Defeating drive by downloads in Windows

There is a good article in Internet Storm Center about Malicious Forum Posts.A"victim"is reading about a computer problem and happen upon a thread that the attacker has placed malicious content. It would be safe to say watch clicking on hyperlinks. Good reading at the Internet Storm Center’s website…Paul

People are getting paid to exploit common vulnerabilities in forum software.They inject iframes, and instead of using search engine poisoning they do forums. ,…paul

and they can post malicious urls because forums are ranked highly in search engines.

That's very true @ Tywin7

 

 

Cheers!

This has changed my way of navigating the internet forever. I rarely use scripts and if I do it is at a site I trust and for one application only. I have used NoScript with Firefox and it is OK but difficult to configure so I just use “no scripts” and have been for a long time…You will get all kind of arguments about NoScript being fantastic but it can be a major headache and he wants $15 now. . There is no way to defend yourself except with the difficult to configure NoScript…Sandboxing is another option I guess. Saving for a Mac is the best choice.I have read the SAS Internet Storm Center website for years and that is why I brought up this thread. Hope everyone enjoyed the info. Paul

I’m going to take some time away, thanks for all the info you have all shared with me…Really great forum!..regards, Paul

 


pehhawaiiisland wrote:
This has changed my way of navigating the internet forever. I rarely use scripts and if I do it is at a site I trust and for one application only. I have used NoScript with Firefox and it is OK but difficult to configure so I just use "no scripts" and have been for a long time...You will get all kind of arguments about NoScript being fantastic but it can be a major headache and he wants $15 now. . There is no way to defend yourself except with the difficult to configure NoScript...Sandboxing is another option I guess. Saving for a Mac is the best choice.I have read the SAS Internet Storm Center website for years and that is why I brought up this thread. Hope everyone enjoyed the info. Paul

You don't need to configure NoScript, the default settings should be adequate protection. Further things you can do in options is to forbid Webugs, and IFRAME. Any sites you trust you just add the URL to the whitelist if you want. I don't know why you are having problems, and it is news to me about the $15, I have never heard Giorgio mention that he is going to start charging for Noscript.

 

$ 15.00 is the suggested donation if someone wants to make a contribution to NoScript :-)

https://addons.mozilla.org/en-US/firefox/addon/722/


Yaso_Kuuhl wrote:

$ 15.00 is the suggested donation if someone wants to make a contribution to NoScript :-)

https://addons.mozilla.org/en-US/firefox/addon/722/


Yes, exactly it is the suggested donation. It is still available for free for anyone who cannot afford to make a donation. As far as I am aware Giorgio has no plans to stop making it available for free.