Windower: GUIDE: Protecting your web browser. - Windower

Jump to content

  • 4 Pages +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • This topic is locked

GUIDE: Protecting your web browser. Rate Topic: ***** 1 Votes

#1 User is offline   Aikar 

  • delete world; world = new Planet("Code");
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Retired Windower Members
  • Posts: 4,045
  • Joined: 19-April 05
  • Gender:Male
  • Location:Raleigh, NC
  • Interests:PHP, FFXI, C++
  • Name: Aikar, Aikari
  • Server: Leviathan
  • Jobs: WHM75 BLM75
  • Race: Tarutaru Male
  • Linkshell: Eternia

Posted 30 December 2007 - 10:40 PM

As everyone knows, People are getting hacked left and right. FFXI is under attack by the chinese RMT by methods of Website instrusion and placing of malicious malware code that executes a key logger on victims PC's.

There is protection you need to use to protect yourself from these attacks.

Normally when loading a persons browser with Firefox Extensions or telling them which ones to get, I wouldnt ever load NoScript if they were not tech-savvy enough to understand how it works.

but this hacking stuff is becoming too much of a problem so heres your made-of-steel condom guide for the internet.
Now, I know theres plenty of guides out there saying use firefox+abp+ns etc, but none the guides actually tell you how noscript works for those non tech-savvy people. So heres a full guide (with pictures) for non tech-savvy people.


  • ==== Browser Changes ====
    • --- Securing Internet Explorer ---
      • Update to IE7 if your still using IE6 (even if you use firefox). IE6 is horrible to even have on your PC. IE7 can be found on the Microsoft website, and should be a recommended update when you do Windows Update on your computer.
      • Open your Internet Explorer (even if you use firefox): Tools -> Internet Options
        Posted Image
      • Go to the Security Tab, and on the Internet Zone, change the Slidebar to High (max).
        Posted Image
      • Go to the Privacy Tab, and click Advanced (Medium Slider should be sufficient). Enable the override checkbox, Prompt for first party cookies, block 3rd party cookies, and always allow session cookies. Click Ok.
        Posted Image
      • Go to the Advanced Tab, and uncheck both Enable third-party browser extensions and Enable websites to use the search pane. Click OK once these changes are made and close IE. Your done securing it.
        Posted Image

    • --- Switching to Firefox ---
      • Our goal above was to secure IE for use of only trusted websites such as Microsoft.com and use Firefox which offers you much more secure tools when browsing.
      • Download Firefox: Here (Instructions for Installing Firefox on that website)
      • Upon start it will ask to be your default browser. CLICK YES! It will also ask to Import your Internet Explorer Settings such as bookmarks. Go through the wizard and bring your bookmarks and such over.
      • Time to get extensions. Heres how you normally get extensions: Go to Tools -> Add-ons -> Click Get Extensions. However I'm just going to give you direct links to them to help you out.
        Posted Image

  • ==== Putting on your condoms (configuring) ====
    • Click OK or Close any popup's that spawn upon opening Firefox. (I already have these installed, so I cant remember exactly what pops up so well go from the menu's to configure them).
    • **Go to Tools -> Addons: we will do this step multiple times for extensions. Each extension you installed will have an Options button on it that we need to configure (with exception to FlashBlock, the default settings are fine)
    • AdBlock:

    • NoScript:
      • Open NoScript options, and go to the Plugins Tab -> Make sure all of the RED CIRCLED checkboxes are selected. DO NOT SELECT THE BOTTOM BOLDED CHECKBOX!!
        Posted Image
      • Go to the Advanced Tab, You will see Sub-Tabs -> Click on Untrusted Tab (if not already selected). You want to make sure all of these are selected.
        Posted Image
      • Click OK to finish.

  • ==== Using your condoms (browsing) ====
    • NoScript:
      • NoScript blocks all unknown websites from executing javascript on load.
      • It also blocks all unknown sites from using 3rd party plugins such as Flash and Java
      • Many websites use javascript to function properly.. Upon visiting a site that uses JavaScript, Flash, Java Applets and more, you will notice the NoScript Icon in the bottom right corner of your Firefox.
        • Posted Image: This means ALL javascript was blocked. The site may not function correctly, or it might work fine. it all depends on how the sites coded to use the javascript.
        • Posted Image: This means javascript was PARTIALLY blocked. This means the site your visiting was allowed to run javascript (or did not contain any) however a 3rd party URL (an address thats not the same website) was blocked from being ran.
          4/5 times this means some ad websites javascript was blocked. In most cases your website your visiting will function correctly, and noscript is doing its job: blocking the unwanted javascript.
        • Posted Image: This means ALL javascript on this website was allowed to run, or else the website did not contain any javascript. This site will function just as if you did not have NoScript.

      • By default you will also receive notification on the bottom with a big bar (this bar can be told to not show).
      • If the website your using needs javascript to run (things are not working properly), you may simply click the NoScript icon, and you will see in Bold Letters "Allow domain.tld" or by option you can allow it temporarily.
        Posted Image
      • If you choose to only allow it temporarily, noscript will block that website again the next time you reopen firefox (its saved until you close firefox).
      • If you choose to allow (the bold letters) this site will always be allowed to run javascript.
      • How do you know which sites need to be allowed? Simple: None unless they dont work without it. When you visit a site, browse it normal. If things arnt working such as links misbehaving or not working at all, and scripts are blocked, enable it temporarily. Does the link now work? If so, then it needs the javascript.
        If you add a site to temporary allow that you want to perma allow, you need to remove the temporary allow (as in reblock it) then choose the permanent option.
      • Next you ask, what if you allow javascript on these trusted websites, how is that protecting you from the malware? These malware infections are linking offsite to other websites. Remember that 2nd icon (Partially blocked)?
        That malware website its linking to will not have permission to be ran in noscript. Your root website your viewing will, but that extra url will be blocked because its not the same address.
        Posted Image
        The only case you will be vulnerable to the javascript is if the malware infectors add their virus code to the websites server itself (so that its not linking to another website).
        This is very possible for them to do, but they in general want to link it to their own site so they may modify the virus code when they need and log whos being infected -- so they in general wont (or cant) do this approach,
        so noscript will be protecting you.

        A blocked flash player will also display a NoScript icon showing its blocked. Simply click the NS icon to display it if needed (It will auto be allowed if the current site its coming from is already allowed)

        You generally will not need to run most flash applications on a web page unless its for navigational purposes or a video player. Most sites use flash for ads or logos, which you do not need to see.

        For sites like youtube and such, adding them to allow list to view videos easier is recommended.


  • ==== Additional Security Measures ====
    Following the above guide will provide you a condom made of steel, and protect you from at least 95% of possible infections.
    A good first layer of security on your browser is the best step at protecting yourself from infection. However, theres always a chance something new comes out and bypasses your first layer of protection, so there is additional things to be sure you have.
    • Anti Virus: Some like to argue this is the most important thing. I have to disagree, an anti virus software is only useful if your first layer of protection is penetrated. Following my guide above puts you in very low chance that it ever is penetrated.
      Common sense, Web Browser Security and safe browsing habits are the most important thing in securing your PC.
      However, its a good thing to have that backup protection in place to possibly catch the new exploits.

      I STRONGLY recommend Avast. Avast has state of the art protection even in the free edition, and uses very little resources. Compared to AVG, Avast is Steel and AVG is Plastic.
      If you have the money, get ESET Smart Security, a non free AV/Firewall/AS suite and one the highest ranked.

    • Firewall: Ok, so you got some nasty trojan that bypassed BOTH of your 2 layers of protection (Secure Browsing, AntiVirus), theres one final Layer, a software firewall.

      Software firewalls alert you when unknown applications are trying to connect to the internet. So even if you are key logged, your firewall is going to ask "Can this program you have no clue what the hell is connect to some website you have no clue what the hell is with some information?"

      Pretty obvious answer. Keylogger DENIED!
      I recommend Sygate Personal Firewall. Its very quiet beyond the questions about allowing applications - Doesnt eat up resources - and it even knows when an application changes to reask for permission.

    • Install AntiSpyware: Spybot Search & Destroy is one of the leading spyware removal and prevention tools. Best of all, its free! Spybot S&D has tools to help prevent you from getting Spyware -- however, it shouldnt catch 'much' as your first layer should be blocking spyware too.

    • Uninstall Real Player & QuickTime: Access your Control Panel by clicking your Start Menu then going to Control Panel. Then go to Add & Remove Programs. Wait a minute for the list to build, and then check it for anything about "Real Player" and Quicktime.

      Is it installed? If so, REMOVE IT! Quicktime/Real Player are devil applications that some of the main reasons many are losing their accounts.
      Get rid of them, get rid of any piece of trash that relies on it. You have 2 options: Keep your FFXI account or keep Real Player, decide now.
    • Save your PlayOnline Password!!!! - Most trojans are key loggers, and monitor key strokes to steal your password. While this isnt fullproof, I have not heard of the new password file format being cracked, and even if so, this is the least likely method of them stealing your password.
      If you need to keep people out of your account on your PC, use that alternate password lock thing and use a DIFFERENT PASSWORD!!
    • Keep flash updated!! - Go to http://adobe.com and keep flash updated.
    • Keep your PC up to date with Windows Updates. We had security beefed up on Internet Explorer in the first part of the guide, but Microsoft.com is automatically in Trusted group so it will be fine.

      If you want to update your PC without even using Internet Explorer, there is a free update website called WindizUpdate for Firefox users that offers all of the Windows Updates that Microsoft offers.


There you go, Safe Surfing.
- RETIRED - I am no longer working on the Windower project and have retired from MMO's entirely to work on my personal RL goals and creating my own MMO game, follow up on what im doing @ Aikar.co
- FFOChat - Join the FFXI Community!
1

#2 User is offline   aceofspades 

  • App Developer
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,368
  • Joined: 27-September 06
  • Gender:Male
  • Location:Texas

Posted 30 December 2007 - 10:51 PM

Aikar said:

Save your PlayOnline Password!!!! - No, The trojans ARE NOT downloading your saved password file and decrypting it. The recent trojans have been investigated and they are simple key loggers, they are not stealing files, and to our knowledge the encryption scheme has not been cracked by the RMT yet.

Saving your password is a great idea, as you no longer have to type it to log in! Cant be key logged now.


your password file can be transferred to another pc though with no checks
Before making an ass out of yourself, please Posted Image Search
Posted Image

Rocl said:

he was born a poor white child in the suburbs of Detroit where he brutally murdered the mid-wife for looking at him lovingly. That's right, murder- straight out the womb. In his later years, he got Windows Vista. WILLINGLY. If that doesn't send a shiver down your spine, you aren't human.

lolLJ http://x-aceofspades-x.livejournal.com
0

#3 User is offline   Aikar 

  • delete world; world = new Planet("Code");
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Retired Windower Members
  • Posts: 4,045
  • Joined: 19-April 05
  • Gender:Male
  • Location:Raleigh, NC
  • Interests:PHP, FFXI, C++
  • Name: Aikar, Aikari
  • Server: Leviathan
  • Jobs: WHM75 BLM75
  • Race: Tarutaru Male
  • Linkshell: Eternia

Posted 30 December 2007 - 11:08 PM

gg ace give them ideas!
- RETIRED - I am no longer working on the Windower project and have retired from MMO's entirely to work on my personal RL goals and creating my own MMO game, follow up on what im doing @ Aikar.co
- FFOChat - Join the FFXI Community!
0

#4 User is offline   aceofspades 

  • App Developer
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,368
  • Joined: 27-September 06
  • Gender:Male
  • Location:Texas

Posted 31 December 2007 - 01:48 AM

well i thought thats how they got me first off

but then i realised you still need old password to change password

i only posted that as a warning, bc they can still hack your account and liquidate just not change info
Before making an ass out of yourself, please Posted Image Search
Posted Image

Rocl said:

he was born a poor white child in the suburbs of Detroit where he brutally murdered the mid-wife for looking at him lovingly. That's right, murder- straight out the womb. In his later years, he got Windows Vista. WILLINGLY. If that doesn't send a shiver down your spine, you aren't human.

lolLJ http://x-aceofspades-x.livejournal.com
0

#5 User is offline   Genesisx 

  • General Moderator
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Moderators
  • Posts: 1,641
  • Joined: 06-August 07
  • Gender:Not Telling

Posted 31 December 2007 - 10:58 AM

You being targeted makes me worried. I just got back from being out of town. Was visiting folks for the X-mas holidays. Came back though and everything was still intact. Glad I never type my password lol.
0

#6 User is offline   Emelyn 

  • Jedi
  • PipPipPipPipPipPipPip
  • Group: Members
  • Posts: 533
  • Joined: 19-April 05
  • Gender:Female
  • Server: Lakshmi

Posted 31 December 2007 - 02:02 PM

Thanks for the ABP subscription links. I always used just Fliterset.g but I will look into those now.
FFXI - Retired
Please Posted Image before posting.

FFXI Vista Guide/Support

Posted Image
0

#7 User is offline   souleman 

  • Jedi Grandmaster
  • PipPipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,659
  • Joined: 29-August 07
  • Gender:Male
  • Location:Michigan
  • Name: Souleman
  • Server: Phoenix
  • Jobs: RDM
  • Race: Elvaan Male
  • Linkshell: TheUsualSuspects

Posted 31 December 2007 - 02:16 PM

Great post Aikar.. Not only isn't the typical "don't use IE" that you see everywhere, but actually shows people how to set stuff up. Yeah, the programs are really simple now (especially comapred to how they were when they came out), but this is good for eveyone, not just people playing ffxi.


I did want to point out you might wanna check for an update to noscript. My Plugins page looks different then yours.
0

#8 User is offline   aceofspades 

  • App Developer
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,368
  • Joined: 27-September 06
  • Gender:Male
  • Location:Texas

Posted 31 December 2007 - 02:29 PM

i would like to note a possible exploit found on wordpress blogs that will still be run with the default abp and noscript setups

http://www.bluegartrls.com/forum/viewtopic...=865818#p865818

for more info
Before making an ass out of yourself, please Posted Image Search
Posted Image

Rocl said:

he was born a poor white child in the suburbs of Detroit where he brutally murdered the mid-wife for looking at him lovingly. That's right, murder- straight out the womb. In his later years, he got Windows Vista. WILLINGLY. If that doesn't send a shiver down your spine, you aren't human.

lolLJ http://x-aceofspades-x.livejournal.com
0

#9 User is offline   Aikar 

  • delete world; world = new Planet("Code");
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Retired Windower Members
  • Posts: 4,045
  • Joined: 19-April 05
  • Gender:Male
  • Location:Raleigh, NC
  • Interests:PHP, FFXI, C++
  • Name: Aikar, Aikari
  • Server: Leviathan
  • Jobs: WHM75 BLM75
  • Race: Tarutaru Male
  • Linkshell: Eternia

Posted 31 December 2007 - 03:30 PM

aceofspades said:

i would like to note a possible exploit found on wordpress blogs that will still be run with the default abp and noscript setups

http://www.bluegartrls.com/forum/viewtopic...=865818#p865818

for more info


That's actually why i posted this. Now people cant even view their linkshell websites safely.
- RETIRED - I am no longer working on the Windower project and have retired from MMO's entirely to work on my personal RL goals and creating my own MMO game, follow up on what im doing @ Aikar.co
- FFOChat - Join the FFXI Community!
0

#10 User is offline   banannaphone 

  • Member
  • PipPipPip
  • Group: Members
  • Posts: 60
  • Joined: 08-January 06

Posted 01 January 2008 - 03:07 PM

Quote

Great post Aikar.. Not only isn't the typical "don't use IE" that you see everywhere, but actually shows people how to set stuff up. Yeah, the programs are really simple now (especially comapred to how they were when they came out), but this is good for eveyone, not just people playing ffxi.


I did want to point out you might wanna check for an update to noscript. My Plugins page looks different then yours.


qft x2.



I also found some interesting posts on Allakhazam about this topic-

How to prevent yourself from being hacked Part I:
http://ffxi.allakhazam.com/forum.html?foru...3;num=37;page=1

How to prevent yourself form being hacked Part II:
http://ffxi.allakhazam.com/forum.html?foru...68;num=1;page=1

Protect Your PC- A Guide
http://ffxi.allakhazam.com/forum.html?foru...023532218128862



Take everything with a grain of salt though-the third guide had the wrong Spybot S&D Hyperlink.


Just thought I'd add:
Firewalls are like condoms- if you use more than one you might end up with no protection!
0

#11 User is offline   aceofspades 

  • App Developer
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,368
  • Joined: 27-September 06
  • Gender:Male
  • Location:Texas

Posted 01 January 2008 - 03:11 PM

software firewalls are a bunch of bullshit anyway

dont rely on software to protect you from software
Before making an ass out of yourself, please Posted Image Search
Posted Image

Rocl said:

he was born a poor white child in the suburbs of Detroit where he brutally murdered the mid-wife for looking at him lovingly. That's right, murder- straight out the womb. In his later years, he got Windows Vista. WILLINGLY. If that doesn't send a shiver down your spine, you aren't human.

lolLJ http://x-aceofspades-x.livejournal.com
0

#12 User is offline   banannaphone 

  • Member
  • PipPipPip
  • Group: Members
  • Posts: 60
  • Joined: 08-January 06

Posted 01 January 2008 - 07:01 PM

I have a 512mb 2.3gHz firewall before it gets to my router :)
0

#13 User is offline   Calina 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 127
  • Joined: 07-July 05

Posted 02 January 2008 - 03:01 AM

thanks Aikar been wanting to use no script for a while but dident want to mess anything up this helped alot^^
Posted Image
Posted Image
0

#14 User is offline   Aikar 

  • delete world; world = new Planet("Code");
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Retired Windower Members
  • Posts: 4,045
  • Joined: 19-April 05
  • Gender:Male
  • Location:Raleigh, NC
  • Interests:PHP, FFXI, C++
  • Name: Aikar, Aikari
  • Server: Leviathan
  • Jobs: WHM75 BLM75
  • Race: Tarutaru Male
  • Linkshell: Eternia

Posted 02 January 2008 - 04:17 AM

banannaphone said:

I have a 512mb 2.3gHz firewall before it gets to my router :)

lol man ram and processor speed dont make firewalls better =P
- RETIRED - I am no longer working on the Windower project and have retired from MMO's entirely to work on my personal RL goals and creating my own MMO game, follow up on what im doing @ Aikar.co
- FFOChat - Join the FFXI Community!
0

#15 User is offline   banannaphone 

  • Member
  • PipPipPip
  • Group: Members
  • Posts: 60
  • Joined: 08-January 06

Posted 02 January 2008 - 11:31 AM

Quote

banannaphone wrote:
I have a 512mb 2.3gHz firewall before it gets to my router Smile

lol man ram and processor speed dont make firewalls better =P


Yeah, but they make my ego bigger. :)
0

#16 User is offline   Setesh 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 123
  • Joined: 30-October 05
  • Gender:Male
  • Name: Setesh
  • Server: Fenrir
  • Jobs: WHM SMN BLU BLM SCH COR PLD DNC DRG
  • Race: Hume Male
  • Linkshell: Frenzy

Posted 02 January 2008 - 12:14 PM

Aikar said:

Saving your password is a great idea, as you no longer have to type it to log in! Cant be key logged now.

Unless PlayOnline is constantly forgetting that you stored your password. :roll: Still, this is all really good info, very nice Aikar.
0

#17 User is offline   aceofspades 

  • App Developer
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 1,368
  • Joined: 27-September 06
  • Gender:Male
  • Location:Texas

Posted 02 January 2008 - 02:09 PM

pol forgetting your saved password is one of the symptoms of one of the trojans/malware infections, please check your pc if you havent already

and just because you may or may not have followed OP to the T, your still at risk
Before making an ass out of yourself, please Posted Image Search
Posted Image

Rocl said:

he was born a poor white child in the suburbs of Detroit where he brutally murdered the mid-wife for looking at him lovingly. That's right, murder- straight out the womb. In his later years, he got Windows Vista. WILLINGLY. If that doesn't send a shiver down your spine, you aren't human.

lolLJ http://x-aceofspades-x.livejournal.com
0

#18 User is offline   Zal 

  • Trainee
  • Pip
  • Group: Members
  • Posts: 18
  • Joined: 08-June 07

Posted 12 January 2008 - 03:59 AM

Thanks for the tip on the firewall. I never used one because most were bulky piles of crap that didn't actually block anything.

Sygate is snappy and quick, I love it.
0

#19 User is offline   Genesisx 

  • General Moderator
  • PipPipPipPipPipPipPipPipPipPip
  • Group: +Moderators
  • Posts: 1,641
  • Joined: 06-August 07
  • Gender:Not Telling

Posted 12 January 2008 - 04:36 AM

Setesh said:

Unless PlayOnline is constantly forgetting that you stored your password. :roll:

Ya.. total
~Red Flag~
0

#20 User is offline   Setesh 

  • Advanced Member
  • PipPipPipPip
  • Group: Members
  • Posts: 123
  • Joined: 30-October 05
  • Gender:Male
  • Name: Setesh
  • Server: Fenrir
  • Jobs: WHM SMN BLU BLM SCH COR PLD DNC DRG
  • Race: Hume Male
  • Linkshell: Frenzy

Posted 12 January 2008 - 02:59 PM

I've been watching for strange activity on my computer though... odd programs, processes I don't recognize, registry entries... and strange programs trying to connect to the Internet. Nothing. I really don't know what's causing it.
0

Share this topic:


  • 4 Pages +
  • 1
  • 2
  • 3
  • Last »
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users