<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>rotas»sator &#187; Web browsers</title>
	<atom:link href="http://rotassator.com/category/safe-computing/web-browsers/feed/" rel="self" type="application/rss+xml" />
	<link>http://rotassator.com</link>
	<description>Random musings on safe computing, God, music, technology and anything else that comes to mind</description>
	<lastBuildDate>Thu, 15 Jul 2010 15:52:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Already? IE7 security holes</title>
		<link>http://rotassator.com/2006/10/already-ie7-security-holes/</link>
		<comments>http://rotassator.com/2006/10/already-ie7-security-holes/#comments</comments>
		<pubDate>Fri, 20 Oct 2006 00:03:14 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://rotassator.com/2006/10/already-ie7-security-holes/</guid>
		<description><![CDATA[Unfortunately, the day after IE7's big release, Secunia already lists two security flaws <a href="http://rotassator.com/2006/10/already-ie7-security-holes/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>For anyone that hasn&#8217;t been bombarded with recent marketing,  Microsoft has finally released <strong><abbr title="Internet Explorer 7">IE7</abbr></strong> &#8212; the successor to its ancient and much-maligned <a title="Microsoft Internet Explorer" href="http://http://www.microsoft.com/windows/ie/">Internet Explorer</a> browser.</p>

<p><abbr title="Internet Explorer 7">IE7</abbr> is being hailed as Microsoft&#8217;s trump card on the web. If you ask anyone in the know, there are better features and security in nearly <a title="Browse Happy: Online. Worry-Free" href="http://browsehappy.com/browsers/">any other browser</a>, but Microsoft <em>does </em>have the market cornered, with  <abbr title="Internet Explorer 7">IE7</abbr> set to be rolled out <em>automatically</em> to millions of computers via <a title="Microsoft Windows Update" href="http://windowsupdate.microsoft.com/">Windows Update</a>.</p>

<h4>IE7 vulnerabilities&#8230; already?</h4>

<p>Unfortunately, the day after <abbr title="Internet Explorer 7">IE7</abbr>&#8216;s big release, <a title="Secunia: a leading software security website" href="http://secunia.com/">Secunia</a> already lists two security flaws:<a title="Secunia: Security Advisory" href="http://secunia.com/advisories/22477/"></a>
<span id="more-77"></span></p>

<ul>
    <li><a title="Secunia: Security Advisory" href="http://secunia.com/advisories/22477/"> Internet Explorer 7 &#8220;mhtml:&#8221; Redirection Information Disclosure</a></li>
    <li><a title="Secunia: Security Advisory" href="http://secunia.com/advisories/19738/">Internet Explorer &#8220;mhtml:&#8221; Redirection Disclosure of Sensitive Information</a></li>
</ul>

<p>Gladly, the vulnerabilities only rate as &#8220;<a title="Secunia: Vulnerabilities and Virus Information" href="http://secunia.com/about_secunia_advisories/">Less Critical</a>&#8220;, so it&#8217;s unlikely that they&#8217;ll bring your computer to a halt. It&#8217;s more of a possible risk of exposing your browsing habits to someone with malicious intent.
It&#8217;s not that these vulnerabilities are new, per se. It&#8217;s just that Microsoft hasn&#8217;t bothered to fix them. Personally, I expect better quality control from one of the world&#8217;s largest software giants.</p>

<p>Despite this nasty early surprise (can we really call it that?), <abbr title="Internet Explorer 7">IE7</abbr> <em>is</em> definitely an improvement over all previous versions of Internet Explorer. <strong>Everyone with Windows XP Service Pack 2 should install <abbr title="Internet Explorer 7">IE7</abbr></strong> to get rid of older, even buggier, versions of Internet Explorer.</p>

<p>After upgrading, you might still like to consider using <a title="Browse Happy: Online. Worry-Free" href="http://browsehappy.com/browsers/">a better, more frequently updated browser</a>.</p>

<p>Blessings,
<cite>Steve</cite></p>

<p class="note">P.S. For any eagle-eyed readers, there&#8217;s also been a <a title="Secunia: Security Advisory" href="http://secunia.com/advisories/22218/">recent &#8220;Highly Critical&#8221; flaw</a> discovered in <a title="Opera browser" href="http://www.opera.com/">Opera</a>. For anyone with version 9.01 or earlier, you can already <a title="Download the Opera browser" href="http://www.opera.com/download/">update your browser</a> (version 9.02 at the time of writing).</p>

<p class="listening">[Listening to <a title="A rocking live performance, featuring the entire Red Rocks concert" href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B0006709MG">Incubus, Alive at Red Rocks</a> --- Idiot Box]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2006/10/already-ie7-security-holes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is your Flash Player vulnerable?</title>
		<link>http://rotassator.com/2006/03/is-your-flash-player-vulnerable/</link>
		<comments>http://rotassator.com/2006/03/is-your-flash-player-vulnerable/#comments</comments>
		<pubDate>Fri, 17 Mar 2006 05:37:26 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://rotassator.com/2006/03/is-your-flash-player-vulnerable/</guid>
		<description><![CDATA[A "Highly Critical" vulnerability has been found in Flash Player, affecting nearly all web users. <a href="http://rotassator.com/2006/03/is-your-flash-player-vulnerable/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A &#8220;Highly Critical&#8221; vulnerability has been found in Flash Player, affecting <strong>nearly all web users.</strong></p>

<p><span id="more-74"></span></p>

<p>A new <a title="Secunia Advisory: Flash Player Unspecified Code Execution Vulnerabilities" href="http://secunia.com/advisories/19218/">security advisory at Secunia</a> describes newly-found problems in Macromedia&#8217;s Flash Player for all versions up to v8.0.22.0.</p>

<p>This <strong>affects almost everyone on the web</strong>, as the Flash Player is used by almost every Windows-based browser, including (but not limited to):</p>

<ul>
    <li><a title="Microsoft Internet Explorer" href="http://www.microsoft.com/windows/ie/default.mspx">Internet Explorer</a> (including IE-based &#8220;browsers&#8221; such as <a title="Maxthon Browser â€“ Tabbed Internet browser software" href="http://www.maxthon.com/">Maxthon</a> and <a title="Avant Browser, a tabbed browser with Flash Filter, Popup Blocker, Cleaner and Web Search" href="http://www.avantbrowser.com/">Avant Browser</a>)</li>
    <li><a title="Firefox - Rediscover the Web" href="http://www.mozilla.com/firefox/">Firefox</a> (including derivatives such as <a title="Firefox-based browser" href="http://www.flock.com/">Flock</a>)</li>
    <li><a title="Mozilla Suite - The All-in-One Internet Application Suite" href="http://www.mozilla.org/products/mozilla1.x/">Mozilla</a> (and other Mozilla-based browsers)</li>
    <li><a title="Opera Web Browser" href="http://www.opera.com/">Opera</a></li>
    <li><a title="Netscape Browser" href="http://browser.netscape.com/ns8/">Netscape</a></li>
    <li>Other Flash-capable browsers</li>
</ul>

<p><em>This is not a fault with these browsers per se</em>. However, as the Flash Player component is embedded into the browser, the problem can be exploited by simply browsing to a site that contains a malicious Flash movie.</p>

<h4>Updating Flash Player</h4>

<p><strong>You need to update the Flash Player for your browser(s)</strong>. To avoid having any (more?) problems because of this vulnerability, <a title="Macromedia Flash Player Download Center" href="http://www.macromedia.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash">download the latest Flash Player</a> (v8.0.24.0 at the time of writing) from the Macromedia website.</p>

<ul>
    <li><a title="Download the latest version of Flash Player" href="http://www.macromedia.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash">Macromedia Flash Player Download Center</a></li>
</ul>

<p class="note">Important: If you have more than one browser installed (eg. Firefox and Internet Explorer), make sure you <strong>update the software for each browser</strong>. To do this, you will have to visit the <a title="Download the latest version of Flash Player" href="http://www.macromedia.com/shockwave/download/download.cgi?P1_Prod_Version=ShockwaveFlash">Flash Player Download Center</a> with each browser you have installed. The page automatically detects your browser and displays an appropriate version of the software.</p>

<p>Go and update as soon as possible!</p>

<p>Blessings
<cite>Steve</cite></p>

<h4>Update: Problems downloading</h4>

<p>Heh.</p>

<p>When I tried to update my other browsers, I had mixed results. I was able to update the Flash Player easily using Firefox, which also updated all the other Mozilla or Netscape-based versions.</p>

<p>However, when I accessed the Download Center using Internet Explorer, it seemed to display the download for a random operating system (namely Mac OS X and OS 9&#8230; I&#8217;m using Windows here&#8230;).</p>

<p><strong>If you are having trouble updating your browser</strong>, Macromedia also have a list of <a title="Macromedia Web Players" href="http://www.macromedia.com/shockwave/download/alternates/">downloads for all versions of Flash Player</a>.</p>

<ul>
    <li><a title="Alternate versions of Flash Player" href="http://www.macromedia.com/shockwave/download/alternates/">Macromedia Web Players</a> &#8211; list of &#8220;alternate&#8221; versions of Flash Player<a href="http://www.macromedia.com/shockwave/download/alternates/">
</a></li>
</ul>

<p>Hopefully that&#8217;s the last we&#8217;ll hear of it. <img src='http://rotassator.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>

<p class="listening">[Listening to <a title="Powerful worship album from one of the very best" href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B00004YWWF">Delirious, GLO</a> â€” Jesus' Blood]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2006/03/is-your-flash-player-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Firefox 1.5.0.1</title>
		<link>http://rotassator.com/2006/02/firefox-1501/</link>
		<comments>http://rotassator.com/2006/02/firefox-1501/#comments</comments>
		<pubDate>Wed, 01 Feb 2006 23:22:05 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=73</guid>
		<description><![CDATA[The Mozilla Foundation surprised me this morning with an update to the excellent Firefox browser, now at version 1.5.0.1. <a href="http://rotassator.com/2006/02/firefox-1501/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<h4>Surprise!</h4>

<p>The Mozilla Foundation surprised me this morning with an update to <a href="http://www.spreadfirefox.com/?q=affiliates&#038;id=14835&#038;t=69" title="Mozilla Firefox 1.5.0.1">the excellent Firefox browser</a>, now at version 1.5.0.1. <del datetime="2006-02-09T22:41:20+00:00">Couldn&#8217;t find that much info about what was updated though&#8230;</del> <ins datetime="2006-02-09T22:41:20+00:00">Secunia has a full list of <a href="http://secunia.com/advisories/18700/" title="Firefox Multiple Vulnerabilities">vulnerabilities that have now been fixed</a> in v1.5.0.1.</ins></p>

<p><span id="more-73"></span></p>

<p>I only had two extensions disabled with this one &#8212; <a href="https://addons.mozilla.org/extensions/moreinfo.php?id=402&#038;application=firefox" title="Text emulation of what screen reader output">Fangs</a> and <a href="https://addons.mozilla.org/extensions/moreinfo.php?id=216&#038;application=firefox" title="A powerful Javascript Debugger">Venkman</a>, so I didn&#8217;t have too much to complain about in the upgrade.</p>

<p>For all you Firefox lovers out there (isn&#8217;t that all of you? <img src='http://rotassator.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />  ), <a href="http://www.spreadfirefox.com/?q=affiliates&#038;id=14835&#038;t=69" title="Mozilla Firefox 1.5.0.1">go forth and download</a>!</p>

<p>Blessings,
<cite>Steve</cite></p>

<h4>Update</h4>

<p><a href="http://secunia.com/advisories/18700/" title="Secunia Advisory: Firefox Multiple Vulnerabilities">Secunia outlines the list of vulnerabilities</a> in Firefox that have been fixed in version 1.5.0.1. The advisory is rated as being <strong>Highly Critical</strong>, and there are already some nefarious types using exploits on the internet to infect unsuspecting users.</p>

<p>The good news is that the team behind Firefox have moved very quickly to fix these problems. All software has bugs, but the negative effect of the bugs are minimised when they are addressed quickly.</p>

<p>Don&#8217;t wait to update your browser when there is an update. <a href="http://www.spreadfirefox.com/?q=affiliates&#038;id=14835&#038;t=69" title="Mozilla Firefox">Update Firefox now</a>!</p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B00008BRB6" title="Excellent and varied - the Police at their live best">The Police, Live! (Disc 1)</a> &#8212; Landlord]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2006/02/firefox-1501/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Update your Flash Player(s)</title>
		<link>http://rotassator.com/2005/11/update-your-flash-players/</link>
		<comments>http://rotassator.com/2005/11/update-your-flash-players/#comments</comments>
		<pubDate>Tue, 29 Nov 2005 04:44:20 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=69</guid>
		<description><![CDATA[A "highly critical" vulnerability has been found in Macromedia Flash Player that affects <strong>virtually every web browser on every platform</strong>. <a href="http://rotassator.com/2005/11/update-your-flash-players/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>A &#8220;highly critical&#8221; vulnerability has been found in Macromedia Flash Player that affects <strong>virtually every web browser on every platform</strong>.</p>

<p>Earlier this month, Macromedia disclosed a <a href="http://www.macromedia.com/devnet/security/security_zone/mpsb05-07.html" title="Security Bulletin: MPSB05-07 Flash Player 7 Improper Memory Access Vulnerability">problem with its Flash Player software</a> that may give hackers access to your computer. <a href="http://secunia.com/advisories/17430/" title="Secunia Advisory: Macromedia Flash Player SWF File Handling Arbitrary Code Execution">Secunia also reported the problem</a>, giving it a rating of <em>Highly critical</em>.</p>

<p><span id="more-69"></span></p>

<h4>Does this affect me?</h4>

<p>Yes. Almost without question. Virtually every web browser comes with Flash Player as part of the software (such as Microsoft Internet Explorer) or as a downloadable plugin (as in Firefox, etc). Macromedia&#8217;s surveys claim that <a href="http://www.macromedia.com/software/player_census/flashplayer/" title="Macromedia Flash content reaches 97.3% of Internet viewers">97% of browsers have Flash Player</a>.</p>

<p>The vulnerability has been confirmed <em>not only on Windows systems but also on Mac and Linux platforms</em>.</p>

<p>In fact, if you have more than one browser installed, <strong>you probably also have more than one version of Flash Player installed</strong>. For example, Windows comes with Internet Explorer already installed (and so also Flash Player), so if you&#8217;ve upgraded to a <a href="http://browsehappy.com/" title="Choose a safer, better browser">better browser</a> (eg. Firefox or Opera), you probably have another version of Flash Player installed.</p>

<h4>How do I update Flash Player?</h4>

<p>Go and get yourself a cup of your favourite beverage before you start, particularly if you&#8217;re not that comfortable with the thought of <em>upgrading things</em>.</p>

<h5>Updating Microsoft Internet Explorer</h5>

<p><strong>All Windows users</strong> should do the following:</p>

<ol>
    <li>Open Microsoft Internet Explorer (one of the only times I&#8217;ll be telling you to do this!);</li>
    <li>Browse to the <strong>Macromedia Player Download Center</strong> at <a href="http://www.macromedia.com/go/getflash">http://www.macromedia.com/go/getflash</a>;</li>
    <li>Follow the instructions to upgrade <dfn title="Internet Explorer">IE</dfn>&#8216;s Flash <dfn title="A proprietary Microsoft technology that has created many security problems due to its integration with Windows">ActiveX control</dfn>. You may need to <em>read the instructions</em> related to browser security options;</li>
    <li>Close Internet Explorer. If you have another browser, you still need to upgrade its Flash Player as well (keep reading).</li>
</ol>

<h5>Updating other browsers</h5>

<p>To update other browsers, such as Firefox, Mozilla or Opera:</p>

<ol>
    <li>Open your preferred browser (not Internet Explorer!);</li>
    <li>Browse to the <strong>Macromedia Player Download Center</strong> at <a href="http://www.macromedia.com/go/getflash">http://www.macromedia.com/go/getflash</a> (you&#8217;ll see a different page than that displayed by IE);</li>
    <li>Download the latest version of Flash Player to your computer (v8.0.22.0 at the time of writing);</li>
    <li>Close your browser and install the Flash Player update (double-click the install file).</li>
</ol>

<h4>All done</h4>

<p>If you have done all the appropriate steps outlined above, your Flash Player(s) should be up to date and safe from this vulnerability.</p>

<p>Take a deep breath and relax for a bit! If you&#8217;d like a laugh after all the hard work, check out my favourite reason to have a Flash Player &#8212; <a href="http://www.homestarrunner.com/" title="More fun than you can poke a stick at">Homestar Runner</a>.</p>

<p>Blessings,
<cite>Steve</cite></p>

<p class="listening">[Listening to <a href="http://www.amazon.com/exec/obidos/redirect?tag=rotassator-20&#038;path=tg/detail/-/B000002HPT" title="Probably my favourite album from this amazing bunch of prog freaks">Dream Theater, Falling Into Infinity</a> &#8212; New Millennium]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/11/update-your-flash-players/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Yet another reason not to use Internet Explorer</title>
		<link>http://rotassator.com/2005/11/yet-another-reason-not-to-use-internet-explorer/</link>
		<comments>http://rotassator.com/2005/11/yet-another-reason-not-to-use-internet-explorer/#comments</comments>
		<pubDate>Tue, 22 Nov 2005 04:32:08 +0000</pubDate>
		<dc:creator>Steve</dc:creator>
				<category><![CDATA[Safe computing]]></category>
		<category><![CDATA[Web browsers]]></category>

		<guid isPermaLink="false">http://rotassator.com/?p=68</guid>
		<description><![CDATA[Another "Extremely Critical" vulnerability has been found in Microsoft Internet Explorer 5.x and 6.0. <a href="http://rotassator.com/2005/11/yet-another-reason-not-to-use-internet-explorer/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Another &#8220;Extremely Critical&#8221; vulnerability has been found in Microsoft Internet Explorer 5.x and 6.0.</p>

<p><a href="http://secunia.com/advisories/15546" title="Secunia: Microsoft Internet Explorer 'window()' Arbitrary Code Execution Vulnerability">Secunia, et al</a> detail how a malicious webmaster could easily break the current version of <dfn title="Internet Explorer">IE</dfn>, even with all current patches, using an extremely simple script in a page. <a href="http://www.microsoft.com/technet/security/advisory/911302.mspx" title="Microsoft Security Advisory (911302): Vulnerability in the way Internet Explorer Handles onLoad Events Could Allow Remote Code Execution">Microsoft says it&#8217;s &#8220;investigating&#8221; the issue</a>, which it admits <strong>has been on its books since May</strong>!</p>

<p><span id="more-68"></span></p>

<h4>Stop using Internet Explorer now.</h4>

<p>It won&#8217;t take long before this vulnerability is being exploited and real users suffering as a result.</p>

<p><strong>Don&#8217;t be one of them.</strong> <a href="http://browsehappy.com/" title="Browser Happy: Choose a safer, better browser">Get a real browser now</a>, like <a href="http://www.spreadfirefox.com/?q=affiliates&#038;id=14835&#038;t=69" title="Mozilla Firefox browser">Firefox</a> or <a href="http://opera.com/products/desktop/" title="The Opera Browser">Opera</a>.</p>

<p>As far as I&#8217;m concerned, Internet Explorer should now only be used to <a href="http://update.microsoft.com/microsoftupdate/" title="Microsoft Update. Open this link with Internet Explorer, as it doesn't work in other browsers.">update your computer with the latest patches</a> to make your PC safer. Unfortunately Microsoft Update doesn&#8217;t work in safer browsers.</p>

<p>What a sad irony.</p>

<p>If you&#8217;re <em>still</em> using Internet Explorer, <a href="http://browsehappy.com/" title="Browser Happy: Choose a safer, better browser">consider changing to a safer, better browser</a>. The internet will be safer for it.</p>

<p>Blessings,
<cite>Steve</cite></p>

<h4>Udpates</h4>

<ul>
    <li><a href="http://news.zdnet.com/2100-1009_22-5965247.html?tag=nl.e540" title="Article at ZDNet">Attack code released for IE hole</a></li>
</ul>

<p class="listening">[Listening to <a href="http://www.radiantrecords.com/catalog.asp?Item=153" title="A soulful prog rock album detailing NM's personal testimony">Neal Morse, Testimony</a> &#8212;  Sing It High ]</p>
]]></content:encoded>
			<wfw:commentRss>http://rotassator.com/2005/11/yet-another-reason-not-to-use-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
