Post Reply 
Browser Security Pack
Aug. 18, 2005, 08:53 PM
Post: #301
 
Version 4.37 is Released!

Last Updated: August 18th, 2005 - 5:54 PM EST

What's New?

Quote:[-Version 4.37-]

-Modified (IE: Remove Problematic CLASSIDs)
http://isc.sans.org/diary.php?date=2005-08-18

http://www.prxbx.com/forums/viewtopic.php?p=1115#1115

Download here!

MD5: 90F2203F7122717B7396EFA5E263CC1D
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 18, 2005, 08:53 PM
Post: #302
 
Version 4.37 is Released!

Last Updated: August 18th, 2005 - 5:54 PM EST

What's New?

Quote:[-Version 4.37-]

-Modified (IE: Remove Problematic CLASSIDs)
http://isc.sans.org/diary.php?date=2005-08-18

http://www.prxbx.com/forums/viewtopic.php?p=1115#1115

Download here!

MD5: 90F2203F7122717B7396EFA5E263CC1D
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 19, 2005, 07:22 AM
Post: #303
 
I am wondering why the 'Javascript "charAt" Remover' code was included in the
"IE: Nullify Vulnerable Javascript Functions" filter? The charAt filter is still
in the security filter set as a separate general browser filter. If that filter
can apply to other browsers should it not remain as a general filter?
Would the list of locations for the information for the combined filters in the
"IE: Nullify" filter not still be helpful?

http://www.securityfocus.com/bid/8169/info/
http://www.securityfocus.com/bid/10473/info/
http://www.securityfocus.com/bid/10514/info/
http://www.greymagic.com/security/advisories/gm012-ie/
http://secunia.com/advisories/7364/
Add Thank You Quote this message in a reply
Aug. 19, 2005, 02:21 PM
Post: #304
 
I will release v4.38 today Wink

I have a driving lesson in a few minutes so I will be back and I'll try to see if there are any new exploits I can include in the next release.

Thanks Siamesecat Wink
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 19, 2005, 09:23 PM
Post: #305
 
Version 4.38 is Released!

Last Updated: August 19th, 2005 - 6:25 PM EST

What's New?

Quote:[-Version 4.38-]

-Removed (Javascript "charAt" Remover)
--Redundant (Already included in [IE: Nullify Vulnerable Javascript Functions])

http://www.prxbx.com/forums/viewtopic.php?p=1115#1115

Download here!

MD5: F6F5A70A8327B64A3FA69F7CB038DB51
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 20, 2005, 05:56 AM
Post: #306
 
Quote:-Removed (Javascript "charAt" Remover)
--Redundant (Already included in [IE: Nullify Vulnerable Javascript Functions])
Would it not have been better to do it the other way around? Why not keep the separate Javascript "charAt" Remover filter? Is it not applicable to Mozilla browsers or Opera?
Add Thank You Quote this message in a reply
Aug. 20, 2005, 04:50 PM
Post: #307
 
*slaps head*

I'm so stupid xD

I will fix it in v4.39, but I will try to include another exploit in it, so it might be a while (since there hasn't been any major exploit found since MSDDS.dll ActiveX.)

Thanks again Siamesecat. I don't know what I'd do without you Big Teeth
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 23, 2005, 08:21 PM
Post: #308
 
http://castlecops.com/f201-Kye_U_Proxomitron.html

Eyes Closed Smile
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 23, 2005, 11:42 PM
Post: #309
 
As always, thanks, Kye-U! Hail
Add Thank You Quote this message in a reply
Aug. 24, 2005, 08:11 AM
Post: #310
 
Congrats! Smile!
Add Thank You Quote this message in a reply
Aug. 24, 2005, 01:28 PM
Post: #311
 
Kye-U , keep up the great work ! Thanks . A while ago Sidke posted a site : http://bcheck.scanit.be/bcheck/index.php to check your vulnerability which I have used regularly . I get 0 for 40 tests using Firefox or IE . No apparent vulnerabilities . Now this is with Sidke's configuration without Kye-U's security filters . I am reluctant to add additional filters to Sidke's set if I do not need them ; since from previous experience , there seem to be bloating and or conflicts , slowing the system down . Sidke's config seems perfect out of the box . I haven't tried the tests with Proxo bypassed but I'm sure I'd fail most of the tests . Thanks for your and other input on this .
Add Thank You Quote this message in a reply
Aug. 28, 2005, 01:00 AM
Post: #312
 
Version 4.39 is Released!

Last Updated: August 27th, 2005 - 10:01 PM EST

What's New?

Quote:[-Version 4.39-]

-Added (Javascript "charAt" Remover [Kye-U])

-Added (IE: Remove Suspicious IFRAME (Possible Buffer Overflow Exploit) [Kye-U])
http://secunia.com/advisories/12959/

-Modified (IE: Nullify Vulnerable Javascript Functions)
--Removed (Javascript "charAt" Remover) Match and made it its own standalone filter (as it applied to all browsers)

http://www.prxbx.com/forums/viewtopic.php?p=1115#1115

Download here!

MD5: 7BE6F84A679066882B6619CFA010C978
Visit this user's website
Add Thank You Quote this message in a reply
Aug. 30, 2005, 12:01 PM
Post: #313
 
Gee whiz , I thought I would have gotten a response to my question which I posted on the 24th . I guess I answered it myself . Sad
Add Thank You Quote this message in a reply
Aug. 30, 2005, 04:22 PM
Post: #314
 
Ralph Wrote:Gee whiz , I thought I would have gotten a response to my question which I posted on the 24th . I guess I answered it myself . Sad
Sorry Ralph,

I don't use the Browser Security Pack - doesn't mean it doesn't have its place, Grypen-followers tend to appreciate the BSP...

As a sidki-follower and due to various "test" sites as mentioned above, I feel I myself can do without the BSP...
Add Thank You Quote this message in a reply
Aug. 30, 2005, 05:04 PM
Post: #315
 
Ralph Wrote:Kye-U , keep up the great work ! Thanks . A while ago Sidke posted a site : http://bcheck.scanit.be/bcheck/index.php to check your vulnerability which I have used regularly . I get 0 for 40 tests using Firefox or IE . No apparent vulnerabilities . Now this is with Sidke's configuration without Kye-U's security filters . I am reluctant to add additional filters to Sidke's set if I do not need them ; since from previous experience , there seem to be bloating and or conflicts , slowing the system down . Sidke's config seems perfect out of the box . I haven't tried the tests with Proxo bypassed but I'm sure I'd fail most of the tests . Thanks for your and other input on this .

Ralph, I don't see any questions in this Sad

(If I did see one, I would answer it Wink )

Sidki does do a good job on his config, and I'd be surprised if you didn't need to have my pack installed to block most of the exploits out there. Smile!
Visit this user's website
Add Thank You Quote this message in a reply
Post Reply 


Forum Jump: