<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>Web Hosting Geeks&#039; Blog &#187; web browser</title> <atom:link href="http://webhostinggeeks.com/blog/tag/web-browser/feed/" rel="self" type="application/rss+xml" /><link>http://webhostinggeeks.com/blog</link> <description>Web Hosting Industry News, Latest Trends, and Analyses.</description> <lastBuildDate>Thu, 24 May 2012 11:11:11 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <item><title>Google Chrome Browser Cracked</title><link>http://webhostinggeeks.com/blog/google-chrome-browser-cracked/</link> <comments>http://webhostinggeeks.com/blog/google-chrome-browser-cracked/#comments</comments> <pubDate>Mon, 30 May 2011 19:29:36 +0000</pubDate> <dc:creator>Art</dc:creator> <category><![CDATA[Security Issues]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[exploit]]></category> <category><![CDATA[Google]]></category> <category><![CDATA[hackers]]></category> <category><![CDATA[Vupen Security]]></category> <category><![CDATA[web browser]]></category><guid
isPermaLink="false">http://webhostinggeeks.com/blog/?p=1621</guid> <description><![CDATA[Vupen Security, a group specializing in vulnerability research, claims to have broken through the Google Chrome browser as well as the sandbox thus denting claims regarding the security of the browser. A video was recently released on Vupen’s website displaying the exploit from Google Chrome v11.0.696.65 using Microsoft Windows 7 SP1 (x64). The exploit is [...]]]></description> <content:encoded><![CDATA[<p>Vupen Security, a group specializing in vulnerability research, claims to have broken through the Google Chrome browser as well as the sandbox thus denting claims regarding the security of the browser. A video was recently released on Vupen’s website displaying the exploit from Google Chrome v11.0.696.65 using Microsoft Windows 7 SP1 (x64). The exploit is also effective on Google Chrome versions 11.x and 12.x</p><p><strong>The Exploit</strong></p><p>A user visiting the page is tricked into thinking they are at the correct web page that hosts the exploit which executes a variety of actions that end in downloading the Calculator from a remote location to externally launch it from Google Sandbox.</p><p><strong>Technical Details</strong></p><p>According to Vupen, the exact details of the breach including the code have not been publicly disclosed and will only be shared with their government customers to prove the effectiveness of their services. The exploit has been noted as one of the most sophisticated codes as it completely bypasses all security features such as ASLR/DEP/Sandbox.</p><p>Also, the vulnerability does not crash following the execution of the exploit and it relies on zero-day vulnerabilities found by Vupen Security while working within a Windows system. Chrome is said to be one of the most secure sandboxes in the industry. Vupen is the first to find a reliable method of executing code on a default installation regardless of the security measures.</p><p><strong>Chrome Security Features</strong></p><p>Chrome was developed with advanced security technologies like Safe Browsing, auto updates and sandboxing to protect its users from malicious activities. Therefore, the browser shows the user a warning message before they visit the website. Meanwhile, the sandbox feature adds protection by eliminating web pages that leave malicious programs on a local computer while monitoring web activities.</p><p><strong>The Vupen Team</strong></p><p>Furthermore, the software analyzes and patches known flaws and other vulnerabilities. The Vupen Security team is dedicated to uncovering new vulnerabilities across widely used software to assist vendors with the elimination of vulnerabilities resulting in an airtight software program. However, since Vupen is under contract with the vendor, they are never allowed to release the exact technical details found with the security exploit.</p><p>Although it was difficult, cracking the Google Chrome web browser will significantly help the company improve security to make it almost impossible for any hacker to develop an exploit. In this situation, Vupen has definitely done their job well by helping the largest search engine company in the world.</p><h3  class="related_post_title">Related posts:</h3><ul
class="related_post"><li><a
href="http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/" title="Browsers Aiding in Website Attacks ">Browsers Aiding in Website Attacks </a></li><li><a
href="http://webhostinggeeks.com/blog/web-browsers-comparison/" title="Comparing The Best Web Browsers ">Comparing The Best Web Browsers </a></li><li><a
href="http://webhostinggeeks.com/blog/protecting-your-site-from-ddos-attacks/" title="Protecting Your Site from DDoS Attacks ">Protecting Your Site from DDoS Attacks </a></li><li><a
href="http://webhostinggeeks.com/blog/healthy-website-security-practices/" title="Healthy Website Security Practices ">Healthy Website Security Practices </a></li><li><a
href="http://webhostinggeeks.com/blog/five-simple-website-safety-tips/" title="Five Simple Website Safety Tips ">Five Simple Website Safety Tips </a></li><li><a
href="http://webhostinggeeks.com/blog/is-cloud-computing-behind-the-twitter-hack/" title="Is Cloud Computing Behind the Twitter Hack?">Is Cloud Computing Behind the Twitter Hack?</a></li><li><a
href="http://webhostinggeeks.com/blog/web-hosting-security-at-risk-are-you/" title="Web Hosting Security at Risk: Are you?">Web Hosting Security at Risk: Are you?</a></li><li><a
href="http://webhostinggeeks.com/blog/protect-your-site-from-maliciously-activities/" title="Protect Your Site From Maliciously Activities ">Protect Your Site From Maliciously Activities </a></li><li><a
href="http://webhostinggeeks.com/blog/fighting-back-against-website-attacks/" title="Fighting Back Against Website Attacks">Fighting Back Against Website Attacks</a></li><li><a
href="http://webhostinggeeks.com/blog/visual-website-optimizer/" title="Visual Website Optimizer: A Better Way to Perform A/B Testing">Visual Website Optimizer: A Better Way to Perform A/B Testing</a></li></ul>]]></content:encoded> <wfw:commentRss>http://webhostinggeeks.com/blog/google-chrome-browser-cracked/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Browsers Aiding in Website Attacks</title><link>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/</link> <comments>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/#comments</comments> <pubDate>Mon, 29 Dec 2008 16:00:45 +0000</pubDate> <dc:creator>Art</dc:creator> <category><![CDATA[Security Issues]]></category> <category><![CDATA[Active X]]></category> <category><![CDATA[Chrome]]></category> <category><![CDATA[cross site scripting]]></category> <category><![CDATA[exploits]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[hackers]]></category> <category><![CDATA[Javascript]]></category> <category><![CDATA[Opera]]></category> <category><![CDATA[Safari]]></category> <category><![CDATA[SQL injection]]></category> <category><![CDATA[web browser]]></category> <category><![CDATA[website attack]]></category><guid
isPermaLink="false">http://webhostinggeeks.com/blog/?p=133</guid> <description><![CDATA[Website attacks are on the rise with intruders using an array of hacking techniques from cross site scripting to SQL injection.  Although careless development and insecure applications play a major role in a site&#8217;s vulnerability, the typical web browser is a contributing factor as well. Despite the fact that several improvements have been made, none [...]]]></description> <content:encoded><![CDATA[<p>Website attacks are on the rise with intruders using an array of hacking techniques from cross site scripting to SQL injection.  Although careless development and insecure applications play a major role in a site&#8217;s vulnerability, the typical web browser is a contributing factor as well.</p><p>Despite the fact that several improvements have been made, none of the top web browsers are completely secure.  Because of this, many web security experts are projecting that website attacks will continue to be an issue.  The combination of enhanced functionality and the lack of adequate security implementations have left a number of browsers vulnerable to sophisticated attacks.  Some researchers are saying that the increasing number of exploits is the direct result of Web 2.0 technologies and advanced web hosting features.</p><p><strong>Evolution in Technology Opens Doors to Further Threats</strong></p><p>Things were fairly innocent in the early days of the internet when static pages were prevalent, before technologies such as JavaScript and Active X came into play.  Today&#8217;s World Wide Web is dominated by dynamic web-based applications and complex server-side scripting languages, factors that enable browsers to be used in various ways to exploit websites.  Gary McGraw of Cigital, a software security company, agrees that these feature-rich designs have made browsers far less secure, stating that they are structured more like complete operating systems.</p><p>This past September Google released Chrome, its new web browser which was immediately faced with stiff competition in the form of Microsoft Internet Explorer, Mozilla Firefox, Apple Safari and Opera.  While internet users have a wide variety of browsers to choose from, the options are still limited in terms of security, including Chrome.  Experts contend that the browser war of who can out do one another in the feature department is what ultimately leads to these security vulnerabilities.</p><p>Though quite serious, the security issues associated with today&#8217;s popular web browsers are not attributed to a lack of effort.  Some say that developers are doing all they can but when considering the fact that website attacks such as cross site scripting and cross site request forgery are typically the result of design, these flaws tend to be much harder to fix than bugs found in software code.  Observers suggest that the vulnerabilities are not going to disappear entirely but do stress that browser developers can do more to enhance security.</p><p>In general, development teams only have a little time to address browser vulnerabilities before the hacker community is able to discover them.  Developers are being encouraged to practice browser security just like those who make other software products.  This is extremely important as the major web browsers literally have hundred of millions of users.  One solid approach towards website security is standardized authentication, something that would need to be addressed by system administrators.  Another recommendation is for browser developers to design products that alert users when they are being directed to intranet zones such as localhost or RFC1918 as attackers are increasingly targeting internal devices.  Security firms have also predicted that the manner in which data is handled when requests are made between a browser and website should play a critical part in future designs.</p><h3  class="related_post_title">Related posts:</h3><ul
class="related_post"><li><a
href="http://webhostinggeeks.com/blog/web-browsers-comparison/" title="Comparing The Best Web Browsers ">Comparing The Best Web Browsers </a></li><li><a
href="http://webhostinggeeks.com/blog/google-chrome-browser-cracked/" title="Google Chrome Browser Cracked">Google Chrome Browser Cracked</a></li><li><a
href="http://webhostinggeeks.com/blog/authentication-hacking-is-your-site-vulnerable/" title="Authentication Hacking: Is Your Site Vulnerable? ">Authentication Hacking: Is Your Site Vulnerable? </a></li><li><a
href="http://webhostinggeeks.com/blog/major-threats-to-business-website-security/" title="Major Threats to Business Website Security ">Major Threats to Business Website Security </a></li><li><a
href="http://webhostinggeeks.com/blog/how-to-find-secure-shared-hosting/" title="How to Find Secure Shared Hosting ">How to Find Secure Shared Hosting </a></li><li><a
href="http://webhostinggeeks.com/blog/the-vulnerability-of-ajax-applications/" title="The Vulnerability of AJAX Applications">The Vulnerability of AJAX Applications</a></li><li><a
href="http://webhostinggeeks.com/blog/cross-site-scripting-the-underestimated-website-attack/" title="Cross Site Scripting: The Underestimated Website Attack">Cross Site Scripting: The Underestimated Website Attack</a></li><li><a
href="http://webhostinggeeks.com/blog/malware-attacks-on-the-rise/" title="Malware Attacks on the Rise">Malware Attacks on the Rise</a></li><li><a
href="http://webhostinggeeks.com/blog/google-dart-new-language-arrives/" title="Google Dart – Ready or not, a new Language Arrives">Google Dart – Ready or not, a new Language Arrives</a></li><li><a
href="http://webhostinggeeks.com/blog/godaddy-account-hack/" title="What the New User can Learn from the GoDaddy Account Hack">What the New User can Learn from the GoDaddy Account Hack</a></li></ul>]]></content:encoded> <wfw:commentRss>http://webhostinggeeks.com/blog/browsers-aiding-in-website-attacks/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Content Delivery Network via Amazon Web Services: CloudFront: d3pnguju6g7vh.cloudfront.net

Served from: webhostinggeeks.com @ 2012-05-25 21:03:49 -->
