Latest Movie :
Recent Movies
Showing posts with label Explorer. Show all posts
Showing posts with label Explorer. Show all posts

Firefox 10 in Ubuntu 11.10 and 11.04 20 January 2012


The following tutorial will teach all Ubuntu 11.10 (Oneiric Ocelot) and Ubuntu 11.04 (Natty Narwhal) users how to update their systems to the Mozilla Firefox 10.0 web browser.

Mozilla Firefox 10 will bring features such as implementation of Anti-Aliasing for WebGL, the forward button is hidden by default and it will active when you navigate back, implementation of Full Screen APIs to easily build full-screen web apps, support for CSS3 3D-Transform, CSS properties support, <bdi> element for HTML5 bi-directional text isolation, CSS Style Inspector, and IndexedDB APIs.

At the request of many of our readers, we've created the following tutorial, based on our previous success on how to install Firefox 9 on Ubuntu 11.10 and Ubuntu 11.04, to guide them with the installation of the upcoming Mozilla Firefox 10.0 web browser in the Ubuntu 11.04 (Natty Narwhal) and Ubuntu 11.10 (Oneiric Ocelot) operating systems.

Official 64-bit and 32-bit Mozilla Firefox 10.0 packages are now available for the following Ubuntu distributions:

· Ubuntu 11.10 (Oneiric Ocelot)
· Ubuntu 11.04 (Natty Narwhal)

To install Mozilla Firefox 10.0 on your system follow the next step-by-step (with screenshots) tutorial.

XSS Attacks Possible Due to IE URI Encoding Flaw 2012

Best Internet Explorer

















A flaw currently present in Internet Explorer (IE) could be exploited by hackers and used to launch cross-site scripting (XSS) attacks, due to the way double quotes (“) are encoded by the web browser.

IMPERVA researchers found the vulnerability and contacted Microsoft, but the Redmond company doesn’t see it as a security vulnerability.

“The behavior you are describing is something that we are aware of and are evaluating for changes in future versions of IE, however it's not something that we consider to be a security vulnerability that will be addressed in a security update,” said a Microsoft representative regarding the issue.

On the other hand IMPERVA experts reveal that XSSed, a website that publicly discloses XSS vulnerabilities, reported a number of attacks that only affect IE users due to this encoding bug.

So what is this bug exactly?

Because IE doesn’t encode double quote characters in the query part of the uniform resource identifier (URI), websites that support the browser may assume that it's properly encoded and embed the URI in the request “as is” in the HTML response.

But since they’re not properly encoded, this may break the site’s structure and allow a hacker to launch an XSS attack.

RFC 3986, the Internet standard that defines the URI syntax, states that characters such as the double quote should be “pct-encoded”, a policy that's implemented in other web browsers such as Chrome or Firefox.

Internet Explorer only encodes the problematic character in the path part or the URI and not the query section. Considering that many websites are designed in a way to let the browser do the encoding, the HTML may be broken and used by the hacker to launch what is called a reflected XSS attack by convincing the victim to click on a malicious link.
 
Support : Creating Website | Johny Template | Mas Template
Copyright © 2011. Fine Technology - All Rights Reserved
Template Created by Creating Website Published by Mas Template
Proudly powered by Blogger