Join the AMA (Ask Me Anything) with the Firefox leadership team to celebrate Firefox 20th anniversary and discuss Firefox’s future on Mozilla Connect. Mark your calendar on Thursday, November 14, 18:00 - 20:00 UTC!

为提升您的使用体验,本站正在维护,部分功能暂时无法使用。如果本站文章无法解决您的问题,您想要向社区提问的话,请到 Twitter 上的 @FirefoxSupport 或 Reddit 上的 /r/firefox 提问,我们的支持社区将会很快回复您的疑问。

搜索 | 用户支持

防范以用户支持为名的诈骗。我们绝对不会要求您拨打电话或发送短信,及提供任何个人信息。请使用“举报滥用”选项报告涉及违规的行为。

详细了解

google safe browsing: meaning of "malicious software being downloaded and installed without user consent"

  • 5 个回答
  • 3 人有此问题
  • 1 次查看
  • 最后回复者为 TheOldFox

more options

As an example, see http://www.google.com/safebrowsing/diagnostic?site=google.com What does this phrase mean? Is it a browse-and-get-owned exploit? Is it for outdated browsers, or modern browsers too? Does it require specific vulnerable plugins to be active, such as Java?

As an example, see http://www.google.com/safebrowsing/diagnostic?site=google.com What does this phrase mean? Is it a browse-and-get-owned exploit? Is it for outdated browsers, or modern browsers too? Does it require specific vulnerable plugins to be active, such as Java?

所有回复 (5)

more options

Read the following about "drive-by downloads". Item 2 at the top of the page. User does not need to click on something on the infected page for a download to occur. Simply visiting the page is enough for the download to occur.

You can also read this (3rd paragraph under "Delivery Methods").

由TheOldFox于修改

more options

So in this case, the malware is downloaded, but not run?

more options

Most malware using the drive-by download method is downloaded and automatically installed or the user is fooled with some pop-up to "update" something which they may already have installed or believe that they need to install. Read the last paragraph (above "References") in - https://en.wikipedia.org/wiki/Drive-by_installation

  • A drive-by install (or installation) is a similar event. It refers to installation rather than download (though sometimes the two terms are used interchangeably).

由TheOldFox于修改

more options

Then in this case, how worried should I be about the safebrowsing numbers for "malicious software being downloaded and installed without user consent", if I am using an up-to-date Firefox with javascript enabled? What if I have flash enabled?

more options

Bottom line: The warning is just that - a warning.

  • If a user proceeds to a suspicious site or a site known to be malicious, it is the user's decision and responsibility.
  • The browser used and/or browser settings may or may not protect you if it is a new (zero-day) attack vector. That is the reason for frequent updates.
  • If a user proceeds and is infected with a virus, the user needs to refer to the following for assistance -

The information on the page http://www.google.com/safebrowsing/diagnostic?site=www.google.com seems a bit garbled and contradictory as it starts by saying "Of the 37966 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent" then below that listed sites that may contain malicious downloads. You will need to contact Google about that seeming discrepancy as Mozilla is not involved in visiting or analyzing those pages

I gave you the definition that you requested in your original question. If your aim is to investigate Google's methodology or reporting, then contact Google.