FireCAT is a Firefox Framework Map collection of the most useful security oriented extensions. It can be used to turn your favorite browser (Firefox) into a powerful security framework. Have you heard of FireCAT? I find it useful for doing security audits but it can other security tasks. Did you tested out the other features like information gathering or web proxying? . The link for this article located at darknet.org is no longer available. . Uncover the ways that FireCAT transforms Firefox into a powerful security platform, featuring elite add-ons.. FireCAT, Firefox Security Extensions, Security Tools, Web Proxy, Firefox Framework. . Bill Locke
You manage a heterogeneous network and want to provide different Quality of Service agreements and network restrictions based on the client operating system. With pf and altq, you can now limit the amount of bandwidth available to users of different operating systems, or force outbound web traffic through a transparent filtering proxy. This article describes how to install pf, altq, and Squid on your FreeBSD router and web proxy to achieve these goals. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will define how to implement more-stringent security, required under the Real ID Act for state-issued driver's licenses and other ID cards. The rules, which go into effect in May 2008, may push some agencies toward chip-based cards. Indeed, Blair said, "any security features could become obsolete in two years." The link for this article located at Security Pipeline is no longer available. . The U.S. Department of Homeland Security is drafting regulations, expected by August, that will defi. manage, heterogeneous, network, provide, different, quality, service, agreements. . Brittany Day
Privoxy version 3.0.3 was today released. Privoxy is a web proxy with advanced filtering capabilities for protecting privacy, modifying web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk. . . .. This is the another maintenance release of Privoxy which fixes more bugs, further refines the configuration based on half a year's worth of user feedback, and works around some known third-party problems. Upgrading from 3.0.2 is recommended. -------------------------------------------------------------------------- ChangeLog for Version 3.0.3: -------------------------------------------------------------------------- - Fixed yet another two memory leaks. Process growth looks stopped now. - Further tightened security against malicious toggle-off links. - Excluded text/plain MIME types from filtering. This fixes a couple of client-crashing, download corruption and Privoxy performance issues, whose root cause lies in web servers labelling content of unknown type as text/plain. - Assorted fixes for POSIX compliance, signal handling, graceful termination, compiler warnings, OSX support, Win32 systray, error logging, hostname wildcards, correct detection of NetBSD. - Workarounds for client (iTunes etc) and server (PHP < 4.2.3) bugs including the notorious "blank page" problem. - Various filter improvements; most notably the unsolicited-popups filter became less destructive - Major revamp of the actions file . This is the another maintenance release of Privoxy which fixes more bugs,further refines the configu. privoxy, version, today, released, proxy, advanced, filtering, capabilitie. . LinuxSecurity.com Team
A pact between the U.S. government and the electronic privacy company Anonymizer, Inc. is making the Internet a safer place for controversial websites and subversive opinions -- if you're Iranian. This month Anonymizer began providing Iranians with free access to . . . . A pact between the U.S. government and the electronic privacy company Anonymizer, Inc. is making the Internet a safer place for controversial websites and subversive opinions -- if you're Iranian. This month Anonymizer began providing Iranians with free access to a Web proxy service designed to circumvent their government's online censorship efforts. In May, government ministers issued a blacklist of 15,000 forbidden "immoral" websites that ISPs in the country must block -- reportedly a mix of adult sites and political news and information outlets. An estimated two million Iranians have Internet access. Among the banned sites are the website for the U.S.-funded Voice of America broadcast service, and the site for Radio Farda, another U.S. station that beams Iranian youth a mix of pop music and westernized news. Both stations are run by the International Broadcasting Bureau (IBB), the U.S. government's overseas news and propaganda arm. The U.S. responded to the filtering this month by paying Anonymizer (neither the IBB nor Anonymizer will disclose how much) to create and maintain a special version of the Anonymizer proxy which only accepts connections from Iran's IP address space, and features instructions in Farsi. The link for this article located at SecurityFocus is no longer available. . Partnership between a privacy tool and U.S. authorities boosts internet connectivity for Iranians in the face of restrictions.. Web Proxy, Internet Privacy, Anonymization Service. . Anthony Pell
Privoxy is a web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk. . .. Privoxy is a web proxy with advanced filtering capabilities for protecting privacy, filtering web page content, managing cookies, controlling access, and removing ads, banners, pop-ups and other obnoxious Internet junk . Privoxy has a very flexible configuration and can be customized to suit individual needs and tastes. Privoxy has application for both stand-alone systems and multi-user networks. Privoxy is based on Internet Junkbuster (tm). At present, Privoxy is known to run on Windows(95, 98, ME, 2000, XP), Linux (Red Hat, SuSE, Debian, Conectiva, Gentoo), Mac OSX, OS/2, AmigaOS, BeOS, FreeBSD, NetBSD, Solaris, and many more flavors of Unix. In addition to the traditional features of Internet Junkbuster , such as ad and banner blocking, cookie management/protection, and HTTP header manipulation, Privoxy adds many enhancements, and new features in the same vein. Integrated browser based configuration and control utility at Privoxy is not being used (shortcut: ). Browser-based tracing of rule and filter effects. Remote toggling. Web page content filtering (removes banners based on size, invisible "web-bugs" , JavaScript and HTML annoyances, pop-up windows, etc.) Modularized configuration that allows for standard settings and user settings to reside in separate files, so that installing updated actions files won't overwrite individual user settings. HTTP/1.1 compliant (but not all optional 1.1 features are supported). Support for Perl Compatible Regular Expressions in the configuration files, and generally a more sophisticated and flexible configuration syntax over previous versions. Improved cookie management features (e.g. session based cookies). GIF de-animation. Bypass many click-tracking scripts (avoidsscript redirection). Multi-threaded (POSIX and native threads). User-customizable HTML templates for all proxy-generated pages (e.g. "blocked" page). Auto-detection and re-reading of config file changes. Improved signal handling, and a true daemon mode (Unix). Every feature now controllable on a per-site or per-location basis, configuration more powerful and versatile over-all. Many smaller new features added, limitations and bugs removed, and security holes fixed. Download location: Privoxy - Browse Files at SourceForge.net Home Page: Privoxy - Home Page Privoxy Developers . GnuPG is a cryptographic tool designed for secure communication and data encryption, ensuring privacy and authenticity of digital information.. Privoxy Proxy, Content Filtering, Privacy Control, Web Management, Ad Blocking. . LinuxSecurity.com Team
For some time at my workplace we've been running an ad-zapping service on our web proxy. This page documents how it works, how to use it yourself, how to join the mailing list for updates of the pattern file, and the weirdnesses of our local setup (which you need not duplicate yourself).. . .. For some time at my workplace we've been running an ad-zapping service on our web proxy. This page documents how it works, how to use it yourself, how to join the mailing list for updates of the pattern file, and the weirdnesses of our local setup (which you need not duplicate yourself). Ad zapping is not a new idea. Basicly you interpose between the reader and the web some kind of filter which replaces those annoying ad banners with something unobtrusive. (There are a few motivations for this; see this digression for mine.) The link for this article located at Cameron Simpson is no longer available. . Learn the steps to enable ad-blocking techniques with Squid and streamline your local proxy management effectively.. Ad Zapping, Web Proxy, Squid Configuration, Filtering Services. . LinuxSecurity.com Team
In this column, we look at insecure Web Proxy Servers; buffer overflows in ncurses, Squid, hanterm, and ripMime; and problems in gnujsp, the NetBSD kernel, jmcce, the IRIX Unified Name Service Daemon, and Chuid. Some insecurely-configured Web proxy servers can be . . . . In this column, we look at insecure Web Proxy Servers; buffer overflows in ncurses, Squid, hanterm, and ripMime; and problems in gnujsp, the NetBSD kernel, jmcce, the IRIX Unified Name Service Daemon, and Chuid. Some insecurely-configured Web proxy servers can be exploited by a remote attacker to make arbitrary connections to unauthorized hosts. Two common abuses of a misconfigured proxy server are to use it to bypass firewall restrictions and to send spam email. A server is used to bypass a firewall by connecting to the proxy from outside the firewall and then opening a connection to a host inside the firewall. A server is used to send spam by connecting to the proxy and then having it connect to a SMTP server. It has been reported that many Web proxy servers are distributed with insecure default configurations. . Uncover vulnerable Web Proxy Servers and buffer overflow vulnerabilities affecting numerous software, including ncurses and Squid.. Web Proxy Security, Network Configuration Risks, Buffer Overflow Issues. . LinuxSecurity.com Team
Last week, I mentioned that the new beta version of Proxomitron, a local Web proxy, supports SSL. Let's look at how this works. Normally, Proxomitron works only with unencrypted traffic. It listens (by default) on port 8080. To relay traffic through . . . . Last week, I mentioned that the new beta version of Proxomitron, a local Web proxy, supports SSL. Let's look at how this works. Normally, Proxomitron works only with unencrypted traffic. It listens (by default) on port 8080. To relay traffic through it, set your browser's HTTP proxy to localhost:8080. In Netscape, that's Edit-> Preferences-> Advanced-> Proxies-> Manual Configuration-> View-> HTTP. In MSIE, it's Tools-> Internet Options-> Connections-> LAN Settings-> Proxy Server-> Use a Proxy Server. Now you can watch the conversation between your browser and a Web server in Proxomitron's log window. Here's the browser on my Windows machine talking to the server on my Linux machine, as seen in the log window: The link for this article located at BYTE is no longer available. . The new Proxomitron beta significantly enhances secure client/server communications with SSL support, ensuring data confidentiality and protection from eavesdroppers. Proxomitron, SSL Support, Secure Communication, Web Proxy, Local Proxy. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.