: Internet Explorer has been hijacked by "About:Blank"
    ... less bug-riddled browser and abandon IE to the ... Because you cannot abandon it completely and although there are "less ... found one browser that blocks all popups or all spyware/adware/malware yet - ... getting attacked and showing its true vulnerabilities. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • LevCGI.coms NetPad 1.0.2 multiple vulnerabilities
    ... Levcgi.coms NetPad 1.0.2 Multiple Vulnerabilities Advisory ... Easy to install and use text editor for your web browser! ... Remote Command Execution Exploit: ...
    (Bugtraq)