Risk
7/19/2010
03:58 PM
Connect Directly
RSS
E-Mail
50%
50%

Dell KACE Offers Free Secure Browser

To protect against web malware, Dell KACE's new free Secure Browser virtualizes a browser and restricts direct and cross-site access to dangerous or inappropriate websites.

To help companies increase the safety of their Windows users' web browsing from malicious code, including restricting direct and cross-site access to dangerous or inappropriate websites, Dell KACE has introduced the Dell KACE Secure Browser, available immediately as a free download.

The Dell KACE Secure Browser consists of a browser -- currently, FireFox 3.6 -- plus plug-ins -- currently, Adobe Flash and Adobe Reader -- plus proprietary Dell KACE "Virtual Kontainer" application virtualization technology developed as part of the company's K1000, all packaged into one download that uses a standard Windows installer.

"The instance of the browser is virtualized," says Rob Meinhardt, President, Dell KACE. "A process may think it is writing to the system, but that doesn't happen."

Dell KACE Secure Browser aims to proactively contain threats before they become a problem. "The UI includes a 'click and undo' for whatever's happened," says Meinhardt.

The initial release is for 32-bit versions of Windows 7, Vista and XP supports the FireFox browser. "We chose FireFox as the best fit for the verticals that our products play in, and FireFox's Open-Source was a good fit for working with -- MSIE is a black box, FireFox lets us see inside." But, Meinhardt adds, "We do intend to support Microsoft Internet Explorer. We will probably start with Internet Explorer 6, since, as a virtual instance, you could run it on Vista or on Windows 7."

According to Meinhardt, downloads do get written to the system disk. "The download isn't contained, but if it were executed, you'd get the process start prompt," says Meinhardt, "And if run from the secure browser, activity would be contained in the secure space." (Hopefully, the user's system will have separate security that will automatically scan any such downloads before trying being accessed other than by Secure Browser...)

Users can update FireFox and the reader plug-ins, as well as install their own plug-ins and extensions, such as NoScript. "Users can update their own instance, and we will release new installers with the latest version of FireFox," says Meinhardt.

The Secure Browser can also allow/disallow programs being invoked by a web page. "If the browser wants to start up a process, like Windows Media Player, it will ask for permission," says Meinhardt. "You say tell it, Always, Now, or Never."

Currently, resetting the Secure Browser restores it to the original state, on an "all or none" basis -- including losing any bookmarks and other settings. "We intend to provide a way to install to your own state, and to exclude things from a reset," says Meinhardt.

The new tool is intended to work in concert with a Dell KACE Dell KACE K1000 Management Appliance on the user's network, which provides the company with network-wide capabilities. However, the Secure Browser does not require a K1000 to be used as a virtualized browsing environment.

Using a K1000, IT can remotely reset or kill a Secure Browser session, and create whitelisting and blacklisting for URLs. "If a permitted site is infected with a cross-site scripting exploit, whatever is on those non-whitelisted sites won't run," says Meinhardt.

According to Meinhardt, the K1000 is intended for use in companies with anywhere from 100 to 10,000 people. "Most of these users are in the mid-100's to mid-thousands of users," says Meinhardt. (MSRP for a K1000 starts at just under $9,000, for use with up to 100 users.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7392
Published: 2014-07-22
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

CVE-2014-2385
Published: 2014-07-22
Multiple cross-site scripting (XSS) vulnerabilities in the web UI in Sophos Anti-Virus for Linux before 9.6.1 allow local users to inject arbitrary web script or HTML via the (1) newListList:ExcludeFileOnExpression, (2) newListList:ExcludeFilesystems, or (3) newListList:ExcludeMountPaths parameter t...

CVE-2014-4326
Published: 2014-07-22
Elasticsearch Logstash 1.0.14 through 1.4.x before 1.4.2 allows remote attackers to execute arbitrary commands via a crafted event in (1) zabbix.rb or (2) nagios_nsca.rb in outputs/.

CVE-2014-4511
Published: 2014-07-22
Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

CVE-2014-4911
Published: 2014-07-22
The ssl_decrypt_buf function in library/ssl_tls.c in PolarSSL before 1.2.11 and 1.3.x before 1.3.8 allows remote attackers to cause a denial of service (crash) via vectors related to the GCM ciphersuites, as demonstrated using the Codenomicon Defensics toolkit.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Where do information security startups come from? More important, how can I tell a good one from a flash in the pan? Learn how to separate ITSec wheat from chaff in this episode.