<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Trenches &#187; Firefox</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/it-trenches/tag/firefox/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/it-trenches</link>
	<description></description>
	<lastBuildDate>Fri, 19 Nov 2010 14:37:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Google has published a browser security handbook for developers</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/google-has-published-a-browser-security-handbook-for-developers/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/google-has-published-a-browser-security-handbook-for-developers/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 13:02:55 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[browser]]></category>
		<category><![CDATA[browser security]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web development]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/google-has-published-a-browser-security-handbook-for-developers/</guid>
		<description><![CDATA[If you develop websites or manage webservices, then you should check out the Browser Security Handbook that Google publishes on their code.google.com website. The Browser Security Handbook currently has three sections: Part 1: Basic concepts behind web browsers Uniform Resource Locators Unicode in URLs True URL schemes Pseudo URL schemes Hypertext Transfer Protocol Hypertext Markup [...]]]></description>
				<content:encoded><![CDATA[<p>If you develop websites or manage webservices, then you should check out the <a href="http://code.google.com/p/browsersec/wiki/Main" target="_blank">Browser Security Handbook</a> that Google publishes on their <a href="http://code.google.com" target="_blank">code.google.com</a> website. The Browser Security Handbook currently has three sections:</p>
<p>Part 1: Basic concepts behind web browsers</p>
<ul>
<li>Uniform Resource Locators
<ul>
<li>Unicode in URLs</li>
</ul>
</li>
<li>True URL schemes</li>
<li>Pseudo URL schemes</li>
<li>Hypertext Transfer Protocol</li>
<li>Hypertext Markup Language
<ul>
<li>HTML entity encoding</li>
</ul>
</li>
<li>Document Object Model</li>
<li>Browser-side Javascript
<ul>
<li>Javascript character encoding</li>
</ul>
</li>
<li>Other document scripting languages</li>
<li>Cascading stylesheets
<ul>
<li>CSS character encoding</li>
</ul>
</li>
<li>Other built-in document formats</li>
<li>Plugin-supported content</li>
</ul>
<p>Part 2: Standard browser security features</p>
<ul>
<li>Same-origin policy
<ul>
<li>Same-origin policy for DOM access</li>
<li>Same-origin policy for XMLHttpRequest</li>
<li>Same-origin policy for cookies</li>
<li>Same-origin policy for Flash</li>
<li>Same-origin policy for Java</li>
<li>Same-origin policy for Silverlight</li>
<li>Same-origin policy for Gears</li>
<li>Origin inheritance rules</li>
<li>Cross-site scripting and same-origin policies</li>
</ul>
</li>
<li>Life outside same-origin rules
<ul>
<li>Navigation and content inclusion across domains</li>
<li>Arbitrary page mashups (UI redressing)</li>
<li>Gaps in DOM access control</li>
<li>Privacy-related side channels</li>
</ul>
</li>
<li>Various network-related restrictions
<ul>
<li>Local network / remote network divide</li>
<li>Port access restrictions</li>
<li>URL scheme access rules</li>
<li>Redirection restrictions</li>
<li>International Domain Name checks</li>
<li>Simultaneous connection limits</li>
</ul>
</li>
<li>Third-party cookie rules</li>
<li>Content handling mechanisms
<ul>
<li>Survey of content sniffing behaviors</li>
<li>Downloads and Content-Disposition</li>
<li>Character set handling and detection</li>
<li>Document caching</li>
</ul>
</li>
<li>Defenses against disruptive scripts
<ul>
<li>Popup and dialog filtering logic</li>
<li>Window appearance restrictions</li>
<li>Execution timeouts and memory limits</li>
<li>Page transition logic</li>
</ul>
</li>
<li>Protocol-level encryption facilities</li>
</ul>
<p>Part 3: Experimental and legacy security mechanisms</p>
<ul>
<li>HTTP authentication</li>
<li>Name look-ahead and content prefetching</li>
<li>Password managers</li>
<li>Microsoft Internet Explorer zone model</li>
<li>Microsoft Internet Explorer frame restrictions</li>
<li>Mozilla and Safari HTML5 storage experiments</li>
<li>Microsoft Internet Explorer XSS filtering</li>
<li>Script restriction frameworks</li>
<li>Origin headers</li>
<li>Mozilla content security policies</li>
</ul>
<p>This is a good resource for developers and administrators to understand browser &amp; web security considerations.</p>
<p>Thanks for reading and let&#8217;s continue to be good network citizens.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/google-has-published-a-browser-security-handbook-for-developers/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Holiday greeting cards, holiday shopping and computer security awareness</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/holiday-greeting-cards-holiday-shopping-and-computer-security-awareness/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/holiday-greeting-cards-holiday-shopping-and-computer-security-awareness/#comments</comments>
		<pubDate>Wed, 03 Dec 2008 15:50:08 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[administration]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[data loss]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[education]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Firewalls]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[SSL]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/holiday-greeting-cards-holiday-shopping-and-computer-security-awareness/</guid>
		<description><![CDATA[I just sent this email reminder to all users in my organization. I would recommend you do something similar if you are not already ensuring users are aware of these issues. Feel free to use my content and add your own.  It is that time of year again when folks send electronic holiday greeting cards [...]]]></description>
				<content:encoded><![CDATA[<p> <!--[if gte mso 9]&amp;gt;     Normal   0               false   false   false      EN-US   X-NONE   X-NONE                                                     MicrosoftInternetExplorer4                                                   --><!--[if gte mso 9]&amp;gt;                                                                                                                                                                                                                                                                                                                                                                                                                                --> <!--  /* Font Definitions */  @font-face 	{font-family:"Cambria Math"; 	panose-1:2 4 5 3 5 4 6 3 2 4; 	mso-font-alt:"Calisto MT"; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1107304683 0 0 159 0;} @font-face 	{font-family:Calibri; 	panose-1:2 15 5 2 2 2 4 3 2 4; 	mso-font-alt:"Century Gothic"; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:-1610611985 1073750139 0 0 159 0;} @font-face 	{font-family:Verdana; 	panose-1:2 11 6 4 3 5 4 4 2 4; 	mso-font-charset:0; 	mso-generic-font-family:swiss; 	mso-font-pitch:variable; 	mso-font-signature:536871559 0 0 0 415 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-unhide:no; 	mso-style-qformat:yes; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Verdana","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman";} a:link, span.MsoHyperlink 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:blue; 	text-decoration:underline; 	text-underline:single;} a:visited, span.MsoHyperlinkFollowed 	{mso-style-noshow:yes; 	mso-style-priority:99; 	color:purple; 	mso-themecolor:followedhyperlink; 	text-decoration:underline; 	text-underline:single;} p.MsoListParagraph, li.MsoListParagraph, div.MsoListParagraph 	{mso-style-priority:34; 	mso-style-unhide:no; 	mso-style-qformat:yes; 	margin-top:0in; 	margin-right:0in; 	margin-bottom:0in; 	margin-left:.5in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Verdana","sans-serif"; 	mso-fareast-font-family:Calibri; 	mso-fareast-theme-font:minor-latin; 	mso-bidi-font-family:"Times New Roman";} .MsoChpDefault 	{mso-style-type:export-only; 	mso-default-props:yes; 	font-size:10.0pt; 	mso-ansi-font-size:10.0pt; 	mso-bidi-font-size:10.0pt;} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.0in 1.0in 1.0in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;}  /* List Definitions */  @list l0 	{mso-list-id:403718830; 	mso-list-type:hybrid; 	mso-list-template-ids:1134166048 67698703 67698713 67698715 67698703 67698713 67698715 67698703 67698713 67698715;} @list l0:level1 	{mso-level-tab-stop:none; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level2 	{mso-level-tab-stop:1.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level3 	{mso-level-tab-stop:1.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level4 	{mso-level-tab-stop:2.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level5 	{mso-level-tab-stop:2.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level6 	{mso-level-tab-stop:3.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level7 	{mso-level-tab-stop:3.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level8 	{mso-level-tab-stop:4.0in; 	mso-level-number-position:left; 	text-indent:-.25in;} @list l0:level9 	{mso-level-tab-stop:4.5in; 	mso-level-number-position:left; 	text-indent:-.25in;} ol 	{margin-bottom:0in;} ul 	{margin-bottom:0in;} --> <!--[if gte mso 10]&amp;gt;   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-priority:99; 	mso-style-qformat:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman","serif";}  --></p>
<p class="MsoNormal">I just sent this email reminder to all users in my organization. I would recommend you do something similar if you are not already ensuring users are aware of these issues. Feel free to use my content and add your own.</p>
<p class="MsoNormal"> It is that time of year again when folks send electronic holiday greeting cards to one another. Some of the greetings may also be games that bear holiday messages. It is also a time when malicious software spreads using these same types of messages and software. You should also be cautious when doing any holiday shopping online or at stores. It is important that you and those you communicate with understand these risks. Your finances and identity are always at risk in today&#8217;s technology environment, but you may be less attentive during the holiday season. The following 10 tips are meant to remind you of some important security precautions.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>1.<span>    </span></span></span><!--[endif]-->Do NOT use your company email address for personal holiday greetings or shopping activities. Merchants may sell your email address to other non-reputable sources and this puts your company identity at risk.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>2.<span>    </span></span></span><!--[endif]-->If you receive personal holiday greetings or &#8220;cute&#8221; games at your company email address, ask the sender to not send those to you at work. Use a personal email account for those communications.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>3.<span>    </span></span></span><!--[endif]-->If you do receive holiday greetings or games at your personal email address, check with the sender before opening to be sure they sent the message. Spammers and malicious software writers can easily deceive you through social engineering. They will do everything possible to get you to open their message and potentially damage your computer and/or harvest your email address as a valid address.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>4.<span>    </span></span></span><!--[endif]-->Don&#8217;t trust everything you see online. Finding something on the internet does not guarantee that it is true. Anyone can publish information online, so before accepting a statement as fact or taking action, verify that the source is reliable.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>5.<span>    </span></span></span><!--[endif]-->If it looks too good to be true, it probably is. You have probably seen many emails promising fantastic rewards or monetary gifts. However, regardless of what the email claims, there are not any wealthy strangers desperate to send you money. Beware of grand promises—they are most likely spam, hoaxes, or phishing schemes. Also be wary of pop-up windows and advertisements for free downloadable software—they may be disguising spyware. Close the pop-up windows by clicking the X in the top right corner. Do not click the YES, NO, or CANCEL buttons in the window. It may cause unwanted computer issues if you do. Do not trust what you see in these pop-up windows. Contact IT support if you have any questions or issues.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>6.<span>    </span></span></span><!--[endif]-->Avoid phishing schemes. Banks and other institutions will not actively solicit personal information by email. When you click a link in an email asking for this type of information, your choice may risk your finances and personal identity. The link may take you to a website hosted by someone with malicious intentions. If you enter your personal information on the website, you have just had your identity taken by a social engineering attack and may have incurred a financial loss.</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>7.<span>    </span></span></span><!--[endif]-->If you are unsure whether an email request is legitimate, try to verify it by contacting the company directly. Do not use contact information provided on a web site connected to the request; instead, check previous statements for contact information. Information about known phishing attacks is also available online from groups such as the Anti-Phishing Working Group (<a href="http://www.antiphishing.org/phishing_archive.html">http://www.antiphishing.org/phishing_archive.html</a>).</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>8.<span>    </span></span></span><!--[endif]-->If you believe your financial accounts may be compromised, contact your financial institution immediately and close any accounts that may have been compromised. Watch for any unexplainable charges to your account. Consider reporting the attack to the police, and file a report with the Federal Trade Commission (<a href="http://www.ftc.gov/">http://www.ftc.gov/</a>).</p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>9.<span>    </span></span></span><!--[endif]-->Do not participate in forwarding chain letters or perpetuating hoaxes or urban legends. Hoaxes attempt to trick or defraud users. A hoax could be malicious, instructing users to delete a file necessary to the operating system by claiming it is a virus. It could also be a scam that convinces users to send money or personal information. Phishing attacks could fall into this category. Urban legends are designed to be redistributed and usually warn users of a threat or claim to be notifying them of important or urgent information. Another common form are the emails that promise users monetary rewards for forwarding the message or suggest that they are signing something that will be submitted to a particular group. Urban legends usually have no negative effect aside from wasted network bandwidth, server resources and time. If you want to check the validity of an email, there are some web sites that provide information about hoaxes and urban legends: Urban Legends and Folklore &#8211; <a href="http://urbanlegends.about.com/">http://urbanlegends.about.com/</a>;  Urban Legends Reference Pages &#8211; <a href="http://www.snopes.com/">http://www.snopes.com/</a>; Hoaxbusters &#8211; <a href="http://hoaxbusters.ciac.org/">http://hoaxbusters.ciac.org/</a>; TruthOrFiction.com &#8211; <a href="http://www.truthorfiction.com/">http://www.truthorfiction.com/</a>; Symantec Security Response Hoaxes &#8211; <a href="http://www.symantec.com/avcenter/hoax.html">http://www.symantec.com/avcenter/hoax.html</a>; McAfee Security Virus Hoaxes &#8211; <a href="http://vil.mcafee.com/hoax.asp">http://vil.mcafee.com/hoax.asp</a></p>
<p class="MsoListParagraph">&nbsp;</p>
<p class="MsoListParagraph"><!--[if !supportLists]--><span><span>10.<span> </span></span></span><!--[endif]-->Protect yourself while shopping online. Use and maintain anti-virus software, a firewall, and anti-spyware software. Keep software, particularly your web browser, up to date. Do business with reputable vendors. Take advantage of security features like secure passwords and encrypting information between your computer and the vendor&#8217;s website (look for the &#8220;lock&#8221; symbol in the browser or the website address beginning with &#8220;https&#8221; rather than &#8220;http&#8221;. Use a credit card rather than a debit card. Check your statements for any unusual or unauthorized activity.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">Hopefully these tips will help you and those around you to have a happy holiday and reduce the risk of an unwelcome holiday event due to being uninformed. Please feel free to share these tips with your friends and family to help increase awareness and reduce risky behavior.</p>
<p class="MsoNormal">&nbsp;</p>
<p class="MsoNormal">See the <a href="http://www.us-cert.gov/cas/tips/" target="_blank">CERT Cyber Security Tips</a> website for more information like this.</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/holiday-greeting-cards-holiday-shopping-and-computer-security-awareness/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Did you see this? &#8211; Encyclopedia of internal network security threats</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/#comments</comments>
		<pubDate>Fri, 19 Sep 2008 12:53:21 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Browsers]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[design]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[homeland security]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[man-in-the-middle]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[research]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[tools]]></category>
		<category><![CDATA[troubleshooting]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/</guid>
		<description><![CDATA[Promisec has released an online encyclopedia of internal network security threats. This is available online for free. There is a lot of information to look through and decide how the risks affect your organization. Take for example the entry describing GoogleTalk. The site rates it as one of the top 5 internal threats. The more [...]]]></description>
				<content:encoded><![CDATA[<p><a href="http://http://www.promisec.com/encyclopedia/" target="_blank">Promisec</a> has released an online encyclopedia of internal network security threats. This is available online for free. There is a lot of information to look through and decide how the risks affect your organization.</p>
<p>Take for example the entry describing <a href="http://www.promisec.com/encyclopedia/InternalThreatsDetails.asp?catID=6394&amp;itemID=37255" target="_blank">GoogleTalk</a>. The site rates it as one of the top 5 internal threats.</p>
<p>The more we know about these risks the better prepared we can be. Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/did-you-see-this-encyclopedia-of-internal-network-security-threats/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browser warnings &#8211; Danger Will Robinson! &#8211; or did it just cry &#8220;Wolf!&#8221;?</title>
		<link>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/</link>
		<comments>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/#comments</comments>
		<pubDate>Tue, 08 Jul 2008 17:12:33 +0000</pubDate>
		<dc:creator>Troy Tate</dc:creator>
				<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[awareness]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[Data security]]></category>
		<category><![CDATA[Development]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[forensics]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[honeynet]]></category>
		<category><![CDATA[honeypot]]></category>
		<category><![CDATA[IT education]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[Metrics]]></category>
		<category><![CDATA[online identity]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[policy enforcement]]></category>
		<category><![CDATA[reporting]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[web]]></category>
		<category><![CDATA[website]]></category>
		<category><![CDATA[WWW]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/</guid>
		<description><![CDATA[I sometimes browse the internet using Firefox. I say sometimes because Internet Explorer is the standard browser at my company and Firefox is not supported by IT. Well, since I work in IT, sometimes you have to test things on behalf of users and also to see how certain sites are different depending on the [...]]]></description>
				<content:encoded><![CDATA[<p>I sometimes browse the internet using Firefox. I say sometimes because Internet Explorer is the standard browser at my company and Firefox is not supported by IT. Well, since I work in IT, sometimes you have to test things on behalf of users and also to see how certain sites are different depending on the client browser.</p>
<p>Well, I recently upgraded Firefox to v3. It does seem much better than v2 although some of my useful addins are now broken (when will YSlow get fixed for v3?). One of the new features of Firefox v3 is the ability to report to the user if the visited website is a known potential malware site. This is a good feature! It provides the user with some useful information and education about the dangers on the internet. However, how accurate is this feature? What if you are visiting a trusted website that you frequently visit and now get this message?</p>
<p>For your information, this is the message that you will see when you attempt to visit a site deemed as risky.</p>
<p><strong>Reported Attack Site!</p>
<p>This web site at certification.xxxxxxx.org has been reported as an attack site and has been blocked based on your security preferences.</p>
<p>Attack sites try to install programs that steal private information, use your computer to attack others, or damage your system.</p>
<p>Some attack sites intentionally distribute harmful software, but many are compromised without the knowledge or permission of their owners.</strong></p>
<p>I blanked out the actual website address above. However, those of you with a bit of detective in you are likely going to figure it out.</p>
<p>What is interesting about this particular warning message is that it is referring to a website that has security as a guiding principle. When you see this message in Firefox, you have three options presented:</p>
<ul>
<li>Get me out of here!</li>
<li>Why was this site blocked?</li>
<li>Ignore this warning &#8211; in very tiny print at bottom of message.</li>
</ul>
<p>I was curious as to why this site would be considered as a danger. I clicked on the <em>Why was this site blocked?</em> option. The report I received was interesting and as I mentioned earlier, could this be an example of someone crying &#8220;Wolf!&#8221;?</p>
<p>The report was as follows:</p>
<p class="d"><strong>What is the current listing status for certification.xxxxxxx.org/?</strong></p>
<blockquote><p>Site is listed as suspicious &#8211; visiting this web site may harm your computer.</p>
<p>Part of this site was listed for suspicious activity 1 time(s) over the past 90 days.</p></blockquote>
<p class="d"><strong>What happened when Google visited this site?</strong></p>
<blockquote><p>Of the 6 pages we tested on the site over the past 90 days, 1 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 07/06/2008, and the last time suspicious content was found on this site was on 07/06/2008.</p>
<p>Malicious software includes 1 scripting exploit(s). Successful infection resulted in an average of 3 new processes on the target machine.</p>
<p>Malicious software is hosted on 3 domain(s), including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=lokriet.com">lokriet.com</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=clrbbd.com">clrbbd.com</a>, <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=catdbw.mobi">catdbw.mobi</a>.</p>
<p>1 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including <a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=catdbw.mobi">catdbw.mobi</a>.</p></blockquote>
<p class="d"><strong>Has this site acted as an intermediary resulting in further distribution of malware?</strong></p>
<blockquote><p>Over the past 90 days, certification.xxxxxxx.org/ did not appear to function as an intermediary for the infection of any sites.</p></blockquote>
<p class="d"><strong>Has this site hosted malware?</strong></p>
<blockquote><p>No, this site has not hosted malicious software over the past 90 days.</p></blockquote>
<p class="d"><strong>How did this happen?</strong></p>
<blockquote><p>In some cases, third parties can add malicious code to legitimate sites, which would cause us to show the warning message.</p></blockquote>
<p class="d"><strong>Next steps:</strong></p>
<ul>
<li><a href="http://safebrowsing.clients.google.com/safebrowsing/diagnostic?client=Firefox&amp;hl=en-US&amp;site=http://certification.comptia.org/#">Return to the previous page</a>.</li>
<li>If you are the owner of this web site, you can request a review of your site using Google <a href="http://www.google.com/webmasters/tools/">Webmaster Tools</a>. More information about the review process is available in Google&#8217;s <a href="http://www.google.com/support/webmasters/bin/answer.py?answer=45432">Webmaster Help Center</a>.</li>
</ul>
<p>This is great educational stuff, but did it really happen to this particular website? I don&#8217;t know, but apparently Google does. With the report of just one incident, does it make this site really worth the notification? How many incidents should it take before a site is considered malicious and who determines what malicious is?</p>
<p>Just something else to mull over in your copious time as you go perusing websites in Firefox.</p>
<p>Thanks for your time. Let’s be good network citizens together &amp; practice safe networking!</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/it-trenches/browser-warnings-danger-will-robinson-or-did-it-just-cry-wolf/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
