Wednesday, April 28, 2010

Security Tools For IE 7

You can never be too careful when it comes to web browser security. As browser technology evolves, so do the unscrupulous characters looking to exploit new vulnerabilities. Although Internet Explorer 7 is considered to be safer than its predecessors, it is still vulnerable to attacks from time to time. It is a good idea to stay proactive in this area to avoid becoming a victim. The following free tools can aid you in strengthening the security of your IE browser.

Finjan SecureBrowsing

Finjan SecureBrowsing searches major web sites as well as search results for malicious content hiding behind links. By accessing and scanning destination URLs in real time, the add-on proactively warns you when a link is potentially dangerous.

How to Beef Up Your Browser

Web Browser Security

Today's attackers are more likely to host their malicious files on the web. They may even update those files constantly using automated tools that repackage the binary in an attempt to bypass signature-based scanners.
Attackers may entice users into visiting the malicious site via cleverly worded email, such as greeting card scams. Or they may compromise a legitimate site, outfitting the compromised site with hidden iframes or javascript references that pull exploits and malicious files from an external attacker-owned site - with all of this invisible to the casual observer.
Whether through social engineering or through website exploit, the choice of browser will be of little help. All browsers are equally susceptible to Web-based malware and this includes Firefox, Opera, and the much maligned Internet Explorer. Disabling Javascript on all but the most trusted sites will go a long ways towards safer web browsing.
The Firefox noscript addon disables active scripts by default and provides an option button in the lower right corner of the browser screen to change the preference on a per site or per visit basis. If a site won't display properly, just click the option button, locate the site URL on the list, and select "Temporarily allow sitename" (where sitename corresponds to the name of the site you are visiting). It's recommended you do not select 'Temporarily allow all this page' as that would also enable scripts and references embedded on a compromised website. While it's a few extra clicks to manage this on a per visit basis, the pay off in terms of better online safety will be well worth it.
The Opera browser allows you to set a global preference as well as dictate settings on a site by site basis. To configure global preferences in Opera, select Tools | Preferences | Advanced | Content. To configure site-specific settings, access the same menu, select Manage site preferences, then select Add. Once the Site Preferences dialog window opens, type the web site url in the Site field, then tab through the offerings and make the desired selections.
Internet Explorer provides four configurable security zones. While advantageous in previous times, it's a less effective approach given today's Web threats. To be effective, you'll need to disable iframes for each of the security zones and set active scripting to either disable or prompt. Those sites you must visit that require these features will need to be added to the Trusted Sites zone which will need to be configured to be more permissive. The downside: if that trusted site becomes compromised, you could become a victim. For a broader discussion of IE security zones, see Securing Internet Explorer.