Jump to content


Spyware Barely Touches Firefox


  • You cannot start a new topic
  • You cannot reply to this topic
7 replies to this topic

#1 jram

    Administrator

  • 14,795 posts
  • Joined: October 04, 2004
  • 1,674 topics
  • Age: 63
  • Skin: Delicate Blue
  • Local time: 04:33 PM
  • Zodiac:Aries
  • Gender:Male
  • Interests:Love my Mac,along with Windows 7
  • OS:Mac
  • Country:
Offline
  • Time Online: 26d 18h 35m 5s

Posted 10 February 2006 - 08:01 PM

Internet Explorer users can be as much as 21 times more likely to end up with a spyware-infected PC than people who go online with Mozilla's Firefox browser, academic researchers from Microsoft's backyard said in a recently published paper.
ADVERTISEMENT
[0]


"We can't say whether Firefox is a safer browser or not," said Henry Levy, one of the two University of Washington professors who, along with a pair of graduate students, created Web crawlers to scour the Internet for spyware in several 2005 forays. "But we can say that users will have a safer experience [surfing] with Firefox."

In May and October, Levy and colleague Steven Gribble sent their crawlers to 45,000 Web sites, cataloged the executable files found, and tested malicious sites' effectiveness by exposing unpatched versions of Internet Explorer and Firefox to "drive-by downloads." That's the term for the hacker practice of using browser vulnerabilities to install software, sometimes surreptitiously, sometimes not.

"We can't say IE is any less safe," explained Levy, "because we choose to use an unpatched version [of each browser.] We were trying to understand the number of [spyware] threats, so if we used unpatched browsers then we would see more threats."

Levy and Gribble, along with graduate students Alexander Moshchuk and Tanya Bragin, set up IE in two configurations -- one where it behaved as if the user had given permission for all downloads, the other as if the user refused all download permission -- to track the number of successful spyware installations.

During Levy's and Gribble's most recent crawl of October 2005, 1.6 percent of the domains infected the first IE configuration, the one mimicking a na�ve user blithely clicking 'Yes;' about a third as many domains (0.6 percent) did drive-by downloads by planting spyware even when the user rejected the installations.

"These numbers may not sound like much," said Gribble, "but consider the number of domains on the Web."

"You definitely want to have all the patches [installed] for Internet Explorer," added Levy.

In the same kind of configurations, Firefox survived relatively unscathed. Only .09 percent of domains infected the Mozilla Corp. browser when it was set, like IE, to act as if the user clicked through security dialogs; no domain managed to infect the Firefox-equipped PC in a drive-by download attack.

Compare those figures, and it seems that IE users who haven't patched their browser are 21 times more likely to have a spyware attack executed -- if not necessarily succeed -- against their machine.

Most of the exploits that leveraged IE vulnerabilities to plant spyware were based on ActiveX and JavaScript, said Gribble. Those two technologies have taken the blame for many of IE problems. In fact, Firefox boosters often point to their browser's lack of support for ActiveX as a big reason why its security claims are legit.

Levy and Gribble didn't set out to verify that, but they did note that the few successful spyware attacks on Firefox were made by Java applets; all, however, required the user's consent to succeed.

Microsoft's made a point to stress that Internet Explorer 7, which just went into open beta for
Windows XP, tightens up ActiveX controls by disabling nearly all those already installed. IE 7 then alerts the user and requires consent before it will run an in-place control.

Good thing, because one of the research's most startling conclusions was the number of spyware-infected sites. One out of every 20 executable files on Web sites is spyware, and 1 in 25 domains contain at least one piece of spyware waiting for victims.

"If these numbers are even close to representative for Web sites frequented by users," the paper concluded, "it is not surprising that spyware continues to be of major concern."

The moral, said Levy, is: "If you browse, you're eventually going to get hit with a spyware attack."
Macintosh
~The computer for the rest of us~ Posted Image

#2 Guest_mlurp_* Re: Spyware Barely Touches Firefox

  • Joined: --
  • 1,674 topics
Offline

Posted 11 February 2006 - 05:34 AM

My fully patched IE 6.0 has servered me well and weekly security checks and daily updates keep it that way. So far I haven't had any items on my machine in several months. That is due to the fact I have stopped D/L any freeware. trying to get ready for the forced SP 2 upgrade.
Now I run a few security apps to maintain my security as shown. SpywareBlaster isn't shown but runs in the background as Trojan Remover.

Attached Images

  • Attached Image: My_Security001.jpg

Edited by mlurp, 14 February 2006 - 04:41 AM.


#3 jram Re: Spyware Barely Touches Firefox

    Administrator

  • 14,795 posts
  • Joined: October 04, 2004
  • 1,674 topics
  • Age: 63
  • Skin: Delicate Blue
  • Local time: 04:33 PM
  • Zodiac:Aries
  • Gender:Male
  • Interests:Love my Mac,along with Windows 7
  • OS:Mac
  • Country:
Offline
  • Time Online: 26d 18h 35m 5s

Posted 11 February 2006 - 11:12 AM

Quote

My fully patched IE 6.0
Try IE 7, you will like it.. Everybody here that has tried it, likes it. :fat_face_smiling:
Macintosh
~The computer for the rest of us~ Posted Image

#4 Guest_mlurp_* Re: Spyware Barely Touches Firefox

  • Joined: --
  • 180 topics
Offline

Posted 13 February 2006 - 02:54 AM

I want to but haven't put SP 2 on the machine yet. I thought IE 7 was for Sp 2 alone...

#5 jram Re: Spyware Barely Touches Firefox

    Administrator

  • 14,795 posts
  • Joined: October 04, 2004
  • 1,674 topics
  • Age: 63
  • Skin: Delicate Blue
  • Local time: 04:33 PM
  • Zodiac:Aries
  • Gender:Male
  • Interests:Love my Mac,along with Windows 7
  • OS:Mac
  • Country:
Offline
  • Time Online: 26d 18h 35m 5s

Posted 13 February 2006 - 11:40 AM

Quote

I want to but haven't put SP 2 on the machine yet.
Anybody can get it, maybe when the final release comes out you might need SP2, but not now..

Attached Images

  • Attached Image: av_25.gif

Macintosh
~The computer for the rest of us~ Posted Image

#6 Guest_mlurp_* Re: Spyware Barely Touches Firefox

  • Joined: --
Offline

Posted 14 February 2006 - 04:39 AM

Oh then I miss read the info. thanks for correcting me. Now a link would also be nice. but then your old advise to google it might also work.
Guess I need to change avatars as this one has gone and gotten a virus of some sort. lol

#7 dobhar Re: Spyware Barely Touches Firefox

    Member

  • 6,611 posts
  • Joined: October 07, 2004
  • Skin: IP.Board
  • Local time: 03:33 PM
  • Zodiac:Aquarius
  • Gender:Not Telling
  • OS:other
  • Country:
Offline
  • :

Posted 14 February 2006 - 05:12 AM

lurpy...

FYI...

Microsoft said:

Evaluation of Internet Explorer 7 should start now, but the software should not be used on production systems in mission-critical environments. Internet Explorer 7 Beta 2 Preview will only run on Windows® XP Service Pack 2 (SP2) systems, but will ultimately be available for Windows Vista, Windows XP Professional x64 Edition, and Windows Server 2003.
Download linky => http://www.microsoft...taredirect.mspx

#8 jram Re: Spyware Barely Touches Firefox

    Administrator

  • 14,795 posts
  • Joined: October 04, 2004
  • Age: 63
  • Skin: Delicate Blue
  • Local time: 04:33 PM
  • Zodiac:Aries
  • Gender:Male
  • Interests:Love my Mac,along with Windows 7
  • OS:Mac
  • Country:
Offline
  • Time Online: 26d 18h 35m 5s

Posted 14 February 2006 - 05:26 AM

IE beta 1 runs on anything..right here
Macintosh
~The computer for the rest of us~ Posted Image





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users


This topic has been visited by 0 user(s)