<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; localrodea</title>
	<atom:link href="http://www.ghacks.net/tag/localrodea/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 23:31:44 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Local Rodeo Protects Firefox From JavaScript Malware</title>
		<link>http://www.ghacks.net/2008/09/10/local-rodeo-protects-firefox-from-javascript-malware/</link>
		<comments>http://www.ghacks.net/2008/09/10/local-rodeo-protects-firefox-from-javascript-malware/#comments</comments>
		<pubDate>Wed, 10 Sep 2008 14:06:17 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Browsing]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[anti-dns pinning]]></category>
		<category><![CDATA[firefox malware]]></category>
		<category><![CDATA[intranet exploration]]></category>
		<category><![CDATA[javascript]]></category>
		<category><![CDATA[javscript malware]]></category>
		<category><![CDATA[localrodea]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=6907</guid>
		<description><![CDATA[Keeping up with all the different attack vectors is like the protagonist of Cervante&#8217;s famous novel Don Quixote. New threats are emerging on a daily basis while protections seem to remain stagnant at best. Users could opt for a radical solution by choosing to turn off scripts using NoScript and uninstalling scripting languages like Java [...]]]></description>
			<content:encoded><![CDATA[<p>Keeping up with all the different attack vectors is like the protagonist of Cervante&#8217;s famous novel Don Quixote. New threats are emerging on a daily basis while protections seem to remain stagnant at best. Users could opt for a radical solution by choosing to turn off scripts using NoScript and uninstalling scripting languages like Java and Flash content. </p>
<p>That would make most of the Internet unusable and produce some bad looking websites with reduced functionality while some would stop working completely.</p>
<p>Local Rodeo is a <a href="http://www.ghacks.net/tag/firefox/">Firefox</a> extension that protects Firefox against two types of JavaScript malware. The two types are Intranet Exploration and Anti DNS-Pinning.</p>
<p><span id="more-6907"></span><br />
<blockquote>Intranet Exploration (i.e. JavaScript portscanning and fingerprinting): The extension classifies all network locations to be either local or external, with local locations being part of the intranet. All http requests that have an external origin (i.e. were generated within the execution context of an external webpage) and a local target (i.e. an intranet resource) are canceled by LocalRodeo.</p>
<p>Anti DNS-Pinning: LocalRodeo detects this attack method by monitoring DNS answers. The switch of a given domain from external to local (or vice versa) is a clear indication of an anti-pinning attack. If such a switch is detected, all further requests from or to the malicious domain are prohibbited.</p></blockquote>
<p>A detailed explanation of Anti DNS-Pinning can be found at the blog of <a href="http://christ1an.blogspot.com/2007/07/dns-pinning-explained.html">Christian Matthies</a>. The extension was updated to be compatible with Firefox 3 today.</p>

	Tags: <a href="http://www.ghacks.net/tag/anti-dns-pinning/" title="anti-dns pinning" rel="tag">anti-dns pinning</a>, <a href="http://www.ghacks.net/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a href="http://www.ghacks.net/tag/firefox-malware/" title="firefox malware" rel="tag">firefox malware</a>, <a href="http://www.ghacks.net/tag/intranet-exploration/" title="intranet exploration" rel="tag">intranet exploration</a>, <a href="http://www.ghacks.net/tag/javascript/" title="javascript" rel="tag">javascript</a>, <a href="http://www.ghacks.net/tag/javscript-malware/" title="javscript malware" rel="tag">javscript malware</a>, <a href="http://www.ghacks.net/tag/localrodea/" title="localrodea" rel="tag">localrodea</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2008/06/27/you-better-stop-using-internet-explorer-for-now/" title="You better stop using Internet Explorer for now (June 27, 2008)">You better stop using Internet Explorer for now</a> (18)</li>
	<li><a href="http://www.ghacks.net/2008/08/19/view-javascript-sources-with-jsview/" title="View Javascript Sources with JSView (August 19, 2008)">View Javascript Sources with JSView</a> (1)</li>
	<li><a href="http://www.ghacks.net/2008/10/17/test-your-browsers-javascript-performance/" title="Test Your Browser&#8217;s JavaScript Performance (October 17, 2008)">Test Your Browser&#8217;s JavaScript Performance</a> (5)</li>
	<li><a href="http://www.ghacks.net/2008/01/06/control-javascript-events-in-firefox/" title="Control Javascript Events in Firefox (January 6, 2008)">Control Javascript Events in Firefox</a> (1)</li>
	<li><a href="http://www.ghacks.net/2009/07/16/block-noscript-from-opening-homepage-after-update/" title="Block NoScript From Opening Homepage After Update (July 16, 2009)">Block NoScript From Opening Homepage After Update</a> (8)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/09/10/local-rodeo-protects-firefox-from-javascript-malware/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
	</channel>
</rss>
