Go Back   Wireless and Wifi Forums > News > Newsgroups > comp.security.misc
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-21-2008, 07:07 AM
q
Guest
 
Posts: n/a
Default How to prevent my information from being accessed by webpages

Hello - I have visited a few sites that somehow have information about what
city I live in. I have cleared autocomplete and history and cookies and
offline files, and when I go back they still greet me with the city I live
in. How do they get that info? How do I stop it?
Running IE 6
Thanx



Reply With Quote
  #2 (permalink)  
Old 02-21-2008, 10:06 AM
mak
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

q wrote:
> Hello - I have visited a few sites that somehow have information about what
> city I live in. I have cleared autocomplete and history and cookies and
> offline files, and when I go back they still greet me with the city I live
> in. How do they get that info? How do I stop it?
> Running IE 6
> Thanx
>
>

let me guess,

Greater Victoria, BC



M

Reply With Quote
  #3 (permalink)  
Old 02-21-2008, 11:07 AM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

q wrote:

> Hello - I have visited a few sites that somehow have information about what
> city I live in. I have cleared autocomplete and history and cookies and
> offline files, and when I go back they still greet me with the city I live
> in. How do they get that info?



GeoIP

> How do I stop it?



proxying

> Running IE 6



And you don't consider this as a much bigger problem?

Reply With Quote
  #4 (permalink)  
Old 02-21-2008, 06:09 PM
Todd H.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"q" <Q@q.com> writes:

> Hello - I have visited a few sites that somehow have information about what
> city I live in. I have cleared autocomplete and history and cookies and
> offline files, and when I go back they still greet me with the city I live
> in. How do they get that info? How do I stop it?
> Running IE 6
> Thanx


They're most likely divining this info from your computer/ISP's IP
address.

If you proxy your web traffic through another server, then the web
site will think you're coming from there.

Tor is a program that pseudo anonymizes your apparent web whereabouts
by the use of onion routing. You can google the program and term for
more information, but basically, it makes you apparent IP address
appear to come from a number of different places.

I agree with Sebastian though, IE6 is likely the bigger issue here.
You should reconsider that choice if you are concerned with security.
ActiveX is just way too pourous. Firefox and Opera are decent
alternatives.

Best Regards,
--
Todd H.
http://www.toddh.net/

Reply With Quote
  #5 (permalink)  
Old 02-21-2008, 07:42 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Todd H. wrote:


> I agree with Sebastian though, IE6 is likely the bigger issue here.
> You should reconsider that choice if you are concerned with security.
> ActiveX is just way too pourous.



The problem is that you can't actually disable ActiveX due to numerous flaws
in IE's implementation.

Reply With Quote
  #6 (permalink)  
Old 02-21-2008, 08:54 PM
Todd H.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." <seppi@seppig.de> writes:

> Todd H. wrote:
>
>
>> I agree with Sebastian though, IE6 is likely the bigger issue here.
>> You should reconsider that choice if you are concerned with security.
>> ActiveX is just way too pourous.

>
>
> The problem is that you can't actually disable ActiveX due to numerous
> flaws in IE's implementation.


Yup.


--
Todd H.
http://www.toddh.net/

Reply With Quote
  #7 (permalink)  
Old 02-21-2008, 08:54 PM
Todd H.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." <seppi@seppig.de> writes:

> Todd H. wrote:
>
>
>> I agree with Sebastian though, IE6 is likely the bigger issue here.
>> You should reconsider that choice if you are concerned with security.
>> ActiveX is just way too pourous.

>
>
> The problem is that you can't actually disable ActiveX due to numerous
> flaws in IE's implementation.


Yup.


--
Todd H.
http://www.toddh.net/

Reply With Quote
  #8 (permalink)  
Old 02-21-2008, 10:09 PM
Chris Mattern
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

On 2008-02-21, q <Q@q.com> wrote:
> Hello - I have visited a few sites that somehow have information about what
> city I live in. I have cleared autocomplete and history and cookies and
> offline files, and when I go back they still greet me with the city I live
> in. How do they get that info? How do I stop it?
> Running IE 6
> Thanx
>

It's often possible to deduce what city you're in by your IP address,
particularly if you're using a ordinary ISP that's local to you.
Unless you want to dial in to an access point in some other city,
or go through a proxy in some other city, there's not much you can do.

--
Christopher Mattern

NOTICE
Thank you for noticing this new notice
Your noticing it has been noted
And will be reported to the authorities

Reply With Quote
  #9 (permalink)  
Old 02-21-2008, 11:08 PM
Ant
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Todd H." wrote:
> "Sebastian G." writes:
>> The problem is that you can't actually disable ActiveX due to numerous
>> flaws in IE's implementation.

>
> Yup.


Could either of you give me an example of how disabling it fails or
point to somewhere that discusses it?



Reply With Quote
  #10 (permalink)  
Old 02-21-2008, 11:36 PM
Bit Twister
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

On Thu, 21 Feb 2008 08:07:56 GMT, q wrote:
> Hello - I have visited a few sites that somehow have information about what
> city I live in. I have cleared autocomplete and history and cookies and
> offline files, and when I go back they still greet me with the city I live
> in. How do they get that info? How do I stop it?


Quit running IE for starters.
Go here to see what your browser leaks http://gemal.dk/browserspy/

Firefox or opera would be safer from malware.

I would run Firefox with NoScript Add On installed.
http://noscript.net/getit

Most places guess your city from your ip address.

Reply With Quote
  #11 (permalink)  
Old 02-21-2008, 11:43 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Ant wrote:

> "Todd H." wrote:
>> "Sebastian G." writes:
>>> The problem is that you can't actually disable ActiveX due to numerous
>>> flaws in IE's implementation.

>> Yup.

>
> Could either of you give me an example of how disabling it fails or
> point to somewhere that discusses it?



Well, three big issues:

- If you instantiate it through a CLSID instead of the interface name (which
is actually undocumented as well as invalid HTML), then the COM server is
responsible for instantiation. So, in 99% of all cases MSIE is earlier, and
applies it policies (means: does not instantiate the control), in the rest
1% the policies are totally bypassed. Even further, on can trigger updates
of existing controls, provide old signed controls, and possibly even
redirect to arbitrary download locations.

- Aside from the policies, some controls are ultimately trusted and can
always be instantiated. Just take a look at the source code of MSIE's
internal error webpages...

- Even if instantiation is not attempted at all, just searching for the
control has funny side effects. For example, as in Windows 2000 SP3, trying
to instantiate the Control TlntSrvClient.TlntSrvEnum triggers the startup of
the Telnet Server Service (if installed, and the user logged in as Admin).

But IE has other issues as well, like f.e. boundary errors in the CSS parser.

Reply With Quote
  #12 (permalink)  
Old 02-22-2008, 05:30 AM
q
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Thanks for the mention about IE6. I upgraded to ie7 last night and still no
good.I'm going to check out Firefox.
Thanx

"Sebastian G." <seppi@seppig.de> wrote in message
news:6257s7F2249a7U2@mid.dfncis.de...
>q wrote:
>
>> Hello - I have visited a few sites that somehow have information about
>> what city I live in. I have cleared autocomplete and history and cookies
>> and offline files, and when I go back they still greet me with the city I
>> live in. How do they get that info?

>
>
> GeoIP
>
>> How do I stop it?

>
>
> proxying
>
>> Running IE 6

>
>
> And you don't consider this as a much bigger problem?




Reply With Quote
  #13 (permalink)  
Old 02-22-2008, 05:37 AM
Todd H.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"q" <Q@q.com> writes:

> Thanks for the mention about IE6. I upgraded to ie7 last night and still no
> good.I'm going to check out Firefox.


FYI, Firefox won't keep websites from knowing your geographic
location. But it's a wise thing to check out for other security
reasons.

To thwart geolocation based on your ISP's IP address, you'll need to
use a proxy.

http://en.wikipedia.org/wiki/Proxy_server

Something like tor, or ghostsurf,

http://www.torproject.org/
http://www.tenebril.com/consumer/ghostsurf/

There is a speed penalty.


--
Todd H.
http://www.toddh.net/

Reply With Quote
  #14 (permalink)  
Old 02-22-2008, 03:33 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

q wrote:

> Thanks for the mention about IE6. I upgraded to ie7 last night and still no
> good.



Well, why do you insist on abusing MSIE as a webbrowser?

> I'm going to check out Firefox.


Which is a serious webbrowser, but won't solve your problem, since it's not
related to the webbrowser at all (or whatever you choose to abuse as such).

Reply With Quote
  #15 (permalink)  
Old 02-22-2008, 03:49 PM
Techie24Chick
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

On Feb 21, 2:09 pm, comph...@toddh.net (Todd H.) wrote:
> "q" <Q...@q.com> writes:
> > Hello - I have visited a few sites that somehow have information about what
> > city I live in. I have cleared autocomplete and history and cookies and
> > offline files, and when I go back they still greet me with the city I live
> > in. How do they get that info? How do I stop it?
> > Running IE 6
> > Thanx

>
> They're most likely divining this info from your computer/ISP's IP
> address.
>
> If you proxy your web traffic through another server, then the web
> site will think you're coming from there.
>
> Tor is a program that pseudo anonymizes your apparent web whereabouts
> by the use of onion routing. You can google the program and term for
> more information, but basically, it makes you apparent IP address
> appear to come from a number of different places.
>
> I agree with Sebastian though, IE6 is likely the bigger issue here.
> You should reconsider that choice if you are concerned with security.
> ActiveX is just way too pourous. Firefox and Opera are decent
> alternatives.
>
> Best Regards,
> --
> Todd H.http://www.toddh.net/


Firefox has my vote! You should test it out, q...

Reply With Quote
  #16 (permalink)  
Old 02-25-2008, 12:32 AM
Ant
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." wrote:

> Ant wrote:
>> Could either of you give me an example of how disabling it fails or
>> point to somewhere that discusses it?

>
> Well, three big issues:
>
> - If you instantiate it through a CLSID instead of the interface name (which
> is actually undocumented as well as invalid HTML), then the COM server is
> responsible for instantiation. So, in 99% of all cases MSIE is earlier, and
> applies it policies (means: does not instantiate the control), in the rest
> 1% the policies are totally bypassed.


If this is random it would be difficult to check. I'd like to see a
prooof-of-concept.

> Even further, on can trigger updates
> of existing controls, provide old signed controls, and possibly even
> redirect to arbitrary download locations.


Again, I'd like to see a POC.

> - Aside from the policies, some controls are ultimately trusted and can
> always be instantiated. Just take a look at the source code of MSIE's
> internal error webpages...


Error messages (e.g. 404) don't appear in my IE without OK-ing an
ActiveX prompt.

> - Even if instantiation is not attempted at all, just searching for the
> control has funny side effects. For example, as in Windows 2000 SP3, trying
> to instantiate the Control TlntSrvClient.TlntSrvEnum triggers the startup of
> the Telnet Server Service (if installed, and the user logged in as Admin).


I don't know why a search would be made when all automatic object
creation is disallowed in all zones.

> But IE has other issues as well, like f.e. boundary errors in the CSS parser.


I'll have to look into this further.



Reply With Quote
  #17 (permalink)  
Old 02-25-2008, 06:48 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Ant wrote:


>> - Aside from the policies, some controls are ultimately trusted and can
>> always be instantiated. Just take a look at the source code of MSIE's
>> internal error webpages...

>
> Error messages (e.g. 404) don't appear in my IE without OK-ing an
> ActiveX prompt.



Interesting. How did you get such a configuration?

> I don't know why a search would be made when all automatic object
> creation is disallowed in all zones.



Because the implementation is somewhere between stupid and broken.
Instantiation already happens before it tries to apply its policies.

>> But IE has other issues as well, like f.e. boundary errors in the CSS parser.

>
> I'll have to look into this further.


http://web.archive.org/web/200306260...base/ie6crash/
http://web.archive.org/web/200306260...ase/ie6crash2/

reliably crash a fully up-to-date Internet Explorer 7. No news, I reported
these to Microsoft back in 2004; about the time when I stopped caring for MSIE.

Reply With Quote
  #18 (permalink)  
Old 02-26-2008, 06:11 PM
Ant
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." wrote:

> Ant wrote:
>> Error messages (e.g. 404) don't appear in my IE without OK-ing an
>> ActiveX prompt.

>
> Interesting. How did you get such a configuration?


By tweaking the registry values under ...\Internet Settings\Zones\0

Many people would find that a nuisance when performing some normal
day-to-day operations but I tend not to operate normally.

>> I don't know why a search would be made when all automatic object
>> creation is disallowed in all zones.

>
> Because the implementation is somewhere between stupid and broken.
> Instantiation already happens before it tries to apply its policies.


Perhaps limiting ActiveX in *all* zones would stop it. I've yet to see
a control instantiated that I haven't explicitly allowed.

> http://web.archive.org/web/200306260...base/ie6crash/
> http://web.archive.org/web/200306260...ase/ie6crash2/
>
> reliably crash a fully up-to-date Internet Explorer 7. No news, I reported
> these to Microsoft back in 2004; about the time when I stopped caring for MSIE.


No crashes here either online or with locally saved copies of the
tests suitably modified, but then I am using IE5.



Reply With Quote
  #19 (permalink)  
Old 02-26-2008, 07:27 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Ant wrote:

> "Sebastian G." wrote:
>
>> Ant wrote:
>>> Error messages (e.g. 404) don't appear in my IE without OK-ing an
>>> ActiveX prompt.

>> Interesting. How did you get such a configuration?

>
> By tweaking the registry values under ...\Internet Settings\Zones\0



And which exactly? I configured everything possible for the Local Zone,
including everything from IE's GUI as well as all group policies.

> Many people would find that a nuisance when performing some normal
> day-to-day operations but I tend not to operate normally.



I know, even the SCM msc applet hicks up when deactivating scripting for the
local zone.

Still I couldn't reproduce your finding that the Help Message Generator COM
Controls from MSIE's internal resource pages could not be instantiated.

>> Instantiation already happens before it tries to apply its policies.

>
> Perhaps limiting ActiveX in *all* zones would stop it.



No, that won't help either: The problem is that the instantiation is done by
the COM Server (typically running in the DCOM Server Service), and it has
its own policies and configuration. And its default policy is to
automatically download, install and update every control it stumbles upon.

> I've yet to see a control instantiated that I haven't explicitly allowed.



LOL? Even the list view in Windows Explorer is implemented by a COM Control.

Reply With Quote
  #20 (permalink)  
Old 02-27-2008, 01:21 AM
Ant
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." wrote:

> Ant wrote:
>> "Sebastian G." wrote:
>>> Ant wrote:
>>>> Error messages (e.g. 404) don't appear in my IE without OK-ing an
>>>> ActiveX prompt.
>>> Interesting. How did you get such a configuration?

>> By tweaking the registry values under ...\Internet Settings\Zones\0

>
> And which exactly? I configured everything possible for the Local Zone,
> including everything from IE's GUI as well as all group policies.


Changing the 'Flags' value in zone 0[1] to 0x47 causes the 'My
Computer' icon to appear on the security tab in the Internet settings
dialog. You can then manipulate the settings as for other zones. I've
set the running of ActiveX to 'prompt'.

[1]
I did this for my user account under HKU, rather than HKLM.

>>> Instantiation already happens before it tries to apply its policies.

>> Perhaps limiting ActiveX in *all* zones would stop it.

>
> No, that won't help either: The problem is that the instantiation is done by
> the COM Server (typically running in the DCOM Server Service), and it has
> its own policies and configuration. And its default policy is to
> automatically download, install and update every control it stumbles upon.


I've disabled DCOM using dcomcnfg.



Reply With Quote
  #21 (permalink)  
Old 02-27-2008, 02:10 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Ant wrote:

> "Sebastian G." wrote:
>
>> Ant wrote:
>>> "Sebastian G." wrote:
>>>> Ant wrote:
>>>>> Error messages (e.g. 404) don't appear in my IE without OK-ing an
>>>>> ActiveX prompt.
>>>> Interesting. How did you get such a configuration?
>>> By tweaking the registry values under ...\Internet Settings\Zones\0

>> And which exactly? I configured everything possible for the Local Zone,
>> including everything from IE's GUI as well as all group policies.

>
> Changing the 'Flags' value in zone 0[1] to 0x47 causes the 'My
> Computer' icon to appear on the security tab in the Internet settings
> dialog. You can then manipulate the settings as for other zones. I've
> set the running of ActiveX to 'prompt'.



Please tell news. Even deactivating ActiveX there changes nothing about
these special ActiveX Controls.

> I've disabled DCOM using dcomcnfg.


No, you've disabled binding DCOM to network protocols.

Reply With Quote
  #22 (permalink)  
Old 02-27-2008, 06:11 PM
Ant
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

"Sebastian G." wrote:

> Ant wrote:
>> Changing the 'Flags' value in zone 0[1] to 0x47 causes the 'My
>> Computer' icon to appear on the security tab in the Internet settings
>> dialog. You can then manipulate the settings as for other zones. I've
>> set the running of ActiveX to 'prompt'.

>
> Please tell news. Even deactivating ActiveX there changes nothing about
> these special ActiveX Controls.


It produces the prompt to allow/disallow running.

>> I've disabled DCOM using dcomcnfg.

>
> No,


Yes.

> you've disabled binding DCOM to network protocols.


And that.



Reply With Quote
  #23 (permalink)  
Old 02-27-2008, 07:33 PM
Sebastian G.
Guest
 
Posts: n/a
Default Re: How to prevent my information from being accessed by webpages

Ant wrote:

>>> I've disabled DCOM using dcomcnfg.

>> No,

>
> Yes.



If you had disabled DCOM, your Windows installation would hardly work any more.

Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Intel Proset profile keeps getting deleted kishorebudha Network Troubleshooting 1 04-04-2008 09:10 PM
The ISO 27000 Newsletter: Issue 15 Released Sue Thomas comp.security.misc 0 08-03-2007 04:39 PM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 10-19-2005 04:37 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 08-30-2005 04:26 AM
[SSL-Talk List FAQ] Secure Sockets Layer Discussion List FAQ v1.1.1 Shannon Appel comp.security.misc 0 07-31-2005 04:25 AM


All times are GMT. The time now is 08:46 PM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0 RC8

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45