7 Reasons Websites Are No Longer Safe

Wednesday, September 9th, 2009

Conventional wisdom is that Web wanderers are safe as long as they avoid sites that serve up pornography, stock tips, games and the like. But according to recently gathered research from Boston-based IT security and control firm Sophos, sites we take for granted are not as secure as they appear.Among ...

Shutting Down XSS with Content Security Policy

Tuesday, June 23rd, 2009

For several years, Cross-Site Scripting (XSS) attacks have plagued many of the web’s most popular sites and victimized their users. At Mozilla, we’ve been working for the last year on a new technology called Content Security Policy, designed to shut these attacks down. We wanted to give a bit of ...

Mass Injection Attack Affects 40,000 Websites

Tuesday, June 2nd, 2009

Researchers at Websense have discovered a mass injection attack that is redirecting Web browsers to a malware-bearing site. According to a weekend report by researchers at Websense, thousands of legitimate Web sites have been discovered to be injected with malicious Javascript, obfuscated code that leads to an active exploit site. "The active ...

Firefox 3.0.9 Released

Tuesday, April 21st, 2009

Firefox 3.0.9 fixes several security issues found in Firefox 3.0.8: Firefox allows Refresh header to redirect to javascript: URIs POST data sent to wrong site when saving web page with embedded frame Malicious search plugins can inject code into arbitrary sites Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString XSS hazard using third-party stylesheets and XBL bindings Same-origin violations ...

Compromised Site: Peugeot

Wednesday, March 25th, 2009

Websense Security Labs ThreatSeeker Network has discovered that the official Web site of Peugeot in Romania has been compromised and is infecting the machines of site visitors with malicious code. Malicious code has been inserted onto the reported page of the site via iframes. These iframes redirect to the pages ...