29 ms·
I'm very curious too, I wonder why this "waterhole" has not been publicly revealed yet? It would make it easier for others to identify whether they were exposed
by jmsduran 14y ago
I'm very curious too, I wonder why this "waterhole" has not been publicly revealed yet? It would make it easier for others to identify whether they were exposed, and take the necessary actions to secure their workstations.
- dguido 14y agoIf you are running Java in your browser, you were exposed. There, done. The internet is a nasty place, get used it.
- 0x0 14y agoSo let's say I'm not except when I'm forced to use Safari for some pages in the iOS dev center?
- martinced 14y agoIf you are running Java, Flash, most PDF readers, using any browser which doesn't update automatically, you are exposed. Not "were". Even browser updating automatically aren't a panacea: the update itself may be corrupted by an exploit (now that would be a fiasco). That is precisely the reason people should surf from a separate user account, using very strict firewalling rules. "iptables -I OUTPUT -p tcp --dport 80 (and 443) -m state --state NEW -m user --user-id 501 -j ACCEPT" Now it's too bad per-user firewalling cannot be done easily on neither Windows nor OS X. It's also too bad one user (say the one allowed to surf the Web) cannot display its browser window(s) in another user (say your main account)'s graphical display (neither on Windows nor on OS X). Or too bad OS X doesn't allow to run two graphical sessions simultaneously (on some version of Windows, if you pay enough, at least you can do that). All this is trivial to do under Linux. I'm feeling better and better using Linux as my desktop.
- criley 14y agoYou have in one single post perfectly captured why Linux is both amazing and terrible. (Amazing, because look what you've done! Terrible, because almost every other human on this planet could not accomplish your outcome even with guides and training...)
- tolmasky 14y agoI would love a blog post or screencast showing how you do this
- deleted 14y ago[deleted]
- wooster 14y agoNow it's too bad per-user firewalling cannot be done easily on neither Windows nor OS X. I haven't tried this, but pf seems to have the support there, so I'm not sure why you couldn't. It's also too bad one user (say the one allowed to surf the Web) cannot display its browser window(s) in another user (say your main account)'s graphical display (neither on Windows nor on OS X). $ su testuser $ /Applications/Safari.app/Contents/MacOS/Safari Seems to work for me. Or too bad OS X doesn't allow to run two graphical sessions simultaneously This is called Fast User Switching on OS X.
- micampe 14y agoI don’t mean to take away from your feeling good, but why is iptables ok on Linux and ipfw is too hard on OS X? uid user Match all TCP or UDP packets sent by or received for a user. A user may be matched by name or identification number. also, since I agree that neither iptables nor ipfw are good enough as UIs, there are a number of graphical firewall apps that allow people to do very very easily filtering per user, per process, per domain, per ip, timed, with different profiles http://www.obdev.at/products/littlesnitch/ http://www.obdev.at/products/littlesnitch/
- Osmium 14y ago> All this is trivial to do under Linux. In the same way a stubborn mathematical proof is trivial, I'm sure.