Go Back   { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Mandriva

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 07-01-2008, 08:56 AM
Dave Farrance
 
Posts: n/a
Is Firefox 3.0-3 from the backports the official release?

Is the Firefox 3.0 in the Mandriva repository the official release?

firefox-3.0-3mdv2008.1.i586 in the main backports is described as:

"This Firefox 3 Release Candidate is a preview release of Mozilla's next
generation Firefox browser and is being made available for testing
purposes only."

And yet the changelog and datestamp suggests that this is based on the
Firefox 3.0 official release. I don't want to install release
candidates, when I've only got to wait a little while for a release, and
anyway, I've been having enough issues lately with various standard
2008.1 packages. And I'm not going to get the generic Linux version from
Mozilla, because although most people find them OK, there's likely to be
extra work involved in its future maintenance and update.

What's prompted this is that I stumbled across a site, the Washington
Post, that dumped on my Firefox 2.0.0.14. When I arrived at a story
there, after following a link from Digg, that page's Google-powered
rotating adverts popped up a very nasty "anti-virus" site.

DON'T VISIT THESE PAGES IF YOU'RE USING A MICROSOFT OS:

Here's the Washington post story. I guess it's OK most of the time since
the ads are rotating. Firstly, the annoyance is that they've found a way
to break Firefox 2's view-source, so I can't see the source html to find
the follow-on link. The text "DELETETHIS" in this URL must be removed.

http://www.washDELETETHISingtonpost....6073-2004Apr15

And secondly, here's the ad that popped up. It does stuff that Firefox
shouldn't allow. Its script resizes the window, and immediately starts
up the dialogue box saying that you've chosen to open a DOS/Windows
executable. If you close that dialogue and then try to close the window
with the usual terminate-window decoration, then it pops up another
window saying that a virus has been discovered on your machine, and the
open-file dialogue opens again, and this time you can't close it until
the virus-warning popup is closed first. The only way to terminate the
window is with the ctrl-alt-esc cursor of death. Presumably Windows
users would be in trouble here. I thought that browsers had fixed tricks
like this long ago.

http://virDELETETHISus-scanonline.com/nag/

I get the feeling that I should report this somewhere. Anybody know if
Mozilla is still doing security updates to Firefox 2? Firstly the method
by which the scumbags at the Washington Post were able to break the
source code inspection should be fixed, and secondly, the ability of the
fancy scripting used by the vastly worse scumbags at the virus site to
mess with the window management should also be disabled.

--
Dave Farrance
Reply With Quote
  #2 (permalink)  
Old 07-01-2008, 10:55 AM
Bit Twister
 
Posts: n/a
Re: Is Firefox 3.0-3 from the backports the official release?

On Tue, 01 Jul 2008 08:56:48 GMT, Dave Farrance wrote:

> And secondly, here's the ad that popped up. It does stuff that Firefox
> shouldn't allow.


You have firefox controls, have you not set your preferences.
If you have java* enabled, then you give up control to the programmer.

Black hats have been cracking AD servers, not to mention WEB servers.
Since I have installed the privoxy package and installed NoScript Add On,
my browsing speed has increased not to mention MUCH better security.

http://groups.google.com/group/alt.o...c4674ee714a691

As for waiting for third party app updates, I think it is stupid to wait.
Usually exploits are out there within 24 hours of patch update release
hunting for people with unpatched apps.

I keep a /local/opt partition for third party installs.
Example firefox 3.0 install commands follow:

--------------------------------------------------------------
#* Package downloaded from
#* http://download.mozilla.org/?product...nux&lang=en-US

cd /local/opt
tar xvpjf /downloads/firefox-3.0.tar.bz2
mv firefox firefox-3.0

# move the runtime app's link

/bin/rm -f /usr/local/bin/firefox
ln -s /local/opt/firefox-3.0/firefox /usr/local/bin
ls -al /usr/local/bin
--------------------------------------------------------------


My PATH variable has /usr/local/bin moved towards the front so my
installs run instead of default package installs.

echo $PATH
/sbin:/usr/sbin:/usr/local/bin:/usr/local/bin:/bin:/usr/bin:/usr/bin/X11:/usr/games:/usr/lib/qt4/bin
Reply With Quote
  #3 (permalink)  
Old 07-01-2008, 12:52 PM
wisdomkiller & pain
 
Posts: n/a
Re: Is Firefox 3.0-3 from the backports the official release?

Dave Farrance wrote:

> Is the Firefox 3.0 in the Mandriva repository the official release?
>
> firefox-3.0-3mdv2008.1.i586 in the main backports is described as:
>

......
> 2008.1 packages. And I'm not going to get the generic Linux version from
> Mozilla, because although most people find them OK, there's likely to be
> extra work involved in its future maintenance and update.
>

Not so much work. It is updateable just like the windows version.
However, your user must have write permission to the firefox program folder.
Since I don't want to give these permissions permanently, I _do_ start
firefox with sudo _just_ for updating.

> What's prompted this is that I stumbled across a site, the Washington
> Post, that dumped on my Firefox 2.0.0.14. When I arrived at a story
> there, after following a link from Digg, that page's Google-powered
> rotating adverts popped up a very nasty "anti-virus" site.
>
> DON'T VISIT THESE PAGES IF YOU'RE USING A MICROSOFT OS:
>
> Here's the Washington post story. I guess it's OK most of the time since
> the ads are rotating. Firstly, the annoyance is that they've found a way
> to break Firefox 2's view-source, so I can't see the source html to find
> the follow-on link. The text "DELETETHIS" in this URL must be removed.
>
> http://www.washDELETETHISingtonpost....6073-2004Apr15
>

Probably, either the washingtonpost site or - more likely - one of the
adservers that are called in rotation, were hacked and cracked.
Now I have adblockplus and noscript in place and don't see that crap.
Even more so though the privoxy :)
Reply With Quote
Reply

  { mindfrost82.com } > Gadget Corner > Tech Newsgroups > Linux > Mandriva


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 01:16 PM.


Powered by vBulletin, Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.1.0 ©2007, Crawlability, Inc.
© 1999-2008 mindfrost82.com v11.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109