<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>insanesecurity &#187; IE</title>
	<atom:link href="http://insanesecurity.info/blog/tag/ie/feed" rel="self" type="application/rss+xml" />
	<link>http://insanesecurity.info/blog</link>
	<description>security through a distorted eye</description>
	<lastBuildDate>Thu, 25 Feb 2010 22:31:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Browser Security Handbook</title>
		<link>http://insanesecurity.info/blog/browser-security-handbook</link>
		<comments>http://insanesecurity.info/blog/browser-security-handbook#comments</comments>
		<pubDate>Wed, 24 Jun 2009 17:02:07 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Books]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Opera]]></category>
		<category><![CDATA[Safari]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/?p=81</guid>
		<description><![CDATA[Recently after moving the blog to this self-hosted platform I decided to cleanup a bit my feed reader&#8230; you know, add some, delete some. And while searching for blogs to subscribe to I came across Michal Zalewski&#8217;s website searching for a feed. Unfortunately didn&#8217;t find a feed, but did find his newest project&#8230; The Browser [...]]]></description>
			<content:encoded><![CDATA[<p>Recently after moving the blog to this self-hosted platform I decided to cleanup a bit my feed reader&#8230; you know, add some, delete some. And while searching for blogs to subscribe to I came across <a href="http://lcamtuf.coredump.cx/">Michal Zalewski&#8217;s website</a> searching for a feed. Unfortunately didn&#8217;t find a feed, but did find his newest project&#8230;</p>
<p><span id="more-81"></span></p>
<p>
The <a href="http://code.google.com/p/browsersec/wiki/Main">Browser Security Handbook</a> is a free online book covering information related to web browsers like: IE6, IE7, FF2, FF3, Opera, Chrome, Safari and Android. The book covers material from url schemas, http protocol, DOM, up to same-origin policy.</p>
<p>Being a comprehensive document about browsers it&#8217;s a book that I would recommend security testers, as well to website developers. I wouldn&#8217;t be amazed if it where a reference lecture upon browsers in the years to follow.</p>
<p>If you are here you might as well check other published material from Michal Zalewski: <a href="http://lcamtuf.coredump.cx/worm.txt">&#8220;I don&#8217;t think I really love you&#8221;</a> (first Zalewski material I ever read), <a href="http://lcamtuf.coredump.cx/tmp_paper.txt">Absence of fd-based unlink()</a>, <a href="http://lcamtuf.coredump.cx/signals.txt">&#8220;Delivering signals for Fun and Profit&#8221;</a>, <a href="http://artofhacking.com/files/phrack/phrack57/P57-0X0A.TXT">Rise of the Robots</a>, <a href="http://lcamtuf.coredump.cx/juggling_with_packets.txt">Juggling with packets</a>, <a href="http://lcamtuf.coredump.cx/ipfrag.txt">IP Fragmentation</a> and <a href="http://lcamtuf.coredump.cx/strikeout/">&#8220;Strike that out, SAM&#8221;</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/browser-security-handbook/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Exploit Shield</title>
		<link>http://insanesecurity.info/blog/exploit-shield</link>
		<comments>http://insanesecurity.info/blog/exploit-shield#comments</comments>
		<pubDate>Wed, 24 Jun 2009 16:35:20 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
				<category><![CDATA[Toolbox]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://insanesecurity.info/blog/exploit-shield</guid>
		<description><![CDATA[An exploit (from the same word in the French language, meaning &#8220;achievement&#8221;, or &#8220;accomplishment&#8221;) is a piece of software, a chunk of data, or sequence of commands that take advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software, hardware, or something electronic (usually computerized). [...]]]></description>
			<content:encoded><![CDATA[<p>An exploit (from the same word in the French language, meaning &#8220;achievement&#8221;, or &#8220;accomplishment&#8221;) is a piece of software, a chunk of data, or sequence of commands that take advantage of a bug, glitch or vulnerability in order to cause unintended or unanticipated behavior to occur on computer software, hardware, or something electronic (usually computerized). This frequently includes such things as violently gaining control of a computer system or allowing privilege escalation or a denial of service attack. (<a href="http://en.wikipedia.org/wiki/Exploit_(computer_security)">Wikipedia</a>)</p>
<p><span id="more-62"></span></p>
<p>
Eleven days ago Microsoft did a disclosure on the <a href="http://www.microsoft.com/technet/security/Bulletin/MS09-002.mspx">MS09-002</a>. Seven days later we already had a <a href="http://isc.sans.org/diary.html?storyid=5884">proof of concept</a> that was used in the wild, and today having even the <a href="http://thewifihack.com/blog/?p=343">Metasploit exploit</a>.</p>
<p>Eleven days have passed, did you patch the vulnerability? Most of the users will not have it patched too soon, even if it comes with the automatic updates. Many just simply have automatic updates turned off. Even so, there are some patches which take a long time to be released, for example the <a href="http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx">MS08-078</a> patch did take a while to be released.<br />
<script type="text/javascript"><!--
google_ad_client = "pub-4879499347590889";
/* 468x60, created 1/22/09 */
google_ad_slot = "0361207255";
google_ad_width = 468;
google_ad_height = 60;
// --></script></p>
<p><script src="http://pagead2.googlesyndication.com/pagead/show_ads.js" type="text/javascript"></script></p>
<p>And here comes in <a href="http://www.f-secure.com/weblog/archives/00001607.html">Exploit Shield</a> an application which will protect your from browser based exploits (either IE or Firefox), but don&#8217;t over trust it, as soon as a patch comes out you should fix the vulnerability.</p>
<blockquote><p>Exploit Shield is designed to shield Web browsers between the development of an exploit and the release of the vendor&#8217;s patch.</p>
</blockquote>
<p>Exploit Shield posses the following functionality: Zero Day Defense, Patch-Equivalent Protection, Proactive Measures, Protects Against All Websites and Automatic Feedback.</p>
<p>But does it work? Of course it does, check out the <a href="http://www.f-secure.com/weblog/archives/00001608.html">detection of a MS09-002 based exploit</a> which was catched by the heuristics incorporated in the software.</p>
<p>It&#8217;s also a program that would be useful when researching/coding such exploits, although the automatic submission should be disabled in that case (*grin*).</p>
<p>If you haven&#8217;t got it yet, you can download it from <a href="http://support.f-secure.com/beta/estp/estp.shtml">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.info/blog/exploit-shield/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
