<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security and Privacy &#187; browser</title>
	<atom:link href="http://hijack-this.co.uk/tag/browser/feed/" rel="self" type="application/rss+xml" />
	<link>http://hijack-this.co.uk</link>
	<description>My ramblings on how to protect yourself online</description>
	<lastBuildDate>Thu, 01 Dec 2011 08:19:43 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The problem with the Prefetch function in Firefox and Chrome</title>
		<link>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/</link>
		<comments>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/#comments</comments>
		<pubDate>Mon, 31 Jan 2011 11:01:23 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=421</guid>
		<description><![CDATA[Did you know that Firefox and Chrome both have a feature that fetches pages and links that it thinks you might be going to click on? This can slow down your computer and browsing dramatically. The majority of problems come up when using a search engine, particularly Google with its &#8220;preview function&#8221;. The pre-fetch function [...]]]></description>
			<content:encoded><![CDATA[<p>Did you know that Firefox and Chrome both have a feature that fetches pages and links that it thinks you might be going to click on? This can slow down your computer and browsing dramatically. The majority of problems come up when using a search engine, particularly Google with its &#8220;preview function&#8221;.<br />
The pre-fetch function in these browsers silently loads every link in the background and caches ( stores) the pages in your internet temporary files folder used by Firefox or Chrome. So far Internet Explorer has resisted the temptation to do this.<br />
<strong>It also has another major problem when using security software that blocks dangerous or known malicious IP numbers or web addresses</strong>. You either get constant alerts about malicious pages attempting to infiltrate your computer or pop up warnings saying xxxx address or IP number has been blocked. Some security softwares will block you from the original page that you are attempting to visit because of the preloaded link to a potentially malicious site, that can lead to major problems with search engines. In 99% of the time, you have absolutely no intention of ever visisting that site, it is just Firefox or Chrome being <em>helpful</em> and preloading the pages for you<span id="more-421"></span></p>
<p><strong>Here’s how to disable the Firefox prefetch setting</strong>.</p>
<p>1. Type about:config in the address bar and press ENTER. Agree to the warning that changing settings can cause problems</p>
<p>2. Locate and double-click the entry for<br />
network.prefetch-next</p>
<p>3. Set it to false to disable this feature. Double-clicking on the setting will change it.</p>
<div id="attachment_432" class="wp-caption alignleft" style="width: 649px"><img class="size-full wp-image-432 " title="FF_disable-prefetch" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/FF_disable-prefetch.png" alt="" width="639" height="504" /><p class="wp-caption-text">How to disable prefetch in Firefox</p></div>
<p><strong>This is how to disable the prefetch function in Chrome:</strong><br />
1. Click the wrench in the upper-right corner.</p>
<p>2. Select Options<br />
<img class="aligncenter size-full wp-image-425" title="chrome_select_options" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/chrome_select_options.gif" alt="" width="247" height="256" /><br />
3. Select the Under the hood tab.</p>
<p>4. Uncheck &#8220;Use DNS pre-fetching to improve page load performance&#8221; . and then close the options page</p>
<div id="attachment_426" class="wp-caption aligncenter" style="width: 510px"><img class="size-full wp-image-426" title="chrome_disable_prefetch" src="http://hijack-this.co.uk/wp-content/uploads/2011/01/chrome_disable_prefetch.png" alt="" width="500" height="534" /><p class="wp-caption-text">Disable prefetch in Chrome</p></div>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fthe-problem-with-the-prefetch-function-in-firefox-and-chrome%2F&amp;title=The%20problem%20with%20the%20Prefetch%20function%20in%20Firefox%20and%20Chrome" id="wpa2a_2"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/the-problem-with-the-prefetch-function-in-firefox-and-chrome/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Beware of New year e-cards</title>
		<link>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/</link>
		<comments>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/#comments</comments>
		<pubDate>Sat, 01 Jan 2011 17:18:00 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Rogue Software]]></category>
		<category><![CDATA[scams]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>
		<category><![CDATA[fake adverts]]></category>
		<category><![CDATA[fake software]]></category>
		<category><![CDATA[keylogger]]></category>
		<category><![CDATA[protection]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=412</guid>
		<description><![CDATA[Please avoid all untrusted Happy New Year e-card links. The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs. New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0? http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230 Those of us here at Shadowserver hope you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p>Please avoid all untrusted Happy New Year e-card links.  The Shadowserver Foundation is warning of a new malicious and advanced botnet that has just been discovered and ressembles the Storm Worm designs.</p>
<p>New Fast Flux Botnet for the Holidays: Could it be Storm Worm 3.0/Waledac 2.0?<br />
<a href="http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230">http://www.shadowserver.org/wiki/pmwiki.php/Calendar/20101230</a><br />
Those of us here at Shadowserver hope you&#8217;re having a wonderful holiday season and are ready to bring in the new year. We were trying to relax and enjoy relatively quiet times until we noticed a new spam campaign that recently started. At first it looked like your regular old holiday e-card scams that have been around for years. </p>
<p>However, upon closer inspection it looks like we could be dealing with the next generation of Storm Worm or Waledac. If you consider Waledac to be Storm Worm 2.0, this looks like it could be version 3.0 or at least Waledac 2.0. There are no real version numbers of course, but we don&#8217;t have anything else to call it yet. What&#8217;s it involve you ask? </p>
<p> CHARACTERISTICS OF NEW BOTNET </p>
<p>Well here&#8217;s the list of what we&#8217;ve seen so far: </p>
<p>* Large scale Spam campaigns sending out e-mails with links<br />
* New malicious domains that are fast flux! (TTL of 0 and name servers that frequently update IPs)<br />
* Links are to several hacked websites hosting HTML pages that refresh to new malicious domains<br />
* Links are also directly to new malicious domains<br />
* Malicious domains hosting links to fake flash player and refreshes to exploit pages<br />
* Malware installs that begin beaching to several hosts over HTTP (what we dubbed HTTP2p with Waledac)<br />
* Malware that&#8217;s been updated to look a bit more like legitimate than past variants<br />
* A very buggy network that is not often available (upstream devices not available)<br />
* Changing/Updated binaries</p>
<p>  AVOID THESE E-CARD MESSAGES: </p>
<p>Let&#8217;s start with the Spam Campaign. We&#8217;ve seen a multitude of subject lines and bodies. Below you&#8217;ll find a list of subjects we&#8217;ve seen and an example e-mail message. These are coming from all over the Internet with spoofed sender addresses. </p>
<p> Greeting for you!<br />
 Greeting you with heartiest New Year wishes<br />
 Greetings to You<br />
 Happy New Year greetings e-card is waiting for you<br />
 Happy New Year greetings for you<br />
 Happy New Year greetings from your friend<br />
 Have a happy and colorful New Year!<br />
 l want to share Greeting with you<br />
 New Year 2011 greetings for you<br />
 You have a greeting card<br />
 You have a New Year Greeting!<br />
 You have received a greetings card<br />
 You&#8217;ve got a Happy New Year Greeting Card!</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2011%2F01%2Fbeware-of-new-year-e-cards%2F&amp;title=Beware%20of%20New%20year%20e-cards" id="wpa2a_4"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2011/01/beware-of-new-year-e-cards/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>List of public DNS services</title>
		<link>http://hijack-this.co.uk/2010/09/list-of-public-dns-services/</link>
		<comments>http://hijack-this.co.uk/2010/09/list-of-public-dns-services/#comments</comments>
		<pubDate>Sat, 11 Sep 2010 07:20:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[protection]]></category>
		<category><![CDATA[scams]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=331</guid>
		<description><![CDATA[Until fairly recently, nobody bothered with changing their DNS server. Everybody used the&#160;ones provided by their ISP.&#160;Today, there are several providers worldwide that provide free public DNS service with additional features like&#160;&#160;blocking known malware sites,&#160; blocking known&#160;phishing sites, parental controls and some even&#160;say that their services are quicker&#160;and more &#160;reliable. Here are a &#160;few of [...]]]></description>
			<content:encoded><![CDATA[<div>
<p><!--OffDef--></p>

<p>Until fairly recently, nobody bothered with changing their DNS server. Everybody used the&nbsp;ones provided by their ISP.&nbsp;Today, there are several providers worldwide that provide free public DNS service with additional features like&nbsp;&nbsp;blocking known malware sites,&nbsp; blocking known&nbsp;phishing sites, parental controls and some even&nbsp;say that their services are quicker&nbsp;and more &nbsp;reliable.</p>
<p>Here are a &nbsp;few of the&nbsp;&nbsp;better known and more reliable ones . It&#39;s up to you to&nbsp;choose&nbsp;the one that has the&nbsp; features or protection that you want.</p>
<p>You&nbsp;will &nbsp;find&nbsp;instructions on &nbsp;how to change DNS addresses on their webpages.</p>
<p><strong><a href="http://www.opendns.com/" target="_blank">OpenDNS</a></strong><br />
		208.67.222.222<br />
		208.67.220.220</p>
<p><strong><a href="http://code.google.com/speed/public-dns" target="_blank">Google Public DNS</a></strong><br />
		8.8.8.8<br />
		8.8.4.4</p>
<p><strong><a href="http://www.nortondns.com/" target="_blank">Norton DNS (Symantec Corporation)</a></strong><br />
		198.153.192.1<br />
		198.153.194.1</p>
<p><strong><a href="http://www.scrubit.com/" target="_blank">ScrubIT (ScrubDNS Inc.)</a></strong><br />
		67.138.54.100<br />
		207.225.209.66</p>
<p><strong><a href="http://www.dnsadvantage.com/" target="_blank">DNS Advantage (Neustar Inc)</a></strong><br />
		156.154.70.1<br />
		156.154.71.1</p>
<p><strong><a href="http://www.comodo.com/secure-dns/" target="_blank">Comodo Secure DNS (Comodo Security Solutions Inc.)</a></strong><br />
		156.154.70.22<br />
		156.154.71.22</p>
</div>

<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F09%2Flist-of-public-dns-services%2F&amp;title=List%20of%20public%20DNS%20services" id="wpa2a_6"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/09/list-of-public-dns-services/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>IE out of band patch</title>
		<link>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/</link>
		<comments>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 19:10:30 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[Warnings and Alerts]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/</guid>
		<description><![CDATA[This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack. The full [...]]]></description>
			<content:encoded><![CDATA[<p>This is an advance notification of one out-of-band security bulletin that Microsoft is intending to release on January 21, 2010. The bulletin will be for Internet Explorer to address limited, targeted attacks against customers of Internet Explorer 6, as well as fixes for vulnerabilities rated Critical that are not currently under active attack.</p>
<p>The full version of the Microsoft Security Bulletin Advance Notification for this release can be found at  <a href="http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx">http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx</a>.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2010%2F01%2Fie-out-of-band-patch%2F&amp;title=IE%20out%20of%20band%20patch" id="wpa2a_8"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2010/01/ie-out-of-band-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Issues Critical Updates To Flash, AIR &#8211; Security Watch</title>
		<link>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/</link>
		<comments>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 09:11:25 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[adobe]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=276</guid>
		<description><![CDATA[Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild. Click here to install Flash 10.0.42.34. Click here to install AIR 1.5.3. The expanded security advisory explains that critical [...]]]></description>
			<content:encoded><![CDATA[<p>Adobe released new versions of Flash and AIR today to address vulnerabilities in both products. Applying these updates as soon as practicable is a good idea, as Flash vulnerabilities are popular exploit vehicles in the wild.</p>
<p><a href="http://get.adobe.com/flashplayer/" target="_blank">Click here to install Flash 10.0.42.34.</a></p>
<p><a href="http://get.adobe.com/air/" target="_blank">Click here to install AIR 1.5.3.</a></p>
<p><a href="http://www.adobe.com/support/security/bulletins/apsb09-19.html" target="_self">The expanded security advisory</a> explains that critical vulnerabilities could provoke crashes or remote code execution. Adobe Flash Player 10.0.32.18 and earlier versions and Adobe AIR 1.5.2 and earlier versions on all platforms are vulnerable.</p>
<p>7 new vulnerabilities are described cursorily. A patch to an eighth and older vulnerability is also updated. Adobe issues thanks to 6 different researchers for the help they provided with the vulnerabilities.</p>
<p>The advisory also adds that Flash Player version 10.1, which Adobe expects to release in the first half of 2010, will be the last to support PowerPC-based G3 Macs. They are discontinuing support, including security updates, past that version because they are implementing performance enhancements not supported in those processors.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F12%2Fadobe-issues-critical-updates-to-flash-air-security-watch%2F&amp;title=Adobe%20Issues%20Critical%20Updates%20To%20Flash%2C%20AIR%20%26%238211%3B%20Security%20Watch" id="wpa2a_10"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/12/adobe-issues-critical-updates-to-flash-air-security-watch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla fixes 16 flaws with Firefox 3.5.4:</title>
		<link>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/</link>
		<comments>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/#comments</comments>
		<pubDate>Thu, 29 Oct 2009 06:47:55 +0000</pubDate>
		<dc:creator>derek</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[mozilla]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://hijack-this.co.uk/?p=196</guid>
		<description><![CDATA[http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4 Mozilla fixes 16 flaws with Firefox 3.5.4: http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4  Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4.   The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4">http://www.mozilla.org/security/known-vulnerabilities/firefox35.html#firefox3.5.4</a></p>
<p>Mozilla fixes 16 flaws with Firefox 3.5.4:</p>
<p><a href="http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4">http://www.computerworld.com/s/article/9140008/Mozilla_fixes_16_flaws_with_Firefox_3.5.4</a></p>
<p> Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4. </p>
<p> The 11 critical Firefox 3.5 vulnerabilities were located in a variety ofn components, including Web worker calls, the GIF color map parser, the string-to-number converter, a trio of third-party media libraries, and both the JavaScript and browser engines.</p>
<p><a class="a2a_dd a2a_target addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fhijack-this.co.uk%2F2009%2F10%2Fmozilla-fixes-16-flaws-with-firefox-3-5-4%2F&amp;title=Mozilla%20fixes%2016%20flaws%20with%20Firefox%203.5.4%3A" id="wpa2a_12"><img src="http://hijack-this.co.uk/wp-content/plugins/add-to-any/share_save_171_16.png" width="171" height="16" alt="Share"/></a></p>]]></content:encoded>
			<wfw:commentRss>http://hijack-this.co.uk/2009/10/mozilla-fixes-16-flaws-with-firefox-3-5-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

