Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Microsoft
[Top] [All Lists]

RE: New IE flaw and exploit sites/migration to non-MS browser

Subject: RE: New IE flaw and exploit sites/migration to non-MS browser
Date: Mon, 03 Apr 2006 09:10:17 +1000
In agreement with you there--in some departments here, we have a deny all
then only add in sites which are required, using GPO and by setting a proxy
of the loopback. Works quite nicely. The downside is what about sites we
don't know they'll need to link to on a day to day basis. Business use is
business use is business use. I chant this like a mantra to them all.

So I do agree with you when you say that if the browser is locked down
properly to begin with then it is highly unlikely to cause problems.
However, as many of my security bulletins also get taken up by my users for
their home use, I find that certain things are harder for me to control-and
education is key.
As for certain things not working with Firefox(I use it myself)-I have found
the IE tab plugin does the trick pretty much all of the time. It masquerades
as IE when needed. (In fact, I haven't come across a site that it can't work
with). However, I don't think it mimics the flaws-though I could be wrong.
Anyone else got any info on this?

I also agree with the point of firefox now becoming the new target for
exploiters to use. The more people that use it, the more of a target it
becomes.
Regards
Murad Talukdar


 



---------------------------------------------------------------------------
---------------------------------------------------------------------------

<Prev in Thread] Current Thread [Next in Thread>