|
|||||||
| Home | Photo Gallery | Register | All Albums | Blogs | Forum FAQ | FlashChat | Members List | Calendar | Search | Today's Posts | Mark Forums Read | Vendor Directory |
| Notices |
| Welcome to Yotatech! |
|
|
Welcome to Yotatech, You are currently viewing our forum as a guest, which gives you limited access to view most discussions and access our other features. By joining our community, at no cost, you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is free, fast and simple, so please join our community today! |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#1 (permalink) | |||||
|
Contributing Member
Join Date: Nov 2003
Location: Portland, Oregon
Posts: 1,509
|
|
|||||
|
|
|
|
|
#2 (permalink) |
|
Registered User
Join Date: Feb 2003
Location: CA
Posts: 484
|
OS X running Safari:
High Risk Vulnerabilities - 0 Medium Risk Vulnerabilities - 0 Low Risk Vulnerabilities - 0
__________________
Matt 2003 V8 Titanium Limited 4x4 X-REAS |
|
|
|
|
|
#3 (permalink) |
|
Co-Founder/Administrator
Staff
Join Date: May 2002
Location: Auburn, Washington
Posts: 26,077
|
IE 6
Browser Security Test Results Dear Customer, The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0
__________________
Corey 2007 FJ Cruiser Built for 4wheelin', expedition, camping, and overlanding use PNW FJ Cruisers ☺ Detailing 101 ☺ Join Topsites ☺ Muffler Comparisons ☺ Maggiolinas In The Wild FJ Cruiser Buildup ☺ New Roof Top Tent ☺ Video Of My Penthouse Part II ☺ Rehinge Your ARB/Engel Fridge Blog About Roof Top Tents ☺ FJC Magazines Online Review Of My Tent ☺ 2009 Specialized Rockhopper Pro |
|
|
|
|
|
#4 (permalink) |
|
Contributing Member
Join Date: Feb 2004
Location: tulsa, OK
Posts: 1,329
|
Dear Customer,
The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 1 Low Risk Vulnerabilities 0 The vulnerability it said I have? Shell: protocol is handled by Windows Explorer. It apears that it is possible to open local files and folders from a web page using the shell: protocol URLs. For example "shell:windows" URL will open the Windows directory. On Windows XP it is also possible to start local programs, for example "shell:windows\system32\calc.exe" will start Calculator. funny thing is I run linux, I think the error message Opera popped up fooled the test into thinking it had opened a browser window.
__________________
Brian 85 sr5, 5spd - back on the road, doing DD duty for now 86 2wd reg cab - future project 90 sr5, 97 - gone |
|
|
|
|
|
#5 (permalink) |
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Excellent find. I updated the JRE and am clean.
Thanks man!
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
|
|
|
|
|
#6 (permalink) |
|
Contributing Member
|
Firefox:
High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0
__________________
07 4runner 4.7 SR5 98 4runner 3.4 SR5 87 FJ60 |
|
|
|
|
|
#7 (permalink) |
|
Contributing Member
Join Date: Sep 2002
Location: Mission, British Columbia
Posts: 1,558
|
Firefox:
High Risk Vulnerabilities 1 I had to update my jre also. Something about a script leaving a sandbox :-)
__________________
2006 4Runner V8 Sports Edition Red 1997 4Runner 3.4L Bushwacker Flares, 5spd, E locker |
|
|
|
|
|
#8 (permalink) | |
|
Contributing Member
Join Date: Nov 2003
Location: Portland, Oregon
Posts: 1,509
|
Quote:
|
|
|
|
|
|
|
#9 (permalink) |
|
Contributing Member
|
I can't kick this one. I followed the directions and updated java but still can't shake it. What is it?
Browser name: MSIE Version: 6.0 Platform: Windows NT 5.1 Browser Security Test Results Dear Customer, The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 1 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0 High Risk Vulnerabilities Sun Java Plugin Arbitrary Package Access Vulnerability (idef20041123) Description Java Plugin allows web browsers to run Java applets. Java plugin may be used by Internet Explorer, Mozilla (and Mozilla-base browsers, such as Firefox), Opera and other browsers. When a browser opens a web page that contains a Java applet the browser automatically downloads the applet and runs it locally. To protect the user from malicious applets all the applets run in so called "sandbox". The sandbox restricts what an applet can do. For example, the sandbox will not allow an applet to open local files or start programs. This bug in Sun Java Plugin allows a web site to bypass the sandbox and execute Java code that the sandbox will normally not allow and possibly gain control over the client computer. Technical Details Sun Java Virtual Machine contains sun.* packages that are only supposed to be used internally, by the virtual machine itself. Some private classes allow direct access to memory or modifying private fields of Java objects. If an applet attempts to load one of those packages a security exception is thrown. If an applet could load those classes it could turn off Java Security Manager and break out of Java sandbox. JavaScript can access properties and methods of Java applets embedded on the page. It is possible to load a private package from JavaScript as shown in the code below: var c=document.applets[0].getClass().forName('sun.text.Utility'); alert('got Class object: '+c) Java Reflection API allows objects to examine their own structure (for example, find out the class of the object or the available methods). Reflection API defines getClass() function that returns the object's class. forName method of Class object loads the named class. The same operation done from the Java applet instead of JavaScript would fail. Recommendations Upgrade Java Environment to version 1.4.2_06 or later. It can be downloaded from http://java.sun.com/j2se/1.4.2/download.html Additional Information Jouko Pynnonen. Sun Java Plugin arbitrary package access vulnerability Last edited by ewarnerusa; 01-03-2005 at 09:01 PM. |
|
|
|
|
|
#10 (permalink) |
|
Contributing Member
Join Date: Jan 2004
Posts: 3,577
|
WinXP + IE6.0 = 0-0-0
__________________
|
|
|
|
|
|
#11 (permalink) |
|
Contributing Member
Join Date: Oct 2002
Location: Duvall, WA
Posts: 5,109
|
IE6 XP SP2
High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0
__________________
-Rob Slightly Modified 2001 Tacoma - WATRD.COM WATTORA is becoming NWToys! Tread Lightly! certified Tread Trainer Search 100+ Toyota tech sites, including this one: Toyota Tech Search |
|
|
|
|
|
#12 (permalink) | |
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Quote:
If so, then to get it to "take", you have to back all the way out of IE and get the JRE (Java Runtime Engine) to shutdown. You can check this by noting if you still have the "coffee cup" sitting in your systray. If you do, then something is keeping it open, and you may have to restart Windows. Once you restart IE, then come into the test page, and note if you have the coffee cup again. Right click on it, pick "about", and then note the version number. It should be 1.4.2_06. If it's not, then something didn't "take" from the install and you'll have to try again. If you tried the network install (the <2meg download) then try the standalone install. If the coffee cup _never_ shows in the systray, then you're not running the JRE. To set this up, from IE go to:
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
|
|
|
|
|
|
#13 (permalink) | |
|
Contributing Member
|
Quote:
|
|
|
|
|
|
|
#14 (permalink) |
|
Registered User
Join Date: Oct 2003
Location: On a trail in WA.
Posts: 1,439
|
Dear Customer,
The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 1 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0 What the...............I am at work. I would think things would be safe. High Risk Vulnerabilities Sun Java Plugin Arbitrary Package Access Vulnerability (idef20041123) Description Java Plugin allows web browsers to run Java applets. Java plugin may be used by Internet Explorer, Mozilla (and Mozilla-base browsers, such as Firefox), Opera and other browsers. When a browser opens a web page that contains a Java applet the browser automatically downloads the applet and runs it locally. To protect the user from malicious applets all the applets run in so called "sandbox". The sandbox restricts what an applet can do. For example, the sandbox will not allow an applet to open local files or start programs. This bug in Sun Java Plugin allows a web site to bypass the sandbox and execute Java code that the sandbox will normally not allow and possibly gain control over the client computer. Technical Details Sun Java Virtual Machine contains sun.* packages that are only supposed to be used internally, by the virtual machine itself. Some private classes allow direct access to memory or modifying private fields of Java objects. If an applet attempts to load one of those packages a security exception is thrown. If an applet could load those classes it could turn off Java Security Manager and break out of Java sandbox. JavaScript can access properties and methods of Java applets embedded on the page. It is possible to load a private package from JavaScript as shown in the code below: var c=document.applets[0].getClass().forName('sun.text.Utility'); alert('got Class object: '+c) Java Reflection API allows objects to examine their own structure (for example, find out the class of the object or the available methods). Reflection API defines getClass() function that returns the object's class. forName method of Class object loads the named class. The same operation done from the Java applet instead of JavaScript would fail. Recommendations Upgrade Java Environment to version 1.4.2_06 or later. It can be downloaded from http://java.sun.com/j2se/1.4.2/download.html Looks like an easy fix..............
__________________
Ben |
|
|
|
|
|
#15 (permalink) | |
|
Registered User
Join Date: Oct 2003
Location: On a trail in WA.
Posts: 1,439
|
Quote:
__________________
Ben |
|
|
|
|
|
|
#16 (permalink) | ||
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Quote:
The file is named "j2re-1_4_2_06-windows-i586-p-iftw.exe", and it comes from:
Quote:
![]() When you get a chance, do the right_click, then pick "about" and check the version number. Let's start from there and see what you're working with before we come up with a plan of attack.
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
||
|
|
|
|
|
#17 (permalink) |
|
Registered User
Join Date: Oct 2003
Location: On a trail in WA.
Posts: 1,439
|
Here is my IE at work
Dear Customer, The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 2 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0 WTF!!!! High Risk Vulnerabilities Sun Java Plugin Arbitrary Package Access Vulnerability (idef20041123) Description Java Plugin allows web browsers to run Java applets. Java plugin may be used by Internet Explorer, Mozilla (and Mozilla-base browsers, such as Firefox), Opera and other browsers. When a browser opens a web page that contains a Java applet the browser automatically downloads the applet and runs it locally. To protect the user from malicious applets all the applets run in so called "sandbox". The sandbox restricts what an applet can do. For example, the sandbox will not allow an applet to open local files or start programs. This bug in Sun Java Plugin allows a web site to bypass the sandbox and execute Java code that the sandbox will normally not allow and possibly gain control over the client computer. Technical Details Sun Java Virtual Machine contains sun.* packages that are only supposed to be used internally, by the virtual machine itself. Some private classes allow direct access to memory or modifying private fields of Java objects. If an applet attempts to load one of those packages a security exception is thrown. If an applet could load those classes it could turn off Java Security Manager and break out of Java sandbox. JavaScript can access properties and methods of Java applets embedded on the page. It is possible to load a private package from JavaScript as shown in the code below: var c=document.applets[0].getClass().forName('sun.text.Utility'); alert('got Class object: '+c) Java Reflection API allows objects to examine their own structure (for example, find out the class of the object or the available methods). Reflection API defines getClass() function that returns the object's class. forName method of Class object loads the named class. The same operation done from the Java applet instead of JavaScript would fail. Recommendations Upgrade Java Environment to version 1.4.2_06 or later. It can be downloaded from http://java.sun.com/j2se/1.4.2/download.html Additional Information Jouko Pynnonen. Sun Java Plugin arbitrary package access vulnerability Internet Explorer Modal Dialog Argument Caching Cross-Domain Scripting Vulnerability (jel20040607) Description This bug allows a malicious web page to execute any programs on your computer. A malicious hacker can take complete control over your computer using this bug. The bug can be exploited by a web page you browse or HTML email mesage you open. This bug was discovered "in the wild" and is used by malicious web sites to install adware on visitors' computers. Technical Details This cross-domain scripting vulnerability allows executing JavaScript code in the context of any domain. Combined with other Internet Explorer vulnerabilities it allows executing code in Local Computer security zone, leading to installation and execution of arbitrary programs. First a malicious page creates an IFRAME pointing that redirects to a page in the target domain (or Local Computer zone). Then a modal dialog is created and the reference to the IFRAME is passed to the dialog in dialogArguments parameter of showModalDialog function. The modal dialog caches the reference to the IFRAME and waits until IFRAME's domain changes due to the redirect. Then the dialog page closes itself and returns the cached reference. The original page receives the window reference from the modal dialog and changes the location of this window to a javascript: URL. The JavaScript code gets executed in the context of the domain to which the IFRAME was redirected. Recommendations We recommend using Windows Update to correct this problem. Additional Information Rafel Ivgi, The-Insider. 180 Solutions Exploits and Toolbars Hacking Patched Users. NTBugTraq Posting. Jelmer. Internet explorer 6 execution of arbitrary code (An analysis of the 180 Solutions Trojan) Microsoft Security Bulletin MS04-025
__________________
Ben |
|
|
|
|
|
#18 (permalink) | |
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Quote:
Are you getting the coffee cup in the systray after when you're on the test site? If so, then you're running Sun's JRE.. If you never get the coffee cup, then: (ewarnerusa you may want to look here as well):
Give that a shot.
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
|
|
|
|
|
|
#19 (permalink) |
|
Contributing Member
|
yeah, i definitely downloaded the top two downloads when you click that link. The "SDK" ones. When I get home I guess I can try the smaller JRE only one and see if it takes. Thanks for the help!
EDIT: should I uninstall the java's first before trying again? Last edited by ewarnerusa; 01-04-2005 at 09:21 AM. |
|
|
|
|
|
#20 (permalink) | |
|
Contributing Member
|
Quote:
|
|
|
|
|
|
|
#21 (permalink) | |
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Quote:
And... it wouldn't hurt to uninstall the SDK before installing the JRE. It's more of a "just to be sure" type thing, but it will also save you a bunch of disk space. Good luck!
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
|
|
|
|
|
|
#22 (permalink) |
|
Contributing Member
|
MIDIWALL
I'm all set now, I installed the JRE file this time and reran the test with 0-0-0 results. Thanks for the help. My sys tray coffee cup is blue now instead of white. |
|
|
|
|
|
#23 (permalink) |
|
Registered User
Join Date: Oct 2003
Location: On a trail in WA.
Posts: 1,439
|
My Laptop
Firefox Dear Customer, The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0 IE6 Dear Customer, The Browser Security Test is finished. Please find the results below: High Risk Vulnerabilities 0 Medium Risk Vulnerabilities 0 Low Risk Vulnerabilities 0
__________________
Ben Last edited by GRNTACO; 01-04-2005 at 10:14 PM. |
|
|
|
|
|
#24 (permalink) | |
|
Sponsoring Member
Join Date: Dec 2002
Location: Seattleish, WA
Posts: 9,078
|
Quote:
Ben, it looks like you're set as well. Cool!
__________________
~ Mark '96 4Runner Limited S/C MI - 370cc injectors, Air! horns, Airaid MIT, ATS A-arms, 285/75/R16 BFG MTs, Bored TB, Brembo slotted, Cobra 75 WXST, Deckplate, Downey headers, Hayden cooler, IPT valve body, Level 10 torque convertor, Meanstreak exhaust, OME/OME rears, On-board PC (XM, Nav, WiFi, etc), Port 'n Polish, Remote Start, SAW fronts, Hilux console, SMT-5, Stubb's sliders, Supra MAF, TJM-17, 2.0" pulley, Viair 450c, Walbro 190, Weasy2k cams |
|
|
|
|
![]() |
| Tags |
| bccheckscanit |
| Thread Tools | Search this Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How to secure taller-than-stock height battery? | T4R 4ME | General Vehicle Related Topics (Non Year Related) | 15 | 01-09-2007 03:39 AM |
| How does everyone secure gear? | Texas Jim | Newbie Tech Section | 14 | 11-15-2006 09:59 PM |
| HOw do you secure your ride??? | deathrunner | General Vehicle Related Topics (Non Year Related) | 68 | 02-18-2006 03:09 AM |
| do you secure your roof basket? | kato | 95.5-2004 Tacomas & 96-2002 4Runners | 13 | 07-28-2005 11:55 PM |
| How SECURE is your FIREWALL? | amusement | Computer Talk | 24 | 02-13-2005 05:11 PM |