Recommended Posts

haven't you lot heard of FTP?

go to the command prompt and type "ftp o ftp.mozilla.org", low and behold you're connected to Mozilla's FTP servers, ready to download Mozilla [Firefox]

585380631[/snapback]

Actually you have to type in a username and password (anonymous:email), which would confuse most people. We're not talking about the people at neowin here, we're talking about your average computer user.

They also gave:-

Hackers An easy way into the users pc system,

An easy way to install spyware

A Buggy pile of s**t

585380560[/snapback]

I was waiting for you!!! Go here, Securityfocus and have a look at all the vulnerabilities in ALL browsers out there including Firefox, there is a ****load, believe me! Head to the SecurityFocus vulnerabilities page, select Mozilla for the company name, then Firefox for the product. You'll find several serious problems.

lol, if ie didn't originally come with windows, how they hell would ppl download firefox?

Netscape, Mosaic, among others. There would likely be no Firfox as it is the child of Mozilla (Mosaic Killer).

all the fanboys wouldn't be able to access the site without going to the store to purchase *shudder* the browser they hate so much. cuz, common, mozilla wouldn't distribute firefox to stores.

Obviously you are too young to remember that Netscape came bundled with PCs, back in the days. Before that it was Mosaic.

I would say ... every ISP would have followed the AOL route. They would have come up with their own browsers, just like AOL. So today, we would have had hundreds of browsers ... and most of them incompatible with one site or the other!

OMG

Switching ISPs would have meant switching and learning a new browser! Aaaah it would have been a much bigger hell.

I never had to switch browsers when I switched providers. Netscape and Mosaic shared a similar code base.

i say, keep it bundled with xp on a seperate cd install

IE is just a UI wrapper for the explorer shell. The rest of the middleware could be installed separately. Of course Windows would hiccup everytime you wanted to play some media file. "You must install a multimedia player to........We suggest...."

:rolleyes: :rolleyes: :rolleyes: :rolleyes:

Settle down. Remember kids are just adults without brains.

I was waiting for you!!! Go here, Securityfocus and have a look at all the vulnerabilities in ALL browsers out there including Firefox, there is a ****load, believe me! Head to the SecurityFocus vulnerabilities page, select Mozilla for the company name, then Firefox for the product. You'll find several serious problems.

585381050[/snapback]

There are four in FF 1.0:

I can't be bothered to list all the IE6 SP2 as neatly as above:

2005-01-18: Microsoft Internet Explorer Remote Information Disclosure Vulnerability

2005-01-15: Microsoft Internet Explorer Dynamic IFRAME File Download Security Warning Bypass Weakness

2005-01-05: Multiple Browser IMG Tag Multiple Vulnerabilities

2004-12-30: Microsoft Internet Explorer FTP URI Arbitrary FTP Server Command Execution Vulnerability

2004-12-15: Microsoft Internet Explorer DHTML Edit Control Script Injection Vulnerability

2004-12-10: Microsoft Internet Explorer Remote Window Hijacking Vulnerability

2004-12-08: Microsoft Internet Explorer Search Pane URI Obfuscation Vulnerability

2004-11-28: Microsoft Internet Explorer Drag and Drop Vulnerability

2004-11-26: Microsoft Internet Explorer Image Download Filename Extension Spoofing Vulnerability

2004-11-25: Microsoft Internet Explorer Infinite Array Sort Denial Of Service Vulnerability

2004-11-19: Microsoft Internet Explorer File Download Security Warning Bypass Vulnerability

2004-11-12: Microsoft Internet Explorer Embedded Content Status Bar URI Obfuscation Weakness

2004-11-03: Microsoft Internet Explorer Valid File Drag and Drop Embedded Code Vulnerability

2004-10-30: Microsoft Internet Explorer HTML Form Base A Tag Status Bar Spoofing Weakness

2004-10-26: Microsoft Internet Explorer Font Tag Denial Of Service Vulnerability

2004-10-25: Microsoft Internet Explorer HHCtrl ActiveX Control Cross-Domain Scripting Vulnerability

2004-10-23: Microsoft Internet Explorer Malformed HTML Null Pointer Dereference Vulnerability

2004-10-18: Microsoft Internet Explorer Implicit Drag and Drop File Installation Vulnerability

2004-10-18: Microsoft Internet Explorer Heartbeat ActiveX Control Unspecified Vulnerability

2004-10-18: Microsoft Internet Explorer Unspecified showHelp Zone Bypass Vulnerability

2004-10-10: Microsoft Internet Explorer Local XML Document Disclosure Vulnerability

2004-10-05: Multiple Browser Cross-Domain Cookie Injection Vulnerability

2004-09-16: Microsoft Internet Explorer User Security Confirmation Bypass Vulnerability

Opera 7.54:

2004-12-13: Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability

2004-12-08: Opera Web Browser Remote Window Hijacking Vulnerability

2004-11-25: Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability

2004-11-19: Opera Web Browser Java Implementation Multiple Remote Vulnerabilities

2004-10-23: Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability

2004-10-20: Opera Web Browser Cross-Domain Dialog Box Spoofing Vulnerability

There are four in FF 1.0:
First, you're not even considering which of those are already patched, for any of those browsers.

Second, you're only including FF 1.0 which has been only a whole 2 months.. vs IE 6.0 which has been years and Opera 7.54 which has been out since the beginning of the year.

Try including ALL FF since sep/october like you did IE and Opera.

Firefox ALL Since 9/01

2005-01-11: Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulnerability

2005-01-05: Mozilla Temporary File Insecure Permissions Information Disclosure Vulnerability

2005-01-05: Multiple Browser IMG Tag Multiple Vulnerabilities

2005-01-05: Mozilla Firefox Download Dialogue Box File Name Spoofing Vulnerability

2005-01-05: Mozilla Firefox Insecure Default Installation Vulnerability

2005-01-04: Mozilla/Firefox File Download Dialog Spoofing Vulnerability

2004-12-08: Mozilla Browser and Mozilla Firefox Remote Window Hijacking Vulnerability

2004-12-07: Mozilla/Netscape/Firefox Browsers JavaScript IFRAME Rendering Denial Of Service Vulnerability

2004-12-01: LibPNG Graphics Library Multiple Remote Vulnerabilities

2004-11-25: Mozilla Firefox Infinite Array Sort Denial Of Service Vulnerability

2004-11-01: Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability

2004-10-27: Mozilla/Firefox Browsers Unauthorized Clipboard Contents Disclosure

2004-10-27: Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities

2004-10-27: Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability

2004-10-27: Mozilla Browser Non-FQDN SSL Certificate Spoofing Vulnerability

2004-10-27: Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability

2004-10-27: Mozilla Browser Refresh Security Property Spoofing Vulnerability

2004-10-27: Multiple Vendor Internet Browser User Action Prediction/Interception Weakness

2004-10-27: Mozilla SSL Redirect Spoofing Vulnerability

2004-10-27: Mozilla Cross-Domain Frame Loading Vulnerability

2004-10-27: Mozilla Browser Cache File Multiple Vulnerabilities

2004-10-27: Mozilla Personal Security Manager Certificate Handling Denial Of Service Vulnerability

2004-10-22: Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability

2004-10-22: Mozilla Firefox XPInstall Default Installation File Permission Vulnerability

2004-10-20: Mozilla Browser Cross-Domain Tab Window Form Field Focus Vulnerability

2004-10-06: Mozilla Firefox DATA URI File Deletion Vulnerability

2004-10-05: Multiple Browser Cross-Domain Cookie Injection Vulnerability

2004-10-05: Mozilla Browser Non-ASCII Hostname Heap Overflow Vulnerability

2004-09-15: Mozilla/Firefox Browsers Tar.GZ Archive Weak Permissions Vulnerability

Opera ALL since 9/01

2004-12-13: Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability

2004-12-11: Opera Web Browser Download Dialogue Box File Name Spoofing Vulnerability

2004-12-08: Opera Web Browser Remote Window Hijacking Vulnerability

2004-11-25: Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability

2004-11-19: Opera Web Browser Java Implementation Multiple Remote Vulnerabilities

2004-10-23: Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability

2004-10-20: Opera Web Browser Cross-Domain Dialog Box Spoofing Vulnerability

2004-09-07: Opera Web Browser Cross-Domain Frame Loading Vulnerability

2004-09-01: Opera Web Browser Empty Embedded Object JavaScript Denial Of Service Vulnerability

Now stop spreading misinformation in my thread please. This is about Microsft and Internet Explorer.

[Mods: move this if you see fit.  It probably does belong there, so sorry if you do have to move it]

Here's a debate I have not seen in a while.

How do you all feel about Microsoft being sued for shipping IE with windows as the default browser?

Personally, I think it's absolute bollox.  They are including their own utility (IE) in their own software (Windows).  Having a browser come with Windows really helped the internet move along as fast as it did, in my opinion.  People were able to browse the net without having to go to the store or order software to do so.  It came for free* with their computer.

Did Windows not let you install another browser?  Absolutely not.  Did it recommend you not use it when you did? Nope. Did it try to do anything to stop you from installing another browser?  Nope.

It was simply a better browser and more convenient for users.  Besides, if IE wasn't shipped with windows.. how could you download another browser?!  You'd have to go to the store and PAY for Netscape, or order Opera from someone elses computer.

I simply fail to see how a software company can be accused of a "browser monopoly" for including software within their own software, and having the better product.

585372458[/snapback]

You know what really ****es me off is that my ford motor won?t fit in my Chevy and on top of that they refuse to reply to my requests. They have a motor and transmission, just like the next. I absolutely know the automotive manufactures change the bolt patterns so I specifically can't use my motor of choice. I think this is a more serious problem then what browser is supplied with one operating system.

Every time this comes up someone just HAS to use that stupid car analogy. If you like cars so much go to the neobahn, your flawed analogy has no place here.

To all those looking at securityfocus: don't take it too seriously. Securityfocus is known to post up just about anything that is submitted. That Mozilla Firefox Infinite Array Sort Denial Of Service Vulnerability might have come from a IS professional, or it could have come from some propellerhead in Ohio.

wait... i had no idea they were told to remove IE... So they go out and get a new pc/ do fresh windows install but then dont even hav a browser to get the browser they want.... and what about the new sp2 IE... they got to remove that to... they cant put it up for download because it will be hacked into 2000 and 98 os which its not ment for

Lets' make one thing clear for all those who are saying "Why isn't Apple being sued?!?":

* First, Apple has not been found buy a court of law to be a monopoly. It is as simple as that!

* Secondly, Apple only control, what 5% of the personal computer industry? Hardly enough to be a monopoly.

* Thirdly, for you who say that Safari comes bundled with OS X, well it can be uninstalled. Here is how.

ps. This whole topic is all about flamewar.

Here's what, in my opinion, Microsoft did:

1. Microsoft notices Netscape Navigator catching on, they also notice that a lot of people love it, and Netscape Communications is producing this browser equally on Windows, Mac OS, and UNIX systems. This is a problem to them, if applications are developed for the web, there won't be any need to use Windows anymore.

2. Microsoft, as quickly as they can, license the Mosaic (pre-netscape) code and build a browser around it. It's pretty horrible until version 3 or so, but it's free. Later versions tie into the Windows Explorer shell of Windows 95, and don't allow you to remove it.

3. From Windows 98 and onwards, Microsoft bundles IE with Windows, had it everywhere in the shell and highly visible, and forces OEMs to not include Netscape, as well as have an Internet Explorer icon on the desktop, or else they will charge much, much more for their Windows license. This is what they were convicted for, by the way. They're also butchering HTML (Although Netscape did this as well) so many websites will only work with IE on windows.

4. Microsoft also sees Java as a threat, so they hack together a way to run full-blown Windows programs in IE (ActiveX), not really any care for security, just trying to get it adopted as quickly as possible. Aside from ActiveX, since Java is already well adopted, Microsoft licenses Java from Sun and creates their own virtual machine. They make modifications to their Java VM that their license agreement does not allow them to do, so they can butcher the Java specification and cause certain Java applications/applets to only run on Windows. Microsoft has been sued by Sun because of this, and Sun won, which is why there is no more MSJVM (And hey, look, a thing called C# that's similar to Java and runs in the .NET CLR....hmm....).

I don't hate Microsoft for bundling products with their OS, like what Apple does, but they simply used incredibly unfair tactics towards other companies and didn't "play well with others" by destroying specifications to lock people into Windows.

Edited by tapo
First, you're not even considering which of those are already patched, for any of those browsers.

Second, you're only including FF 1.0 which has been only a whole 2 months.. vs IE 6.0 which has been years and Opera 7.54 which has been out since the beginning of the year.

Try including ALL FF since sep/october like you did IE and Opera.

Firefox ALL Since 9/01

2005-01-11:  Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulnerability

  2005-01-05:  Mozilla Temporary File Insecure Permissions Information Disclosure Vulnerability

  2005-01-05:  Multiple Browser IMG Tag Multiple Vulnerabilities

  2005-01-05:  Mozilla Firefox Download Dialogue Box File Name Spoofing Vulnerability

  2005-01-05:  Mozilla Firefox Insecure Default Installation Vulnerability

  2005-01-04:  Mozilla/Firefox File Download Dialog Spoofing Vulnerability

  2004-12-08:  Mozilla Browser and Mozilla Firefox Remote Window Hijacking Vulnerability

  2004-12-07:  Mozilla/Netscape/Firefox Browsers JavaScript IFRAME Rendering Denial Of Service Vulnerability

  2004-12-01:  LibPNG Graphics Library Multiple Remote Vulnerabilities

  2004-11-25:  Mozilla Firefox Infinite Array Sort Denial Of Service Vulnerability

  2004-11-01:  Mozilla Browser Cross-Domain Dialog Box Spoofing Vulnerability

  2004-10-27:  Mozilla/Firefox Browsers Unauthorized Clipboard Contents Disclosure 

  2004-10-27:  Mozilla Browser BMP Image Decoding Multiple Integer Overflow Vulnerabilities

  2004-10-27:  Mozilla/Firefox Browsers URI Drag And Drop Cross-Domain Scripting Vulnerability

  2004-10-27:  Mozilla Browser Non-FQDN SSL Certificate Spoofing Vulnerability

  2004-10-27:  Mozilla Firefox XML User Interface Language Browser Interface Spoofing Vulnerability

  2004-10-27:  Mozilla Browser Refresh Security Property Spoofing Vulnerability

  2004-10-27:  Multiple Vendor Internet Browser User Action Prediction/Interception Weakness

  2004-10-27:  Mozilla SSL Redirect Spoofing Vulnerability

  2004-10-27:  Mozilla Cross-Domain Frame Loading Vulnerability

  2004-10-27:  Mozilla Browser Cache File Multiple Vulnerabilities

  2004-10-27:  Mozilla Personal Security Manager Certificate Handling Denial Of Service Vulnerability

  2004-10-22:  Mozilla/Firefox Browsers PrivilegeManager EnablePrivilege Dialog Manipulation Vulnerability

  2004-10-22:  Mozilla Firefox XPInstall Default Installation File Permission Vulnerability

  2004-10-20:  Mozilla Browser Cross-Domain Tab Window Form Field Focus Vulnerability

  2004-10-06:  Mozilla Firefox DATA URI File Deletion Vulnerability

  2004-10-05:  Multiple Browser Cross-Domain Cookie Injection Vulnerability

  2004-10-05:  Mozilla Browser Non-ASCII Hostname Heap Overflow Vulnerability

  2004-09-15:  Mozilla/Firefox Browsers Tar.GZ Archive Weak Permissions Vulnerability

Opera ALL since 9/01

2004-12-13:  Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability

  2004-12-11:  Opera Web Browser Download Dialogue Box File Name Spoofing Vulnerability

  2004-12-08:  Opera Web Browser Remote Window Hijacking Vulnerability

  2004-11-25:  Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability

  2004-11-19:  Opera Web Browser Java Implementation Multiple Remote Vulnerabilities

  2004-10-23:  Opera Browser TBODY COL SPAN Memory Corruption Denial Of Service Vulnerability

  2004-10-20:  Opera Web Browser Cross-Domain Dialog Box Spoofing Vulnerability

  2004-09-07:  Opera Web Browser Cross-Domain Frame Loading Vulnerability

  2004-09-01:  Opera Web Browser Empty Embedded Object JavaScript Denial Of Service Vulnerability

Now stop spreading misinformation in my thread please.  This is about Microsft and Internet Explorer.

585381350[/snapback]

Thats irrelevant, I compared the latest release versions of each of the browsers and IE 6 SP2 hasn't been around long at all.

I have a few beefs with integrated (not bundled - INTEGRATED. IE is the system shell for Win98 to XP and onward.) IE:

1. Sure, you can get another browser, and install it, and use it, but the fact of the matter is that IE cannot be uninstalled if you don't want it. On Win98/ME it can be... but only with a commercial third-party program that can do some magic with the Windows .INF files and installing the Win95 shell. On Win2k/XP, it's pointless to even imagine trying. Things like the device manager have IE dependencies, without IE you're dead in the water. It's just not possible, things break EVERYWHERE. And the NT4 shell doesn't work very well on XP because things like the network configuration tools are COM objects that only the IE shell can play with - I know, I've personally played with getting the NT4 shell to work on 2k/XP and given up, with slightly less slightly greyer hair. Yes, I know there will be two big answers to this problem, "omfg go back to win95 u stpid nub stop standing in the way of progress" and "Just Use Linux," but there are good reasons not to use both ;)

2. On a similar note, "vital system files" and various things like the IE HTML renderer are highly recommended to be used in 3rd-party programs and can't be gotten without installing IE. IE is not a choice, it is a requirement. This is ignoring the fact the user has no choice in deciding whether or not you want the IE renderer doing things, which recently has shown itself to be a Very Bad Idea.

Really, all of this could have been avoided and made everybody happy simply by continuing the development of the Win95/NT4 shell as a shell, and not a web browser, making the necessary OS library improvements a "service pack," and then writing the web browser as a client program like any other, and distributing it on a CD like any other, with a piece of paper with it telling Joe SixPack in 24pt TNR how to install IE and set msn.com as his homepage. But providing an OS and optional application software for it isn't MS's way - in their mind, the application software is and should be the OS, and the OS is the computer. They can't imagine a world where people use software they didn't write - not that it stops that many people. Rant, terminated.

Edited by vertigosity
I have a few beefs with integrated (not bundled - INTEGRATED. IE is the system shell for Win98 to XP and onward.) IE:

1. Sure, you can get another browser, and install it, and use it, but the fact of the matter is that IE cannot be uninstalled if you don't want it. On Win98/ME it can be... but only with a commercial third-party program that can do some magic with the Windows .INF files and installing the Win95 shell. On Win2k/XP, it's pointless to even imagine trying. Things like the device manager have IE dependencies, without IE you're dead in the water.

585385002[/snapback]

This isn't totally correct. Nlite can remove IE and the IECore. The device manager and management console do not require IE, but you are correct, some things do require IE. Those things include:

User Accounts thing in the control panel (but you can just use the user accounts thing in the management console anyway)

System Restore/remote management

Some MS Office Programs, as well as others listed here

Here's what, in my opinion, Microsoft did:

1. Microsoft notices Netscape Navigator catching on, they also notice that a lot of people love it, and Netscape Communications is producing this browser equally on Windows, Mac OS, and UNIX systems. This is a problem to them, if applications are developed for the web, there won't be any need to use Windows anymore.

2. Microsoft, as quickly as they can, license the Mosaic (pre-netscape) code and build a browser around it. It's pretty horrible until version 3 or so, but it's free. Later versions tie into the Windows Explorer shell of Windows 95, and don't allow you to remove it.

3. From Windows 98 and onwards, Microsoft bundles IE with Windows, had it everywhere in the shell and highly visible, and forces OEMs to not include Netscape, as well as have an Internet Explorer icon on the desktop, or else they will charge much, much more for their Windows license. This is what they were convicted for, by the way. They're also butchering HTML (Although Netscape did this as well) so many websites will only work with IE on windows.

4. Microsoft also sees Java as a threat, so they hack together a way to run full-blown Windows programs in IE (ActiveX), not really any care for security, just trying to get it adopted as quickly as possible. Aside from ActiveX, since Java is already well adopted, Microsoft licenses Java from Sun and creates their own virtual machine. They make modifications to their Java VM that their license agreement does not allow them to do, so they can butcher the Java specification and cause certain Java applications/applets to only run on Windows. Microsoft has been sued by Sun because of this, and Sun won, which is why there is no more MSJVM (And hey, look, a thing called C# that's similar to Java and runs in the .NET CLR....hmm....).

I don't hate Microsoft for bundling products with their OS, like what Apple does, but they simply used incredibly unfair tactics towards other companies and didn't "play well with others" by destroying specifications to lock people into Windows.

585384706[/snapback]

its been long time since i saw anyone post a "detailed" , "with real content" , "all facts" reply like you have done. i hope you continue to reply like this... neowin needs such posters.

Thats irrelevant, I compared the latest release versions of each of the browsers and IE 6 SP2 hasn't been around long at all.

585384955[/snapback]

No, it is not irrelevant. You compared a product which has been out for 2 months to a product that has been out since the beginning of the year and another product that has been out a while as well. But fine, if you want to play that game, I will play.

Mozilla Firefox since 1.0 since it came out 11/9

2005-01-11: Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulnerability

2005-01-04: Mozilla/Firefox File Download Dialog Spoofing Vulnerability

2004-12-08: Mozilla Browser and Mozilla Firefox Remote Window Hijacking Vulnerability

2004-12-07: Mozilla/Netscape/Firefox Browsers JavaScript IFRAME Rendering Denial Of Service Vulnerability

Opera 7.54 since 11/9

2004-12-13: Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability

2004-12-08: Opera Web Browser Remote Window Hijacking Vulnerability

2004-11-25: Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability

2004-11-19: Opera Web Browser Java Implementation Multiple Remote Vulnerabilities

Now, Opera 7.54 was out since before 11/9, so those first 2 could been worked on before 11/9, but we will count them anyways, even though it is unfair to Opera.

So look at that, 4 vulns for each.

No, it is not irrelevant.  You compared a product which has been out for 2 months to a product that has been out since the beginning of the year and another product that has been out a while as well.  But fine, if you want to play that game, I will play.

Mozilla Firefox since 1.0 since it came out 11/9

2005-01-11:  Mozilla/Netscape/Firefox Browser Modal Dialog Spoofing Vulnerability

2005-01-04:  Mozilla/Firefox File Download Dialog Spoofing Vulnerability

2004-12-08:  Mozilla Browser and Mozilla Firefox Remote Window Hijacking Vulnerability

2004-12-07:  Mozilla/Netscape/Firefox Browsers JavaScript IFRAME Rendering Denial Of Service Vulnerability

Opera 7.54 since 11/9

2004-12-13:  Opera Web Browser KDE KFMCLIENT Remote Command Execution Vulnerability

2004-12-08:  Opera Web Browser Remote Window Hijacking Vulnerability

2004-11-25:  Opera Web Browser Infinite Array Sort Denial Of Service Vulnerability

2004-11-19:  Opera Web Browser Java Implementation Multiple Remote Vulnerabilities

Now, Opera 7.54 was out since before 11/9, so those first 2 could been worked on before 11/9, but we will count them anyways, even though it is unfair to Opera.

So look at that, 4 vulns for each.

585385890[/snapback]

Good, I don't have a problem with Opera personally, the original post was more to illustrate how many bugs IE had compared to the other 2 popular browsers. :)

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.