Then check DOM inside your browser..

Hi malware fighters,

Check DOM issues: http://lcamtuf.coredump.cx/dom_checker/

polonus

Opera = Failed checks: 60
IE8 = Failed checks: 39

The sky is falling said Chicken Little.

Had to get rid of all firefox security add-ons (NoScript, RequestPolicy) to get it to even work :wink:

Then only 14 errors (image1), though I did get a warning displayed (image2) during the test, haven’t a clue what it is ;D

40 failed checks in IE8 but guess what—I’m not worried.

The only time this works is if I allow it to by turning off my firefox addons.
So, since I do not use internet explody…I guess I am good :slight_smile:

Thanks but no thanks. I don’t have java.

Scott’s cool. 8)

nmb

It doesn’t use JAVA to run the test, but requires javascript, entirely different.

Hi DavidR,

There were 43 security issues with Browzar used on XP SP3
to mention a few here:
CHECK FAILED : open() frame name lookup is possible!
CHECK FAILED : for (e in (third-party)) iterator is possible!
CHECK FAILED : (third-party).frames[0] probe [value: [object]] is possible!
CHECK FAILED : (third-party).frames.length read [value: 2] is possible!
CHECK FAILED : for (e in (third-party).frames) iterator is possible!
CHECK FAILED : (third-party).onresize write (readback) is possible!
CHECK FAILED : (third-party).onhashchange write (readback) is possible!
CHECK FAILED : (blank).onunload write (readback) is possible!
CHECK FAILED : (blank).onafterprint write (readback) is possible!

polonus

Are you sure, sir? It asks me to install java (firefox)

nmb

I got the error too David,

I win this game (firefox):

Failed checks: 459
Oh wait, that's not right is it? ;D

I didn’t get asked this… ???

-Scott-

Hi scott,

I mean this (see pic) : when I visit the site, it asks me to install jre. Which i dont want to.

Hi nmb,

I see what you mean now…

Initially I didn’t allow the two iframes at the bottom in NS, so I didn’t see this…It is the iframe that points here:

hXXp://213.134.128.25/lcamtuf/dom_target_page.html

When you allow this, the install plugins thing pops up…at which point I say no… :slight_smile:

-Scott-

When JAVA is running you should see the JAVA icon in the system tray.

The iframe tags are used to retrieve the data of the tests into the actual page and iframe is blocked by the Firefox, Options, Embeddings Forbid iframe if you checked this option, like I have.

Java can’t run on my system, it asks to install…

The iframe tags are used to retrieve the data of the tests into the actual page and iframe is blocked by the Firefox, Options, Embeddings Forbid iframe if you checked this option, like I have.

Maybe that is why mine failed so horribly…but then IE doesn’t have any trouble without JAVA…I don’t know…
I do have that setting checked in NS…

The point being it doesn’t ask me to install as it is installed, but then it doesn’t appear to use it (no JAVA applet loading or icon in the tray) and the test completes.

Just right click on the iframe place holder indicating it is blocked by your firefox settings and allow the 2 iframes to load and run the test again. It should be able to complete then and you will see it isn’t a JAVA issue but your firefox settings (which aren’t in IE to easily block or allow iframes).

Ok, fair enough, but why try to install java if it is not used? :-\

Just right click on the iframe place holder indicating it is blocked by your firefox settings and allow the 2 iframes to load and run the test again. It should be able to complete then and you will see it isn't a JAVA issue but your firefox settings (which aren't in IE to easily block or allow iframes).

Ok, that is better… Only 15 failed this time…still don’t see why they push for java installation…

-Scott-

I don’t know why they pop-up the JAVA plug-in install, but it doesn’t use/require JAVA or IE would fail if it didn’t have JAVA (it may has an activeX JAVA handler, which is possibly what one of the tests checks), but it would still require JAVA if it was truly needed.

There you go scotty… you got what I wanted to tell.

@ sir DavidR,

If it is not using java, then why is it asking as to install java? may be it uses java for a short period of time that u dont see the icon in system tray? or may be you have hidden it?

nmb

Flock with(NS,AB)= Failed checks: 452
Mozilla with (NS,RP,AB)= Failed checks: 459
IE8=Failed checks: 42

Flock without(NS,AB)=Failed checks: 14
Mozilla without(NS,RP,AB)=Failed checks: 14