Risk
7/19/2010
03:58 PM
50%
50%

Dell KACE Offers Free Secure Browser

To protect against web malware, Dell KACE's new free Secure Browser virtualizes a browser and restricts direct and cross-site access to dangerous or inappropriate websites.

To help companies increase the safety of their Windows users' web browsing from malicious code, including restricting direct and cross-site access to dangerous or inappropriate websites, Dell KACE has introduced the Dell KACE Secure Browser, available immediately as a free download.

The Dell KACE Secure Browser consists of a browser -- currently, FireFox 3.6 -- plus plug-ins -- currently, Adobe Flash and Adobe Reader -- plus proprietary Dell KACE "Virtual Kontainer" application virtualization technology developed as part of the company's K1000, all packaged into one download that uses a standard Windows installer.

"The instance of the browser is virtualized," says Rob Meinhardt, President, Dell KACE. "A process may think it is writing to the system, but that doesn't happen."

Dell KACE Secure Browser aims to proactively contain threats before they become a problem. "The UI includes a 'click and undo' for whatever's happened," says Meinhardt.

The initial release is for 32-bit versions of Windows 7, Vista and XP supports the FireFox browser. "We chose FireFox as the best fit for the verticals that our products play in, and FireFox's Open-Source was a good fit for working with -- MSIE is a black box, FireFox lets us see inside." But, Meinhardt adds, "We do intend to support Microsoft Internet Explorer. We will probably start with Internet Explorer 6, since, as a virtual instance, you could run it on Vista or on Windows 7."

According to Meinhardt, downloads do get written to the system disk. "The download isn't contained, but if it were executed, you'd get the process start prompt," says Meinhardt, "And if run from the secure browser, activity would be contained in the secure space." (Hopefully, the user's system will have separate security that will automatically scan any such downloads before trying being accessed other than by Secure Browser...)

Users can update FireFox and the reader plug-ins, as well as install their own plug-ins and extensions, such as NoScript. "Users can update their own instance, and we will release new installers with the latest version of FireFox," says Meinhardt.

The Secure Browser can also allow/disallow programs being invoked by a web page. "If the browser wants to start up a process, like Windows Media Player, it will ask for permission," says Meinhardt. "You say tell it, Always, Now, or Never."

Currently, resetting the Secure Browser restores it to the original state, on an "all or none" basis -- including losing any bookmarks and other settings. "We intend to provide a way to install to your own state, and to exclude things from a reset," says Meinhardt.

The new tool is intended to work in concert with a Dell KACE Dell KACE K1000 Management Appliance on the user's network, which provides the company with network-wide capabilities. However, the Secure Browser does not require a K1000 to be used as a virtualized browsing environment.

Using a K1000, IT can remotely reset or kill a Secure Browser session, and create whitelisting and blacklisting for URLs. "If a permitted site is infected with a cross-site scripting exploit, whatever is on those non-whitelisted sites won't run," says Meinhardt.

According to Meinhardt, the K1000 is intended for use in companies with anywhere from 100 to 10,000 people. "Most of these users are in the mid-100's to mid-thousands of users," says Meinhardt. (MSRP for a K1000 starts at just under $9,000, for use with up to 100 users.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Yeah, my cookies were deleted too!!"
Current Issue
Five Things Every Business Executive Should Know About Cybersecurity
Don't get lost in security's technical minutiae - a clearer picture of what's at stake can help align business imperatives with technology execution.
Flash Poll
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Dark Reading Strategic Security Report: The Impact of Enterprise Data Breaches
Social engineering, ransomware, and other sophisticated exploits are leading to new IT security compromises every day. Dark Reading's 2016 Strategic Security Survey polled 300 IT and security professionals to get information on breach incidents, the fallout they caused, and how recent events are shaping preparations for inevitable attacks in the coming year. Download this report to get a look at data from the survey and to find out what a breach might mean for your organization.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-7445
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

CVE-2015-4948
Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

CVE-2015-5660
Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

CVE-2015-6003
Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

CVE-2015-6333
Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
Security researchers are finding that there's a growing market for the vulnerabilities they discover and persistent conundrum as to the right way to disclose them. Dark Reading editors will speak to experts -- Veracode CTO and co-founder Chris Wysopal and HackerOne co-founder and CTO Alex Rice -- about bug bounties and the expanding market for zero-day security vulnerabilities.