<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacymozilla</title>
	<atom:link href="http://hijack-this.co.uk/category/mozilla/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 12 Aug 2010 07:31:02 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Beware of fake shopping sites</title>
		<link>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/</link>
		<comments>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 10:55:16 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[fake adverts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=261</guid>
		<description><![CDATA[With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &#38; credit card details. A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can [...]]]></description>
			<content:encoded><![CDATA[<p><br />
With the seasonal shopping season well underway, watch out for fake shopping sites and phishing emails trying to get your identity &amp; credit card details.</p>
<p>A slightly different approach came into my inbox today which asked me to confirm the item in my shopping basket. Now I haven&#8217;t shopped with Littlewoods online but you can be sure that thousands of people have and the same scam will be applied to just about every well known online shopping site this season.</p>
<p>The email looks quite believable<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email.PNG"><img class="alignnone size-medium wp-image-262" title="littlewoods_email" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_email-300x258.PNG" alt="littlewoods_email" width="300" height="258" /></a></p>
<p>The website if you follow the link looks exactly like the real Littlwoods shopping site Account sign in page <strong>EXCEPT</strong> that the real Littlewwoods or ALL reputable shopping sites will have a Padlock icon and the  site address will start with<strong> HTTPS</strong> and the address bar will turn green to show that you are on a secure site</p>
<p>This screenshot shows the fake site and I have blanked out the address for safety reasons<br />
<a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web.PNG"><img class="alignnone size-medium wp-image-263" title="littlewoods_web" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_web-300x231.PNG" alt="littlewoods_web" width="300" height="231" /></a></p>
<p>These show how a genuine site will appear in Internet Explorer 8 on left and Firefox on right. Both show the padlock icon and a green safe address bar. A genuine shopping site will always start <strong>HTTPS</strong> to show a secure site when you are asked to put in any details. The front page of the site might be a normal http:<br />
Unfortunately a lot of well known shopping sites haven&#8217;t yet signed up to the Extended Valuation green bar very secure system yet so watch for the closed padlock and HTTPS in the address bar to show a secure site. In Firefox browser the closed padlock is on the bottom right hand corner of the page, not in the browser address bar </p>
<table border="0">
<tbody>
<tr>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE.PNG"><img class="alignnone size-medium wp-image-264" title="littlewoods_IE" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/littlewoods_IE-300x193.PNG" alt="littlewoods_IE" width="300" height="193" /></a></td>
<td><a href="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods.PNG"><img class="alignnone size-medium wp-image-265" title="real_littlewoods" src="http://hijack-this.co.uk/wp-content/uploads/2009/11/real_littlewoods-300x232.PNG" alt="real_littlewoods" width="300" height="232" /></a></td>
</tr>
</tbody>
</table>
<p style="text-align: left;"><strong>I strongly recommend using <a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank">ROBOFORM </a>which keeps all passwords in a secure encrypted database that only you (not a keylogger or malware) can access and use it to create safe secure passwords</strong></p>
<p><a href="http://www.roboform.com/php/land.php?affid=dvk01&amp;frm=frame17" target="_blank"><img src="http://www.roboform.com/affiliates/banners/728x90-warning3-free.gif" border="0" alt="RoboForm: Learn more..." width="728" height="90" /></a></p>
By the time  your rss reader get this post here is <strong> 2 </strong>comments ,Welcome you come to leave your opinion !<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/beware-of-fake-shopping-sites/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Sun Java Runtime Environment Multiple Vulnerabilities</title>
		<link>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/</link>
		<comments>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 11:54:06 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=210</guid>
		<description><![CDATA[wg_format ="300x250"; wg_background_color = "#F5F5DD"; wg_text_color = "#000000"; wg_url_text_color = "#008000"; wg_border_color = "#D71921"; wg_click_reference = ""; wg_new_window = true; wg_render(); Sun Java Runtime Environment Multiple Vulnerabilities Affected: JDK and JRE 6 Update 16 and earlier JDK and JRE 5.0 Update 21 and earlier SDK and JRE 1.4.2_23 and earlier SDK and JRE 1.3.1_26 and [...]]]></description>
			<content:encoded><![CDATA[<p>Sun Java Runtime Environment Multiple Vulnerabilities<br />
Affected:<br />
JDK and JRE 6 Update 16 and earlier<br />
JDK and JRE 5.0 Update 21 and earlier<br />
SDK and JRE 1.4.2_23 and earlier<br />
SDK and JRE 1.3.1_26 and earlier</p>
<p>Description: Sun&#8217;s implementation of the Java Runtime Environment (JRE) and Java Web Start contains multiple vulnerabilities. A specially crafted Java application, an audio or image file or an applet could trigger one of these vulnerabilities, with consequences ranging from arbitrary code execution with the privileges of the current user to denials-of-service and security restriction bypass. Note that, depending upon configuration, Java applets embedded in web pages may be opened automatically upon the loading of the page. One of the error is that the update mechanism does not update JRE to the new version when running on non-English Windows versions. There are errors in decoding DER encoded data and the parsing of HTTP headers which might lead to memory exhaustion. There is an authentication bypass vulnerability in JRE while verifying HMAC digests. Multiple buffer overflow and integer overflow vulnerabilities have been reported in JRE while processing specially crafted audio and image files. There is a command execution vulnerability in JRE which could be triggered by a specially crafted web page. There is a flaw in the implementation of security model permissions in the Java Web Start Installer. Some technical details for some of these vulnerabilities are publicly available.</p>
<p>Status: Vendor not confirmed, no updates available. [edit] Updates are available</p>
<p>References:<br />
Zero Day Initiative Advisories<br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-076">http://www.zerodayinitiative.com/advisories/ZDI-09-076</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-077">http://www.zerodayinitiative.com/advisories/ZDI-09-077</a><br />
 <a href="http://www.zerodayinitiative.com/advisories/ZDI-09-078">http://www.zerodayinitiative.com/advisories/ZDI-09-078</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-079">http://www.zerodayinitiative.com/advisories/ZDI-09-079</a><br />
<a href="http://www.zerodayinitiative.com/advisories/ZDI-09-080">http://www.zerodayinitiative.com/advisories/ZDI-09-080</a><br />
Sun Security Advisories<br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270476-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270475-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-270474-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269870-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269869-1</a><br />
<a href="http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1">http://sunsolve.sun.com/search/document.do?assetkey=1-66-269868-1</a><br />
Product Home Page<br />
<a href="http://java.sun.com">http://java.sun.com</a><br />
SecurityFocus BID<br />
<a href="http://www.securityfocus.com/bid/36881">http://www.securityfocus.com/bid/36881</a></p>
<p>for this DO NOT rely on check for updates in JAVA control panel BUT go to <a href="http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80">http://java.com/en/download/ie_manual.jsp?locale=en&amp;host=java.com:80</a></p>
<p>if you have a 64 bit version of windows, you need to install the standard 32 bit version AND the 64 bit version <a href="http://java.com/en/download/manual.jsp">http://java.com/en/download/manual.jsp</a></p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/11/sun-java-runtime-environment-multiple-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla fixes 16 flaws with Firefox 3.5.4:</title>
		<link>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/</link>
		<comments>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 06:47:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=196</guid>
		<description><![CDATA[http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4 Mozilla fixes 16 flaws with Firefox 3.5.4: http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4  Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4.   The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4">http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4</a></p>
<p>Mozilla fixes 16 flaws with Firefox 3.5.4:</p>
<p><a href="http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4">http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4</a></p>
<p> Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4. </p>
<p> The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a trio of third-party media libraries, and both the JavaScript and browser engines.</p>
Here is no comments yet by the time  your rss reader get this, Do you want to be the first commentor? Hurry up <p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share/Bookmark"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
