is my system safe ?

Jul 26, 2006 67 Replies

But Mailwasher doesn't support SSL (or didn't when I checked last time). Every time Mailwasher connects to your mailbox, your username and password are transmitted over the Internet unencrypted, and at least From and Subject are transmitted back, equally unencrypted.

If you use a good mail client, it doesn't matter wether any virus gets through - you'd have to deliberately execute the virus to do any harm.

Juergen Nieveler

Please show me, I'll see. There are several serious web pages demonstrating exploits, f.e.:

formatting link
(German)
formatting link
Wolfgang

Not only: Internet Explorer is the explorer of the internet, is there anything beyond (read the so called "internet options" :-/ of the IE a.s.o.)?

Wolfgang

Is there an actual list of them? Thor Larholms's is closed, umbrella's?

asks Wolfgang

formatting link
No, this list shows only the fixed vulnerabilities. It's a problem of the non disclosure politic of the developers. But there are only a few of known unpatched vulnerabilities in the wild.

Wolfgang

Again:

  1. This exploited flaws are already patched at the time of exploitation.

  1. McAfee ~ 0.75 * Symantec

Yes, I have to update my lists again.

A good starting point today is

formatting link
:-)

A browser works with content. You can browse networks, applications, resources, ... and a browser designed for processing untrustworthy HTML content is usually called a webbrowser.

This is an HTML based application.

Well, IE hardly understands anything but a very small subset of HTML and has certain mechanisms that are inherently insecure on untrusted environments (like the internet).

So far, we have:

- 60+ unpatched vulnerabilities

- non-working cross-domain security

- impossibly to disable ActiveX behaviour

- very lousy parsing and rendering of HTML content

This makes it totally unsuitable and dangerous to (mis)use as a webbrowser.

Nah, it's a documented design.

This could happen to every website, even when driven by competent people

- as you simply don't have much, if any control about the advertisement resell business. As we've seen, a seemingly trustworthy company was founded, bought some ad space, but it's exploit on there, infected some

10000 machines and then was shut down.

This is an inherent fact and has nothing to do with internet safety.

These are all data. Beside that, it seems like some simply HTML tags and/or CSS description is already sufficient to make IE misbehave.

And ActiveX cannot be fully disabled.

Yes. I read the German version of

formatting link
Wolfgang

The point is that there were 50+ vulnerabilities between Firefox 1.0 and

1.5.0.5 that existed but were fixed. How many vulnerabilites still exist in 1.5.0.5 that will get fixed in 2.0? How many will exist in 2.0? You just don't know until they're exploited and/or fixed.

And for IE, you have 50+ vulnerabilities known with Microsoft refusing to submit patches, and there are some inherent design decisions (you may call them flaws) that are unfixable without a complete rewrite.

I guess you understand the difference between random and systematic errors.

I'm not disputing the fact that IE has vulnerabilities (because we all know it does and MS takes its time fixing them), I'm disputing that Firefox is so "internet-safe" as people claim it to be. No browser can be 100% "internet-safe".

Yeah, I know, but again: Firefox isn't as safe as you claim it to be. They have also bugs/flaw/vulnerabilities.

btw: I'm using Firefox most of the time and IE when Firefox can't handle. I admit that Firefox is more safe than IE, but I don't think it's internet-proof.

I don't care what you think of McAfee: I don't use their products.

Peter

More than 3 years?

Maybe you're still unaware of what "internet-safe" means: not having systematic errors, being theoretically secure and only falling at random errors. Get your updates in time and you've achieved the maximum possible.

The difference is what are systematic errors in IE: side-effects in ActiveX implementation, non-working cross-domain security model, non-working policies on graphical contexts and MIME type confusion. Things you can't simply patch away, things that require a rewrite.

I've never claimed that it doesn't.

Talking about safety of IE is like talking about safety of granting remote shells...

Actually it's pretty internet-proof when carefully analyzing the conditions and impacts of previous vulnerabilities, and taking into account how a pro-active security configuration could limit impact.

But you should know who you cite. The claims of McAfee aren't worth any consideration.

Here is no difference between the policies of the developer (or security) teams of mozilla.org and microsoft.com f.e.

Yes, I can read bugzilla.mozilla.org/show_bug.cgi?... or

formatting link
f.e.

How many of them were exploitable in the wild and how long did it took the developers to fix them after they were known for all?

How many of them will be known before they'll get fixed?

I wrote above: It's due to the non disclosure policy and it's not good.

But have a look about the design flaw of the IE (Thor Larholm (who also actually found some of the new vulnerabilities of firefox) posted these problems several years before) Sebastian wrote about in his answer and how long did it took the developers to fix them? There are poles apart IMO.

Wolfgang

Sebastian Gottschalk:

source browser too, McAfee said.

Is it true or not, regardless of who said it?

Geo

The ShellExecute MIME type confusion problem was turned into a group policy with explicit blacklisting (rather than the required whitelisting) solely on Windows Server 2003. The JavaScript domain security has a hidden policy, also just blacklisting instead of required whitelisting.

Of course, the real issues behind were not fixed, apart that Microsoft promissed a nearby complete rewrite at least two times (IE6SP2 and IE7).

source browser too, McAfee said.

It is true, but it is a wrong conclusion. A flaw doesn't have a nearby great effect if it has already been fixed and delivered with an automatic update functionality. And it has no relation to yet unfixed flaws and unfixable design flaws.

BTW, you're a dirty address faker.

formatting link
> There's nothing about Firefox or Opera behind this link, but again

As I said, nothing about Firefox or Opera. At least nothing concrete.

Yours, VB.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required