Web Browsers White Papers
Extensible Web Browser Security
Overview This paper examines the security issues in functionality extension mechanisms supported by web browsers. Extensions (or "Plug-ins") in modern web browsers enjoy unlimited power without restraint and thus are attractive vectors for malware. To solidify the claim, the paper takes on the role of malware writers looking to assume control of a user's browser space. The paper has taken advantage of the lack of security mechanisms for browser extensions and have implemented a piece of malware for the popular Firefox web browser, which is called BROWSERSPY, that requires no special privileges to be installed. Once installed, BROWSERSPY takes complete control of a user's browser space and can observe all the activity performed through the browser while being undetectable.
| Publisher | University of Illinois | File Format | |
|---|---|---|---|
| Date Published | April 2007 | ||
| Format | White Papers | ||
| Topics | |||
MSDN Webcast: Internet Explorer 8 for Developers (Level 200)
Windows Internet Explorer 8 ushers in a new wave of browser innovation from Microsoft, including Web Slices and Accelerators, while maintaining compatibility with the today's Web standards. The presenter of...
MSDN Webcast: Designing Creative DHTML, Silverlight UIs: Simple, Visualized & Intuitive (Level 300)
The presenter of this webcast shows off the new point and click Visual WebGui Control & Theme Designer. This designer joins the well known drag and drop Visual WebGui Form...
MSDN Webcast: Silverlight Controls Framework (Level 100)
The presenter of this webcast provides an overview of the Microsoft Silverlight controls and controls model. The presenter shows how to use Silverlight controls and how to make minor visual...
The Security Architecture of the Chromium Browser
Most current web browsers employ a monolithic architecture that combines "The User" and "The Web" into a single protection domain. An attacker who exploits arbitrary code execution vulnerability in such...
Leading TV and Online Sports Broadcaster Raises the Bar With Microsoft Silverlight
Founded in 1992 and based in London, Setanta Sports is a leading Internet and pay-TV sports broadcaster, operating channels in the U.K., Ireland, North America, and Australia. Setanta wanted to...



