Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: New IE flaw and exploit sites/migration to non-MS browser |
|---|---|
| Date: | Mon, 03 Apr 2006 09:10:17 +1000 |
In agreement with you there--in some departments here, we have a deny all then only add in sites which are required, using GPO and by setting a proxy of the loopback. Works quite nicely. The downside is what about sites we don't know they'll need to link to on a day to day basis. Business use is business use is business use. I chant this like a mantra to them all. So I do agree with you when you say that if the browser is locked down properly to begin with then it is highly unlikely to cause problems. However, as many of my security bulletins also get taken up by my users for their home use, I find that certain things are harder for me to control-and education is key. As for certain things not working with Firefox(I use it myself)-I have found the IE tab plugin does the trick pretty much all of the time. It masquerades as IE when needed. (In fact, I haven't come across a site that it can't work with). However, I don't think it mimics the flaws-though I could be wrong. Anyone else got any info on this? I also agree with the point of firefox now becoming the new target for exploiters to use. The more people that use it, the more of a target it becomes. Regards Murad Talukdar --------------------------------------------------------------------------- ---------------------------------------------------------------------------
| Previous by Date: | Re: New IE flaw and exploit sites/migration to non-MS browser, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] |
|---|---|
| Next by Date: | Re: New IE flaw and exploit sites/migration to non-MS browser, Matt . Carpenter |
| Previous by Thread: | Re: New IE flaw and exploit sites/migration to non-MS browser, Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] |
| Next by Thread: | Re: New IE flaw and exploit sites/migration to non-MS browser, Thor (Hammer of God) |
| Indexes: | [Date] [Thread] [Top] [All Lists] |