Spoof dialog Boxes security issue

Hi all
Any one out there aware of this security issue with Safari
"Secunia Research has discovered a vulnerability in various browser's, which can be exploited by malicious web sites to spoof dialog boxes.
The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site."
I found the above by accident as i was looking up something else.
If you go to Secunia site and try the test you may find that you are also vulnerable.
http://secunia.com/multiple_browser'sdialog_origin_vulnerabilitytest/
The only way i found to stop the spoof dialog box was to turn off enable plug-ins in preferences. However i don't have any plug-ins in my Safari plug-in folder.
I'am running safari 1.3(v312) however it would appear that it also effects version 2.2 of Safari too. Also i have installed the latest update but to no effect. Other browser effect are:-
_ Internet Explorer for Mac
- Internet Explorer
- Opera
- iCab
- Mozilla / FireFox / Camino
My question is, is this vulnerability true, or just a setup
Any comments welcome.
~Tim

Hi,
The issue is resolved, but I don't know what caused this error.
I uninstalled the java components and BO then I deleted the BO folder under program files, then I deleted all BO entries in the registry.
Finally I reinstalled everything except the service pack and that finally worked. I don't know the cause of this error.
Regards,
Marcela

Similar Messages

  • Dialog box background issue

    Hi!
    I'm having this strange beauty problem on MacOsX 10.5.2. On some windows/dialog boxes there is a color difference between the background of the box and the background of the text and buttons.
    The computer is brand new, has some additional software installed and I really don't know what should I do. I'm also posting some print screens to explain the issue.

    I'm having a similar issue. This happened when I switched to a 2.2 gamma from the default 1.8. Any ideas on how to fix this? I prefer working with a 2.2 gamma, and switching back to 1.8 for such a small cosmetic problem doesn't seem like a good solution...

  • Reader X - Save dialog box popup issue

    Hello,
    I found that in Adobe Reader X whenever you goto save a file using just the "Save" (ctrl+S) option it brings up the Windows file system box prompt, which allows the user to see other windows files, folders, etc.. This is a huge issue for us as we do not want our users to be able to save to different locations or change the current filename on accident.
    How can I prevent this Save dialog from showing?  It is the dialog I would expect to get from choosing a "save as" option, not just your standard "save" option. Also, we are opening PDF files from our own software developed in C#. So if there are any open parameters I can pass to disable this save dialog that would be helpful as well.
    Please advise or provide insight.
    Thanks!
    Seth

    Seth -
    This is the expected behavior for Reader X, it's somewhat unexpected, so let me explain the rationale behind it:
    With Reader X, Adobe introduced the concept of sandbox - this mechanism severly curtails the rights provided to the Reader process to prevent exploits from running. In your case, Reader process cannot write to user's disk without users' explicit approval. The Save as dialog that you see is seeking that approval. Certain folders such as the TEMP folder are white listed, you should see if you can incorporate those into your workflows.
    You can find details here:
    http://blogs.adobe.com/asset/2010/10/inside-adobe-reader-protected-mode-part-1-design.html
    http://blogs.adobe.com/asset/2010/11/inside-adobe-reader-protected-mode-part-3-broker-proc ess-policies-and-inter-process-communication.html
    -abhigyan

  • Dialog box display issues

    Thanks for taking the time to help me with this.
    I've been having issues for a few weeks, first with Acrobat Pro X, and now with Acrobat Pro XI.  I can open a pdf fine, but when I try to print, or view the properties, or show the tools on the right side of the screen.  There is no text.  The print window shows a window with some button outlines, but no text.  Same with the other windows and tools.  The "open" command does show the window as it should appear.
    Occasionally, the print window is all blown out of proportion.  I will see two or three words across the entire screen and the window itself goes off the right for several screen widths.
    This is only happing with Acrobat, but the labels on the buttons in other programs do look a little funny.
    I've tried re-installing Acrobat; upgrading Acrobat; Scanning and fixing registry errors; scanning for viruses and malware.  None of it made any difference.  I did also get an error message that said "Acrobat failed to send a DDE command"  Haven't been able to find a solution for that to see if it helps.
    I'm using a Dell, running Windows 7 Pro; Creative Cloud apps; and Acrobat Pro XI
    Here is an image of the screen to better show what I'm looking at.
    Thanks very much to anyone who can shed some light on the issue.

    This type of thing can happen when a font is missing from your system. For example, see this previous thread: http://forums.adobe.com/message/4063094

  • I just wondering can I ask a user in firefox web browser after they have make a decision on one particular dialog box(e.g. security message choices)?

    Hi
    Basically I am doing a research on usability of information security. I would like to assess how likely people love or hate the security message that being presented to them. so I would like to present a dialog box asking their satisfaction after they have made decision upon security message they received (from web browser). If you could advise me on this. we can have a further discussion and it might be useful for you as developer in future as well. (collaborate for articles and journals publications) Please advise.

    This issue can be caused by an extension that isn't working properly.
    *https://support.mozilla.org/kb/Troubleshooting+extensions+and+themes
    You have quite a few extensions installed, so this may be difficult to track down.

  • After installing security update 10.6.8 I've seen dialog boxes asking me if I will permit certain root processes, e.g. configd, to receive unsolicited messages from the internet. What are the consequences of denying these requests?

    After installing security update 10.6.8 last night I've seen dialog boxes asking me if I will allow incoming network connections to certain root processes, e.g. configd.  I didn't see these dialog boxes prior to installing 10.6.8.  How do I make  informed decisions? In other words,
    (1) Where can I find 25-word summary descriptions of these processes?
    (2) Where can I find discussions of the consequences of granting or denying these requests?
    Alternatively (and at some risk of revealing metaphysical doubt) why am I being asked for these permissions?  And who expects me to make correct decisions?
    I have turned on th standard-issue OS X firewall and am running my system in stealth mode.

    After installing security update 10.6.8 last night I've seen dialog boxes asking me if I will allow incoming network connections to certain root processes, e.g. configd.  I didn't see these dialog boxes prior to installing 10.6.8.  How do I make  informed decisions? In other words,
    (1) Where can I find 25-word summary descriptions of these processes?
    (2) Where can I find discussions of the consequences of granting or denying these requests?
    Alternatively (and at some risk of revealing metaphysical doubt) why am I being asked for these permissions?  And who expects me to make correct decisions?
    I have turned on th standard-issue OS X firewall and am running my system in stealth mode.

  • I have a canon MX7600 multifunction printer. My security setting allow connection with the printer. If I disable the firewall it works fine. If the firewall is running I get a dialog box every time I print asking for permission. How do I fix this?

    I have a canon MX 7600 multifunction printer. Each  time I print I get a dialog box asking for permission to allow connections to the printer. This box stays on my screen for a few seconds, if I don't click allow I get a communication error which then requires me to delete the job and start over. I contacted Canon and proceeded with their suggestions to no avail. They now say it is an Apple issue. My security settings are set to allow connection to the canon printer. If I disable the firewall it works fine, once I enable the firewall the problem returns.  This issue is a royal pain. Any suggestions on how to fix it short of buying a new printer?

        jsavage9621,
    It pains me to hear about your experience with the Home Phone Connect.  This device usually works seamlessly and is a great alternative to a landline phone.  It sounds like we've done our fair share of work on your account here.  I'm going to go ahead and send you a Private Message so that we can access your account and review any open tickets for you.  I look forward to speaking with you.
    TrevorC_VZW
    Follow us on Twitter @VZWSupport

  • Secure printing problems with the dialog box

    Hi!
    Some one which has problem with the scure dialog box then using secure printing?
    then we print in Adobe acrobat reader X 10.0.1 the dialog box for entring your pin nummer appearing under acrobat, causeing the program to locking until you go to the dialog box and clicking on it and enter the pin. The problem is that adobe not showing the dialog box in front of the printing overall dialog.
    had nog problem with the old 9, it started then we uppgraded. Haw tride a nother driver but haw same issue. And all other programs works greate, word, notepat etc so it is just Adobe that has the problem.. ?
    /J

    Hi!
    Its´s XP sp3 and the printer is a network printer(Toshiba e-studio 4520c)  running a PCL6 driver.
    Screen capture is not so much to see i think, running Swedish interface to. The ordinary dialogbox för printing is the first thing thats pops up, and then adobe reader frezes because the secund box pops up under adobe, you can click on it in the "toolbar" to continue. One thing that is diffrent when you print in adobe is that you can se on the "toolbar" for the popup box for the pin/password box is a Adobe icon on it. It is not so in example when printing in word, ie8 etc.
    The problem is that many users dont see it and thinks the program has stopt working.
    Im now going to try the PS driver from toshibas homepage..
    thanks for help!

  • Crystal Report dialog box issues

    I am very new at .NET, and this is my second post to this forum.
    I've created a Crystal Report within a project using Visual Studio 2005 Professional Edition, on a Windows XP machine.
    The report is handled by a CrystalReportViewer, which has its ReportSource set to the report.
    Via a dialog box, the report asks for a signon and password for a SQL Server database.  Then, via a second dialog box, it prompts for a parameter required by the report.
    All of this works ok, but I have two issues:
    1) I would like to set the database signon and password so that the user doesn't have to enter them each time he runs the report.
    2) If the Cancel button is clicked on any of the dialog boxes, it renders the report unusable until I shut down the application and reopen it.
    I have looked online for two days, but have not been able to find a solution to these above problems.  It is probably simple, but I'm not seeing it.
    I am attaching the relevant code for the button that runs the report.
        Private Sub cmdChecks_Click(ByVal sender As System.Object, ByVal e As System.EventArgs) Handles cmdChecks.Click
                CrystalReportViewer2.DisplayToolbar = True
                CrystalReportViewer2.Visible = True
                CrystalReportViewer2.Height = 600
                CrystalReportViewer2.Width = 1000
                CrystalReportViewer2.Left = 10
        End Sub
    Can anybody help me with this?
    Thank you!

    Hi,
    I would like you to know the code of the logon based on the object models-
    If you are using the ConnectionInfo then use the below code:-
    //For web application
    ConnectionInfo crConnection = new ConnectionInfo();
    // Connection Information
    crConnection.ServerName="D-2818-W2K";
    crConnection.DatabaseName="Northwind";
    crConnection.UserID="sa";
    crConnection.Password="sa";
    crReport.Load(Server.MapPath("CrystalReport1.rpt"));
    Tables crTables=crReport.Database.Tables;
    foreach(CrystalDecisions.CrystalReports.Engine.Table crTable in crTables)
              TableLogOnInfo crTLOI = crTable.LogOnInfo;
              crTLOI.ConnectionInfo=crConnection;
              crTable.ApplyLogOnInfo(crTLOI);
              crTable.Location=crTable.Location;// for multiple table selection
    CrystalReportViewer1.ReportSource=crReport;
    ====================================================================================
    //For desktop application
    ConnectionInfo crConnection = new ConnectionInfo();
    // Connection Information
    crConnection.ServerName="D-2818-W2K";
    crConnection.DatabaseName="Northwind";
    crConnection.UserID="sa";
    crConnection.Password="sa";
    crReport.Load(Application.StartupPath + "//CrystalReport1.rpt");
    Tables crTables=crReport.Database.Tables;
    foreach(CrystalDecisions.CrystalReports.Engine.Table crTable in crTables)
              TableLogOnInfo crTLOI = crTable.LogOnInfo;
              crTLOI.ConnectionInfo=crConnection;
              crTable.ApplyLogOnInfo(crTLOI);
              crTable.Location=crTable.Location;// for multiple table selection
    CrystalReportViewer1.ReportSource=crReport;
    =====================================================================================
    If using ReportDocument object model
    //For web application
    ReportDocument crReport= new ReportDocument();
    crReport.Load(Server.MapPath("CrystalReport1.rpt"));
    crReport.SetDatabaseLogon("sa","sa");
    CrystalReportViewer1.ReportSource =crReport;
    =====================================================================================
    //For desktop application
    ReportDocument crReport= new ReportDocument();
    crReport.Load(Application.StartupPath + "//CrystalReport1.rpt");
    crReport.SetDatabaseLogon("sa","sa");
    CrystalReportViewer1.ReportSource =crReport;
    To download sample code click [here|https://boc.sdn.sap.com/codesamples].
    You can also take help from [Dev library|https://www.sdn.sap.com/irj/boc/sdklibrary]
    Hope this helps!!
    Regards
    Amit

  • "Security Warning" dialog box when click script set to Run at Server

    I am rendering a PDF form using the renderForm component.  I'm setting the Target URL.  I have a script on a button set to "run at server".  I can render my form in a browser and fill it out, but when I click the button I get a dialog box with a title of "Security Warning".  It says "Acrobat is attempting to connect to [target URL]" with options to Allow or Block.  Is this the expected behaviour for server-side execution of scripts?
    I'm thinking that maybe I should just use a submit button instead.  The problem with that though, is that I don't want to run the mandatory field rules and validation rules.  As I understand, you can't submit a form with a submit button unless all the mandatory fields are completed.
    Here's the requirement.  I need to have two "submit" buttons.  One checks all the mandatory field rules before submitting a "final" version of the form.  The other button submits a "draft" version without the mandatory checks.  I was hoping that the second button could be implemented as a normal command button with a script that executes server-side.  Sure enough, it attempted to submit without checking the mandatory fields.  Unfortunately I ran into other undesirable side-effects including a distressing "Security Warning" dialog box.
    Ideas?
    Jared Langdon

    This was helpful (stopped the request to execute Thunderbird) . However, The pop up window is now asking what program do you want to use to access the website??? What is the next step??

  • Security Dialog Box appears in Javascripts

    hi all.
    I ve some problem with my javascript which is used to present menus at the homepage. I have a dropdown menu also, wherein, whenever I rollover t mouse on dropdown menus, a security dialog box appears(this page works on https), and it doesnot appear until u refresh the page again.
    I have 2 menu scripts. In menu1.js, I call a fn which is in menu_main.js
    The call in menu1.js, goes like this
    startSubmenu("menu_pre_b7","menu_pre_menu",83);submenuItem("Help",loc+"pre_help.htm","_self","menu_pre_plain");submenuItem("Search",loc+"GetPage1Action.do?command=getPage1","_self","menu_pre_plain");submenuItem("DJVU Plugin",loc+"pre_lizardtech_djvu.htm","_self","menu_pre_plain");endSubmenu("menu_pre_b7"); and the menu_main.js has the function for startSubMenu as
    function startSubmenu(name,style,sw){var depth=name.split("_").length+1000;if(NS4)return;if(sw>0)menuw=sw;d.write("<div id=\""+name+"\" style=\"z-index:999;border-color:#000000;border-style:solid;border-width:"+bd+"px 0px "+bd+"px 0px;background-color:#ffffff;position:absolute;left:0px;top:0px;visibility:hidden;z-index:"+depth+";width:"+(menuw+(NS7?bd*2:0))+"px\">");}I hope the problem is with the startSubMenu function. Can someone help me on this?

    Unfortunately this forum is for the Java programming language, not for the ECMAScript compliant Javascript.
    Sincerely,
    Jussi

  • JRE 1.6. 0_01 is giving issues in message dialog box size

    Hi There,
    I am displaying message dialog for one of my web application. To resize the dialog automatically, I have set getPrefferedSize() property.
    This is working fine with JRE 1.5.0_11 and all lower version, even ok with 1.4.x. But if I am viewing the applet in a browser having JRE 1.6.0, dialog box size is automatically streatched. Height of the dialog box is increased automatically more than the desktop height. I can not view top & bottom area of the dialog box on my desktop.
    Please guide me why is this issue only with JRE 1.6.0 and what should I do to eliminate & resolve it.
    Thanks.

    Really? I thought all official versions would be downloadable through webstart. I'm curious why would Sun not make them available. Now I need to explain to my higher-ups why I promised to get webstart to automatically update all our user's JRE but now failed to make good. :-(
    Regarding the printing problem: With b105 the printouts would have text that is upside, mirrored and cropped. It was a total mess. The problem is reproducible. We manually upgraded some users to b106 and the problem disappeared completely. I think Sun fixed it in 106 but now the problem is getting all our users onto JRE b106.
    Java Webstart is supposed to do this for me but now it appears to be failing me big time.

  • Crystal Report - Parameter issue (advanced dialog box)

    In our wpf .net application we view the crystal report, the report prompts for entering 2 parameter values i.e 2 dates and inturn these parameters will be used to generate the crystal report.
    The parameter panel on the left has a button (show advanced dialog box). This button should again invoke the same parameter prompt dialog box, so that the user can modify these parameters and the report can be regenerated.
    Issue is that when I click on the the button, this generates a null reference exception in the code. The call stack is -
    at CrystalDecisions.Windows.Forms.ParameterFieldInfo.get_isDCP()
       at CrystalDecisions.Windows.Forms.InteractiveParameterPanel.ShowAdvancedDialog(ParameterUnit pu)
       at CrystalDecisions.Windows.Forms.InteractiveParameterPanel.pu_ShowAdvancedDialog(Object sender, EventArgs e)
       at CrystalDecisions.Windows.Forms.ParameterUnit.OnShowAvancedDialog(EventArgs e)
       at CrystalDecisions.Windows.Forms.ParameterUnit.editControl_ShowAdvancedDialog(Object sender, EventArgs e)
       at CrystalDecisions.Windows.Forms.ParameterValueEditControl.OnShowAdvancedDialog(EventArgs e)
       at CrystalDecisions.Windows.Forms.ParameterValueEditControl.btnShowAdvancedDialog_Click(Object sender, EventArgs e)
       at System.Windows.Forms.Control.OnClick(EventArgs e)
       at System.Windows.Forms.Button.OnClick(EventArgs e)
       at System.Windows.Forms.Button.OnMouseUp(MouseEventArgs mevent)
       at System.Windows.Forms.Control.WmMouseUp(Message& m, MouseButtons button, Int32 clicks)
       at System.Windows.Forms.Control.WndProc(Message& m)
       at System.Windows.Forms.ButtonBase.WndProc(Message& m)
       at System.Windows.Forms.Button.WndProc(Message& m)
       at System.Windows.Forms.Control.ControlNativeWindow.OnMessage(Message& m)
       at System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
       at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
    Please note, I used the .net reflector to debug the crystal report dll , the isDCP method looks like -
    public bool isDCP
          get
            return (this.Attributes.Contains("IsDCP") && ((bool) this.Attributes["IsDCP"]));
    Looks like the attributes value is null.
    Please let me know your comments. Am I missing something while getting the report in the frontend.
    I use crystal reports 2008 sp 2 (also note that my gac contains different version of crystal reports (cannot remove them - tried it) , with windows server 2003. I use web service with proxy to get the report from the local server.
    Note I also tried to create sample application in which I specify the local path to reports source , this works. However when I tried to use webservice, i was getting soap exception.
    Please let me know how solve above issue

    So you found the Report Design forum, if you looked down one more you would have found the SDK forum, SDK stands for Software Development Kit if you did not know.
    Or did you not mention you get the same error when you run this report in CR Designer, if so then you were in the right forum.
    Try Service Pack 3 also
    Move to the SDK forums.

  • Issue with dialog boxes in Designer, please help

    Hi,
    I'm having a problem with designer the last 4 days. It was working fine before.
    Any dialog box wants to open, I can not insert tables, edit properties, etc.
    I'm using Designer 11.5.0.0 with SP3 update, I reinstalled every thing, but it's still not working.
    Does someone know how to fix it?
    Thanks in advance,
    Marcela

    Hi,
    The issue is resolved, but I don't know what caused this error.
    I uninstalled the java components and BO then I deleted the BO folder under program files, then I deleted all BO entries in the registry.
    Finally I reinstalled everything except the service pack and that finally worked. I don't know the cause of this error.
    Regards,
    Marcela

  • Little security issue in password box on connections

    I'm on 1.2.0.29.98 on OSX. I have a password with an @ symbol in it. I was making a new connection in the connection dialog box and typed in the password wrong. I noticed when I double clicked the obfuscated password it only highlighted part of it to the right of the @ symbol instead of the whole password. For other symbols ($, % for example) it will only highlight from where you double clicked up to (and including) that symbol or between two of those symbols.
    It could help people to figure out the passwords, it should highlight all the password when you double click it.

    Thank you for bringing this to our attention. As you mentioned, it isn't a glaring hole in password security, but even a little hole is undesirable.
    - John McGinnis
    SQL Developer Team

Maybe you are looking for

  • Reports generation in OIM 11g

    Hi, I am using OIM-OAM 11g. My project has constraint that they can not use Oracle BI Publisher for Report Generation. The Client wants us to write Scheduled task which generate reports by calling stored procedure present in Audit Database. Experts a

  • Can't import edited song from iTunes to iPhoto

    Hi, I've created a slideshow in iPhoto and a playlist in iTunes to go with the slideshow. I shortened one of the songs in the playlist from 4.5 minutes to 1.5 minutes (file-get info-options). Within iTunes the song is shortened but when I import the

  • Maintaining a custom tabe w/o transport?

    Hi We have a custom table with table maintenance generator, and it is with 'Standard recording routine', meaning when we create/change/delete an entry in SM30(or associated custom T code) system will prompt for a transport, fine. But, my requirement

  • Problem downloading Twiter for Mac.. Any recommendation?

    I have tried to downloand Twiter several time and still not download. I deleted and tried again with the same results. Have anyone have a recommendation? thanks, iLS

  • PDF to audiobook

    I would like to convert PDF textual file into audiobook, such that, I could listen to it. Which tools would you recommend?