Firefox Plug-In Updated To Fight Clickjacking Attacks

October 14, 2008

Mozilla is doing its part in the battle against clickjacking. The open-source company is offering an updated plug-in for the Firefox browser that blocks what security researchers call one of the most dangerous problems on the Web.

Clickjacking occurs when a person browsing a Web site clicks on an invisible link that leads them to a malicious site without their knowledge. Some never realize it even happened. A design feature in HTML that lets Web sites embed content from other sites makes it possible, which means nearly everybody is vulnerable.

The Firefox add-on, NoScript, is a well-known security plug-in. It is used to block all sorts of content types within Web pages. It is not a security scanner in the sense that it does not scan content with any form of signature database to look for specific known threats. Rather, it is a tool that enables you to block certain types of content. An update to NoScript includes a feature dubbed ClearClick to combat clickjacking. Read more

Hackers using fake YouTube pages to attack computers

October 14, 2008

Computer security specialists warn that hackers are using fake YouTube pages to trick people into opening their machines to diabolical software. A deceptive YouTube attack evolving as it spreads on the Internet is part of a growing trend of hackers to prowl popular online social networking communities in which people trustingly share web links and mini-programs.

“We are seeing tools like this not just for YouTube, but for MySpace, Facebook, America Online instant messaging …,” Trend Micro software threat research manager Jamz Yaneza told AFP on Thursday. “All the various social networking sites have been hit with some page or another.”

Hackers using the YouTube attack send people links to what are said to be must-see snippets at the Google-owned video-sharing website. The links, instead, connect to convincingly realistic replicas of YouTube pages and tell people that a software update is needed to view a requested video. Read more

Opera Lands O2 Germany Mobile Deal

August 10, 2008

Opera Lands O2 Germany Mobile Deal
Opera have been receiving more success in placing their Web browsing software on different platforms, particularly mobile phones.

The latest win is a big one.
O2 in Germany will be exposing millions of their users to Opera Mini, which will be available both pre-installed on handsets and available over-the-air, pretty good growth from 2004 when they were pleased to announce one million downloads. Read more

Firefox 3 Vulnerability Rains on Mozilla Download Parade

June 21, 2008

Firefox 3 Vulnerability Rains on Mozilla Download ParadeFor all the exaggerations about the number of people who downloaded 3 Mozilla’s Firefox open source browser on a five-hour, now there is exaggeration about how long it takes security researchers to disclose a flaw.

Five hours after Mozilla officially released the long-awaited update, turning point confirmed a vulnerability. Point of inflection of the Zero Day initiative program received notification about a critical vulnerability affecting both Firefox Firefox 2 and 3.

“We have verified the vulnerability in our laboratory, it was purchased by researchers, then promptly reported the vulnerability to the Mozilla security team shortly after,” turning point wrote in his blog Digital Vaccine Laboratories. Read more

Next Page »