Showing posts with label JavaScript. Show all posts
Showing posts with label JavaScript. Show all posts

Tuesday, March 15, 2011

Mac Security Status Report,
Part II

--
Internet Privacy Tools

One of the quietly astounding developments on the Mac platform is the arrival of terrific tools for establishing real privacy on the Internet. 2010 was rife with stories about how our privacy and even our identity was being stripped away by everyone from the Corporate Oligarchy to the legitimate US federal government. You'd think we were still living under the thrall of The Bush League Era, the assault on privacy has been so persistent and thorough. But serious tools for reestablishing US Constitution guaranteed privacy rights are here and they work. I would go so far as to say that 2010 established an Internet revolution of user privacy. I could not be more pleased.

Here are a few of the wonderful privacy tools and events from 2010. Keep in mind that much of this has been in the works for years and that there are more privacy tools on the way:

1) The Onion/Tor/Vidalia Project: The "Onion Router" project began back in 2002 as a method for concealing Internet user's identity and network activity, preventing surveillance and traffic analysis. Amazingly, the project was originally supported by the US Naval Research Laboratory. In 2004 the Electronic Frontier Foundation (EFF) began supporting the project, providing important guidance and solidification of the project's manifesto. In 2006 the Tor Project was established as a non-profit organization gathering and providing all financial support.

There are a number of FREE pieces of software that make use of the Tor Network. The prime program is Vidalia, aka 'Tor'. This is the software that runs the show. If you use Firefox, you will also need to install the Tor Button add-on. The next useful tool is a web page called "Check". It will verify for you whether you have Tor properly running on your system and web browser. Of side interest are a few other tools such as the Tor Browser Bundle (currently in beta for Mac OS X), and the Firefox add-on FoxyProxy.

Learning how to use Tor is difficult. Try to find someone who understands it to help you out. It is very much 'geek' level technology with meagre documentation and lots of obscure tricks required to use it to the fullest. With patience you'll find that Tor is astounding, effective and important for maintaining real Net Neutrality and user privacy.

In the near future I will be providing a long promised Mac specific article about how to use Tor for overcoming media marketing blackouts on the Internet. Keep an eye on my MacSmarticles blog. If you wish very hard, you may find me providing a series of articles about how to use Tor, translating geek-speak into intermediate Mac user lingo.

2) Ghostery: This is a FREE tracking cookie and web-bug tracking system. The tracker list is frequently updated and is very thorough from my experience. It runs on-the-fly killing off inter-website tracking systems. As you move from page to page it provides you with a small window listing all the detected and blocked tracking sources. As you use Ghostery you will seriously astounded at the amount of tracking/surveillance being perpetrated at you. Maybe you don't care. Maybe you're in marketing and you believe anti-tracking tools are evil. Personally, I love Ghostery and won't leave my home page without it.

Here is what the Ghostery developers have to say about it:
Be a web detective.

Ghostery is your window into the invisible web – tags, web bugs, pixels and beacons that are included on web pages in order to get an idea of your online behavior.

Ghostery tracks the trackers and gives you a roll-call of the ad networks, behavioral data providers, web publishers, and other companies interested in your activity...
There are THREE versions of Ghostery that work on Mac. One is the Firefox add-on. Another is the Safari extension. The last version is for Google Chrome. You can access all versions of Ghostery HERE.

3) Safari Cookies: This is an indispensable FREE add-on for Safari. It works great with Ghostery and provides further functionality. It has three main functions:
  • It allows you to create a website Cookie white list while killing off everything else.
  • It allows you to create a Flash Cookie white list while killing off everything else.
  • It allows you to create a website Database white list while killing off everything else. (I bet you didn't even know that websites could dump database information into your web browser! Very nasty).
Important: Do NOT use versions 1.6.4 - 1.6.7 of Safari Cookies. I've been in contact with the developer about their bugs and he most kindly has overcome them all with version 1.6.8 onwards. Now that it is working again, I cannot recommend Safari Cookies enough. Many thanks to SweetP Productions!

4) ECMAScript/JavaScript Prevention Tools: JavaScript is both a boon and a plague on the Internet. JavaScript allows such nifty things as Ajax coding on web pages. And yet, frequent readers of this blog know that I would very much enjoy JavaScript being erased from history and replaced with a scripting language that is actually and reliably SECURE. IOW: JavaScript is a gateway for malware and OS pwning. The blame for this catastrophic mess lies with three sources:
  1. Netscape, who invented Mocha, renamed LiveScript, the original name of 'JavaScript' before marketing-morons were allowed to license and inflict the utterly confusing and wrong 'Java' name into its title. (I despise marketing-morons. Have you noticed that? I worked with them every day for five long, stressful, infuriating years at Eastman Kodak, gawd help me. But I rant...).
  2. Microsoft, who inflicted their own typical insecure crapcode into JavaScript in the form of a monstrosity they call 'JScript'. Until recently, if you had attempted to resolve a web page that was designed using Microsoft's worst-in-class web design program 'FrontPage' you found the result to be a disaster. JScript was the main culprit. These days most web browsers comprehend JScript. But it remains a prime cause of hit-and-run website malware infections. Microsoft trolls will find this statement infuriating I exaggerate not. Just be glad that Mac users don't also have to contend with ActiveX, yet-another insecure Microsoft scripting language. (The Mozilla Project used to support Active-X but a couple years back banned it from any of their browsers for the benefit of their users and future generations of Internet users, amen).
  3. Adobe, who own what was once Macromedia, who perpetrated an insecure scripting language called ActionScript. It is mainly used in Flash and SWF embedded web pages, is one reason why Flash hacking is well known as a prime method for pwning Mac OS X. It is also one of the many reasons why Apple wisely banned Flash from their iDevices. It is also a prime source of malware for the Google Android OS.
Preventing this toxic brew of dangerous scripting languages from ruining your Internet browsing experience has become increasingly crutial. That is why I champion browser add-ons that let you choose when or whether to load JavaScript. Here are a few of the JavaScript prevention tools for Mac web browsers:

NoScript: This celebrated FREE Firefox add-on from InformAction is brilliant. It is frequently updated to keep up with the lastest in scripting crapcode. And it not only protects you from evil JavaScript! It also protects you from evil Java, Flash and other insecure web plug-in code that may be out to infect or pwn you. This add-on is one of the prime reasons to dump all your other web browsers and go 100% Firefox. I kid you not. Much as I like Safari, when I want first class web security, I use Firefox with both NoScript and Ghostery running. Get it. Use it. Enjoy!

JavaScript Blacklist: This is a rather meagre FREE Open Source add-on JavaScript killer for Safari. It allows you to block JavaScript from any web domain. Sadly, it is little more than proof-of-concept with a teeny-weeny 2.5 inch text box for inputting  your blocked website list. The best way to use it is to create your list in a text editor then copy and paste it into the teeny-weeny box. Whenever you want to add to your list, edit your text file then copy and paste again. There is no point in bothering to do any editing within JavaScript Blacklist itself. If you can deal with its shortcomings, this is a nice add-on for Safari fans like myself.

If you're ambitious, there are places to find lists of websites know to be infected with dangerous JavaScript. Ideally you could hack together a list from NoScript. But you'll find the task arduous. Don't bother.

5) Open Wi-Fi Router Defense Tools:

HTTPS Everywhere

This is a Firefox extension/add-on that specifically counters the hackware Firesheep extension/add-on. You can read about Firesheep here:

Firesheep

The general concept of this hacker war is that every website must stop using mere http connections and move over to https, SSL encrypted connections. HTTPS forces on SSL at websites exploited by Firesheep that are known to offer it.

6) Evercookie Defense Tools:

The 'Evercookie' is a concept developed this past year that threatens even the most obsessive of personal privacy web surfers. You can read about it here:

Evercookie

The basic concept is that there are multiple files tossed onto our computer as we surf the Internet. What we call browser 'cookies' are only one form. Using the Everycookie concept, a personal privacy parasite needs only one of these several files to track us across the Internet. And any one of these files can be used to respawn all the others. Therefore, with the Evercookie system, real personal privacy requires deleting every single one of these tracking files from your web browser

The best tool to combat the Evercookie so far, that I am aware of, is the BetterPrivacy extension/add-on for Firefox. You can read about hit and download it here:

BetterPrivacy

~~~~~~~~~~~~~

There are further Internet privacy tools a plenty! But this shortlist covers the best of them and will get you going. I know! These tools don't fully solve the 'Evercookie' dilemma. But I don't know anything that does, not yet anyway. Hopefully an Evercookie killing tool is in store for us in 2011.

Coming up in Part III will be my version of a comprehensive list of currently active malware for Mac OS X, including all their various names. All of them are either Trojan horses or hacker tools. I am also looking forward to putting together an article on Mac OS X 10.7 Lion security, which so far sounds like a decent improvement. Stay tuned!
--

Wednesday, October 27, 2010

Firefox v3.5 & v3.6 Zero-Day Exploit:
JavaScript Hell

--
An active zero-day exploit of Firefox versions 3.5 and 3.6 been found In-The-Wild. (The current version of Firefox is v3.6.11). Specifically, the Nobel Peace Prize website injects malware into victim computers via a newly discovered Firefox security hole. So far, the malware being injected is the Windows-only Trojan horse Belmoo-A. However, the injected malware could just as easily be any of the current Mac OS X Trojans.

Note of course that Trojan horses are inert until a 'LUSER' runs and installs them, providing it with their computer's Administrator password.

Firefox are aware of the situation and are working on a patch. In the meantime, they recommend the workaround of disabling JavaScript (aka ECMAScript), or installing and using the Firefox add-on NoScript. I use NoScript. I love it! I never leave my homepage without it.

As per usual, JavaScript is the bane of the Internet. However, Java isn't fairing too well either, much to everyone's dismay. I'll be writing about Java's security ills early next month.
--

Thursday, March 25, 2010

64-bit 7ista Twice Hacked via both IE 8 and Firefox 3!
The End Is Nigh!


I should also mention that both Mac OS X 10.6 Snow Leopard and the iPhone got hacked via Safari. Just doing a little back-at-you priority swapping. These days it is a BIG DEAL when Mac OS X gets hacked because of its reputation as the safest GUI OS on the planet. Hacking Windows is ho hum because it happens every day.

Here are some links to somewhat detailed articles about the Day 1 results from the Pwn2Own contest at CanSecWest 2010 in Vancouver, Canada:

TippingPoint blog.
CNet.
MacWorld.

The contest still has two more days of hacking to go. But here is the current list of winners from Day 1:
PWNED! Vincenzo Iozzo and Ralf Philipp Weinmann - iPhone
PWNED! Charlie Miller - Safari [on Mac OS X 10.6]
Nils - Safari (Prize Claimed) [on Mac OS X 10.6]
PWNED! Peter Vreugdenhil - Internet Explorer 8 [on 7ista]
MemACCT - Internet Explorer 8 (Prize Claimed) [on 7ista]
Anonymous - Nokia
Anonymous - iPhone (Prize already won)
PWNED! Nils - Firefox [on 7ista]
Congratulations to all the hackers and thank you for making it clear that Internet surfing can be dangerous no matter the operating system or web browser. Details of each zero day hack are not published until they have been addressed by the companies or groups in charge of affected programs and operating systems. When the Mac OS X hacks have been published, I'll report them and provide links here.

I'll also post more from CanSecWest as it progresses. Dr. Charlie Miller will be presenting his 20 Mac OS X 10.6 Snow Leopard hacks.

The successful hacking of Windows 7ista is of particular interest because it involved bypassing the much lauded ASLR (Address Space Layout Randomization) and DEP (Data Execution Prevention) built into 7ista. So much for those security technologies!

In each hack the victim computers were directed to websites containing exploit code. I'm going to hazard a wild guess that the sites used code written at least in part in the catastrophic mess known as ECMAScript, aka JavaScript/JScript. Readers of this blog will already know my low opinion of this scripting language and my desire that it be banished from the Internet forever. Listeners to the SecurityNow Podcast know that Steve Gibson of Gibson Research Corporation (GRC) called out ECMAScript as dangerous years ago. He recommends surfing the net with scripting turned OFF in all web browsers by default, only turning it on at trusted websites.

Java exploits are also well known at this time, indicating the need to also turn off Java while surfing the net, except again at trusted websites. What a shame.

(Note that JavaScript and Java have nothing whatsoever to do with each other apart from a similar name caused by a marketing moron deal between Netscape and Sun Microsystems, both companies now defunct).

Wednesday, April 29, 2009

Dump Adobe Reader? Yeah, why not.

--
Intro:
I never like articles with a title ending in a question mark. You know what you're going to get: no answer to the question. Therefore, they are typically filler. Yawn on that. So here is my question and answer title. Let's get to the point right off the bat: Adobe Reader is a security risk.

The chatter on the net this past week has come to the conclusion that the long line of security holes in Adobe Reader over the past two years is enough already. Dump the thing. It's like my conclusion from decades past that Windows, among its many disappointments, is too much of a security risk to use professionally. That any business or any government uses it greatly concerns me. But it's not Microsoft bashing day. It's Adobe bashing day. If you don't need Adobe Reader, don't use it. Thankfully, Mac OS X users have Apple's Preview application, which has not got the JavaScript vulnerabilities of Adobe Reader. So use Preview instead. It's not totally immune to infected PDF files, but it's much safer than Adobe Reader.

OK, it's not like anyone's Mac got pwned by using Adobe Reader. There is no malware targeting Macs that I know of that weasels its way in via holes in Adobe Reader. So really there is no major alarm going off telling us to kick Adobe Reader off the bus for having cooties. But considering that Mac OS X is the safest professional operating system on the planet (not that I'm dissing Linux mind you), avoiding Adobe Reader at this time is a very good idea.

Personally, I've been a fan of PDF since Adobe Acrobat version 3. It's brilliant and has only become better over time. Thank you Adobe, and especially thank you for making it an open standard. Its integration into the core of Mac OS X is incredible. However, Adobe allowed in some poor code, including support for the catastrophe oddly known as JavaScript. I'll skip my usual lecture on how it got its misnomer and how it was ruined as a standard by Microsoft. Simply know that it is a security holey mess. Apple has gotten burned by JavaScript in QuickTime since 2006. The same JavaScript insecurities are equally plaguing Adobe Reader. Apple got control of their JavaScript problems. Adobe are still playing catch up.

Me, I'll still continue to use Acrobat. I'll still keep Reader around for when I absolutely need it. And there are indeed times when I require Reader. But I'm also going to keep an eye on the latest Reader problems and continue to update it (manually!) when updates are offered.
--

Thursday, February 12, 2009

Mac Security Update 2009-001, Java Updates and a Safari for Windows Update

--
If you'd like to read Apple's notes about Security Update 2009-001, you can click HERE.

Ahead is a quick analysis of what is covered in the update, along with comments.

This security update is specifically for computers updated to Mac OS X 10.4.11 and 10.5.6, both client and server. Presumably it will be integrated into 10.5.7 when it's available.

There are 28 specific security updates including fixes for 48 documented vulnerabilities, making this another whopper relative to the updates we used to get from Apple a couple years back. I like that. The updates cover some interesting aspects of the Mac OS X Apple have not previously addressed. This indicates to me that over time they are carefully combing through aspects of the OS rather than randomly poking around or only responding as they receive vulnerability reports from third parties.

As ever, there are several buffer overflow patches. Memory management remains one of the banes of contemporary coding. I'm getting the idea that this problem won't go away until we invent an AI that can self-analyze its own computer code. It could happen!

A surprising trend in this update is the patching of security problems introduced specifically in Mac OS X 10.5.6. Ahem Apple. Ahem beta testers.

Cookies: There are a couple repairs for cookie problems introduced into the CFNetwork process in Mac OS X 10.5.6.

Printing: Included is a CUPS update as well as a repair of an error in the csregprinter process that allowed system privileges escalation.

Scripting: There are several patches provided for python and one for perl.

Remote Apple Events: There are a couple buffer overflow / out-of-bounds memory access patches.

SMB: Apple themselves patched a couple buffer problems, which is interesting. It's good to see Apple serious about compatibility with Windows networks.

X11: There are a collection of patches regarding font handling, user privilege plundering and several other vulnerabilites in the X11 server.

JavaScript: Here's another bane of contemporary coding. This time the patch is to Safari's RSS handling of feed URLs.

Mail services: A pair of patches are made to fetchmail and another pair to SquirrelMail.

Video: Yet another problem with maliciously crafted media files. This time a patch is provided for the Pixlet codec.

Other patched services include:

AFP Server
CarbonCore's Resource Manager
Certificate Assistant
CoreText
DS Tools: dscl
Folder Manager
FSEvents framework: fseventsd
Network Time
Server Manager: servermgrd
XTerm

And included is a security updated version of ClamAV for both 10.4 and 10.5 Server.

There were also a few other security related updates released today. Here is a list with links provided to their individual security update description documents:

Safari 3.2.2 for Windows

Java for Mac OS X 10.4 Release 8

Java for Mac OS X 10.5 Update 3

The Java security vulnerabilities that were patched include maliciously written web page Java applets allowing user privilege plundering. These problems weren't in Apple's implementation but in Java itself. SOS: Java was supposed to be as safe as a sandbox. Yeah, a sandbox full of land sharks.

My recommendation for security fanatics, as per recommendations from security expert Steve Gibson: If you don't want to take chances with hacker perpetrated JavaScript and Java, use a browser that lets you turn on support for both protocols on a site by site basis. As with using Little Snitch, it can be a PITA dithering around with little stuff on the net. But the geek in me adjusted such that I use site by site service control all the time. The browser I use for this purpose is OmniWeb. It's the bells and whistles web browser for Mac OS X and is well worth paying for if you like its abundant added features. You can also rig FireFox to handle site by site services as well. Camino and Safari are sadly site specific clueless. I haven't tested other browsers.

BTW: Coming up is my long delayed discussion of Tracking Cookies.

Share and Enjoy!

:-Derek
--