[Q] javascript / browser security advice. - General Questions and Answers

Hey guys, I'm currently using a HTC sensation with the default browser.
The other day a website I was on redirected me to an untrustworthy site which then (via javascript) started an automatic download (virus) I quickly killed my connection and deleted the partial download.
So on my PC I run Google chrome with a "click to play" plugin to avoid rogue javascripts, I am looking for something similar for my phone.
I know chrome is available for my phone however it does not support flash player which is a requirement, I am aware my current browser has a "on demand" option for plugins but I have tested it and it doesn't work.
I tried opera today and couldn't get along with it.
Could anyone tell me the best way to control what gets downloaded from websites on my phone.
Thankyou in advance for any helpful replies. D

I mean, maybe I have been amiss, but I was under the longstanding impression that hijacks, viruses, and all such malware really didn't effect Linux systems. Like, at all.

Well I don't know much about these operating systems but an executable that downloads itself is not something I want on my phone, regardless of its capabilities.
It was an android application package I do not know if its able to extract itself or if it relies on the user to click on it in the download section, don't know what it installs but I'd rather not find out.

Related

Android Brower Issue-multiple pop up windows

Hey Guys,
I have an issue with some of the browsers available for the android phone.
I would like to access work through my phone via VPN web access. I am sucessfull at this.
When I open my work page, it opens up in a popup window. This is okay too as I allow pop ups under settings.
The issue is, when I click on a case in this pop up window, there is an error thats comes up saying"Cannot open another pop up window, only one pop up window at a time". It is trying to open up my case in another pop up window, which it blocks.
I have used froyo 2.2 on a Nexus one, dell streak, galaxy s tab and motorola droid.
I also used Dolphin HD and Dolphin, with the same results.
I downloaded opera, and there was not even an option for allowing pop ups.
Do you guys have any ideas?
I would like to be able to do my work with out having to lug around a laptop everywhere I go.
Thanks again and Happy Holidays!
Maluman
I would love to find out if this is an Android restriction or there are indeed browsers that support multiple pop ups (or can be tweaked to do so). There are some legit websites that actually rely on pop ups for various purposes (chat rooms for example). Old fashioned and annoying yes, but why punish the end users for it?
Darn, I have the same issue on my HTC EVO. My work website uses pop-ups, but I can't open the link on the pop-up that uses another pop-up! All legitimate pop-ups, not ad-ware. There must be a way to allow trusted sites or something.
Is there a solution to this issue??
Has anyone found an answer/fix to this issue? It is definitely an Android issue b/c I have the new HTC Sensation running Android Gingerbread 2.3, and everyone I know w/ an Android phone from 2 years ago to present has had this same issue....we can not open more than 1 popup window at a time. Like all have posted in this thread, I'm trying to access a number of different applications within my job's website (SWAlife - website for Southwest Airlines employees but specifically for flight attendants to change/trade their trips) and it relies on opening popups within popups but it just doesn't work w/ Android devices.
I've tried the stock browser, Dolphin, Opera mini, Skyfire, rotating the phone horizontally, keeping the setting in Landscape only mode while browsing, and of course, allowing Popups in the browser settings. I also need the browser to allow double-clicks to be just that - a double-click.....not a zoom in and out function.
Please, can someone tell me if there is a fix somewhere to this problem??? I'm interested in buying the new Samsung Galaxy S II but refuse to if I'm not able to access all elements of my job's website. Oh, and someone made a SWAlife app that's accessible with iPhone only (works perfectly & allows popups to open within popups) but I HATE to have to buy an iPhone just b/c of this app. :-(
Thanks in advance for any help anyone can provide!!
You know the SWAlife app is in the Android market too, but you will not be able to check the overtime call out list, not built in to the app yet, same with from iPhone app.
Sent from my PC36100 using Tapatalk
Yea, I've used the Android SWAlife app for some time but it only employees to make non-rev listings, provides company news and operational updates. No Crew Web Access or FA scheduling. In otherwords, this app is pretty useless :-( The one for iPhone, however, is EXACTLY what we need for Android. It allows pilots and FAs to manipulate their schedules in CWA (Inflight Crew Web Access)....it looks identical to what's in SWAlife on the web and functions just as if you were on a PC. Are you aware of another app in the Market that I might be missing that allows that? Thanks for your help!
Questions or Problems Should Not Be Posted in the Development Forum
Please Post in the Correct Forums
Moving to General
I know this is an old problem, but try xScope browser in the market. I needed to be able to open more than one popup window and the website I was trying and failing to access with about 10 other browsers would not work until I tried this one.
I have the same problem. Your tip sounds good. I will give this browser a try. I hope that the search has an end.
This browser works for my sites where I need more than one pop-up. Thanks for the valuable information.

Security News Daily: First Known Android Drive-By Download Found

http://www.securitynewsdaily.com/1805-android-driveby-download.html
I'm wondering if you have your browser's user agent set to desktop or ios, does it still do the redirect or does it just see the browser has something else?
boborone said:
I'm wondering if you have your browser's user agent set to desktop or ios, does it still do the redirect or does it just see the browser has something else?
Click to expand...
Click to collapse
Though I don't know exactly how these exploits work, your question seems valid to me. Hopefully mobile security developers are testing this. I would think that a user agent value of iOS or Android would be most likely to invoke such an exploit when it is aimed at mobile devices.
On my phone, I rarely use a web browser. When I do, it is Firefox with the Phony extension (which lets me change the user agent), and I mostly browse via bookmarks.
Would I have the vigilance and stamina to change to a presumed safer user agent (e.g., Firefox desktop) when I browse to each domain I don't trust? If I could automate the change, yes. Otherwise, maybe not.
Looks like its a page sending an apk to be downloaded. Some browsers like the system on in GB will auto start downloads, Dolphin HD and possibly others will display a prompt before downloading unless these sites have found some exploit.
In order to be infected the user would not only have to download the apk, but also accept the installation notice. A malicious apk file that isn't installed doesn't pose any threat. Its safer than websites that try to send executables to a Windows machine, because those files will post a threat before being installed.
All OSes have their weaknesses, iOS jailbreaks through the browser showed some pretty serious security flaws being exploited.
Major weekness, no, not all. But one that could potentially harm the tech illiterate? Yes. Not all people understand the consequences of clicking links in email. Those who don't would be the ones who this would infect.
"oh something just popped up on my phone.......
it says "better browsing".........*clicks ok
ummm, "Do you wish to install "A Faster Internet".......*clicks ok"
Infected.
spunker88 said:
Looks like its a page sending an apk to be downloaded. Some browsers like the system on in GB will auto start downloads, Dolphin HD and possibly others will display a prompt before downloading unless these sites have found some exploit.
In order to be infected the user would not only have to download the apk, but also accept the installation notice. A malicious apk file that isn't installed doesn't pose any threat. Its safer than websites that try to send executables to a Windows machine, because those files will post a threat before being installed.
All OSes have their weaknesses, iOS jailbreaks through the browser showed some pretty serious security flaws being exploited.
Click to expand...
Click to collapse

[Q] Need an android substitute for IE

My job requires company access to an intranet site that requires IE for access. Their solution for mobile needs is to haul an IE-equipped laptop around, but I obviously would rather connect in the field with my tablet via VPN.
All the solutions I've found via searching online have ranged from "you can't do that" to a virtual desktop that's way out of reach for in individual user. And due to the way the sites are built, only IE will work. This is not about choosing a different browser.
So does anybody know if any work is being done for those of us needing to use/emulate IE on our tablets? I know from my google searches that this is a common problem, so hopefully somebody is working on it.
I think that the only thing you can do is to have a laptop or a desktop at home with IE and access it through something like Splashtop.
You can also enable Wake-on-Lan on that PC so that it can stay off and it turns on only when you need it.
Check out Opera. I'm not sure about the Android version, but the desktop versions allow you to change the user agent (a string included with every page request that includes the OS you are using, browser, browser version, rendering engine, etc.) so that it looks to other websites like you're using IE. I'm pretty sure Dolphin also has this, and I know that there is an extension for Firefox that can do this, too. Whether or not it will work in your case, I can't guarantee, but it's worth a shot.
Solution!
The "desktop user agent" in the Dolphin browser app did the trick. Thanks to those who replied with suggestions.

Always Force Desktop Website Version

Is there a way to go past the website's UA checks and always load their desktop versions instead of mobile? Asking because I already set in the preferences of all my phone browsers to always load the full desktop version and still, many websites somehow know I'm using a mobile device and force the mobile version.
Anyone found solution for Dolphin or Boat browsers? I've read about "about:debug" and "about:useragent" showing extra UA menu elements which in my case does nothing (android 6). I was also unable to find an user agent switching app that could always force Desktop parameters to the websites.
Even if there's no immefiate solution, I would like to know the principle websites choose which version to load irrespective to browser settings. Is it network/data/service provider settings, or specific browser/resolution signature? Thanks a lot for any ideas.
Menergy said:
Is there a way to go past the website's UA checks and always load their desktop versions instead of mobile? Asking because I already set in the preferences of all my phone browsers to always load the full desktop version and still, many websites somehow know I'm using a mobile device and force the mobile version.
Anyone found solution for Dolphin or Boat browsers? I've read about "about:debug" and "about:useragent" showing extra UA menu elements which in my case does nothing (android 6). I was also unable to find an user agent switching app that could always force Desktop parameters to the websites.
Even if there's no immefiate solution, I would like to know the principle websites choose which version to load irrespective to browser settings. Is it network/data/service provider settings, or specific browser/resolution signature? Thanks a lot for any ideas.
Click to expand...
Click to collapse
If the problem is website's UA check, often you can choose an AdWay or something similar, on my phone i'm surprised to see as "auto check" some pop up, check and box.
But for what never stop working, that's need update every day...
There isn't much you can do in this case.
Sometimes in some browsers you've an option with whitelist or other but I do believe they can be related to the mobile display or desktop of a particular site.
Maybe there is an add-on xposed or plugin that I don't know
My problem is that some websites force the mobile version no matter what, as well as lack on services that I need in there, and you couldn't circumvent that in any way.
Yesterday I had to verify an email address and tried with all the browsers I have on my phone (like 5 different). They were all set to display the desktop version and all were forced into the mobile. But on the mobile you couldn't verify the link, probably on purpose (security if on mobile device), and I would not have access to laptop/desktop browser by the evening. The same is with many other features/missing services on forced mobile websites so I want to find a way to have full functionality when on the go.
Does AdWay have options for influencing data the browser notifies to the websites? Anything similar to Mozilla-code based Random Agent Spoofer browser add-on where you can basically force the browser to inject any incorrect data and prevent other data leaking while browsing? Any special cookie mechanisms inherent to mobile browsers only?
Alternatively, can I access browser settings with something like about:config/debug or else? Dolphin, Boat, others? I am sure the browser notifies the correct desktop user agent, there's something else, probably very simple, that tells websites the connection is from a portable device...
Menergy said:
My problem is that some websites force the mobile version no matter what, as well as lack on services that I need in there, and you couldn't circumvent that in any way.
Yesterday I had to verify an email address and tried with all the browsers I have on my phone (like 5 different). They were all set to display the desktop version and all were forced into the mobile. But on the mobile you couldn't verify the link, probably on purpose (security if on mobile device), and I would not have access to laptop/desktop browser by the evening. The same is with many other features/missing services on forced mobile websites so I want to find a way to have full functionality when on the go.
Does AdWay have options for influencing data the browser notifies to the websites? Anything similar to Mozilla-code based Random Agent Spoofer browser add-on where you can basically force the browser to inject any incorrect data and prevent other data leaking while browsing? Any special cookie mechanisms inherent to mobile browsers only?
Alternatively, can I access browser settings with something like about:config/debug or else? Dolphin, Boat, others? I am sure the browser notifies the correct desktop user agent, there's something else, probably very simple, that tells websites the connection is from a portable device...
Click to expand...
Click to collapse
I use "user agent switcher" for chrome and it always works. It requires root though.
Can you provide an example of a website that refuses to show the desktop version?
And additionally, your build.prop contains your device's information. The browser might be transmitting that information to the website.
Thank you, the build.prop info was very helpful. I am not rooted yet as I've got my new phone just less than a month ago so still exploring, but can't really find the file, even among the hidden files on the internal memory. I will explore more and see how it goes.
I am in the UK so for example one of the websites that always loads the limited mobile instead of desktop version is the one of my service provider, EE, ee. co. uk (apologies for the intervals, I'm otherwise not allowed to post it). This mobile version is too basic and 60% of what you could do on a desktop version is cut. I've been on Three Mobile and sometimes I could get their full website working, sometimes not. Other websites are let's say bbc. co. uk and other media/news/bank websites that know, no matter browser settings, you are accessing them from a portable device.
Unfortunately I do not trust Google and any of their products so avoid voluntarily and (un)intentionally handing any personal data over to them. I would have used Mozilla for Android if it was close to the functionality Boat and Dolphin browsers provide. I even contacted the Dolphin team having previously assisted them but have got no feedback whatsoever. There must be a way for editing these unusual browser settings, but as pointed out above, I suspect it has something to do will submitting device ID info from within system folders. Thus probably only browser developers could tell us how the problem could be circumvented (and hopefully at least for now, with no root).
Or the developers of addons such as the Random Agent Spoofer or the user agent switchers.
Menergy said:
Thank you, the build.prop info was very helpful. I am not rooted yet as I've got my new phone just less than a month ago so still exploring, but can't really find the file, even among the hidden files on the internal memory. I will explore more and see how it goes.
I am in the UK so for example one of the websites that always loads the limited mobile instead of desktop version is the one of my service provider, EE, ee. co. uk (apologies for the intervals, I'm otherwise not allowed to post it). This mobile version is too basic and 60% of what you could do on a desktop version is cut. I've been on Three Mobile and sometimes I could get their full website working, sometimes not. Other websites are let's say bbc. co. uk and other media/news/bank websites that know, no matter browser settings, you are accessing them from a portable device.
Unfortunately I do not trust Google and any of their products so avoid voluntarily and (un)intentionally handing any personal data over to them. I would have used Mozilla for Android if it was close to the functionality Boat and Dolphin browsers provide. I even contacted the Dolphin team having previously assisted them but have got no feedback whatsoever. There must be a way for editing these unusual browser settings, but as pointed out above, I suspect it has something to do will submitting device ID info from within system folders. Thus probably only browser developers could tell us how the problem could be circumvented (and hopefully at least for now, with no root).
Or the developers of addons such as the Random Agent Spoofer or the user agent switchers.
Click to expand...
Click to collapse
The build.prop is a text file which should be located in system/ folder. And you usually can't view the contents of that folder without root, so that's why you haven't been able to find it.
I visited ee.co.uk using chrome, and I was able to switch between the mobile and desktop version of the site without any issues, even without using the UA changing app. All I did was select "request desktop site" from the side menu.
I tried using CM's stock browser though, and just like you experienced, the same website refused to load in desktop mode. I even went as far as changing the UA in its settings menu and even that didn't work.
So all that you wrote in the last two paragraphs have been confirmed.
Right now, it's either chrome or root until the devs fix/properly implement their UA changing feature.
I was testing other browsers the whole morning here and finally reluctantly tried Firefox. Somehow its Android version never impressed me or was too buggy for me when tested before. Probably because just before going for it I tried Pale Moon and have seen that I can readily edit just about everything via about:config. The Pale Moon's UI settings menu was however completely missing (probably a bug), along with no other controls, so I had to skip it.
So I am glad to report that using Firefox's "Request desktop website" option I finally was able to load desktop versions of websites that were forcing me to always have their mobile one instead. This means that Firefix for now becomes my main browser. As suggested by you, I tried first with Chrome but with no success (using its internal user agent options). There were a few Chrome user agent switchers in the market but although some of them did not explicitly require root, upon starting them they did so I had to uninstall them.
My question yet remains, what exactly tells websites not to load full version, even if browser's user agent reports the correct values. I will leave this to me as I go deeper into this. Glad to have got what I wanted
Thanks a lot for all your help.
Just to add for all having my problem and using Firefox for Android.
By default Firefox will always load the mobile website version and every time you will need to tick "Request desktop site" if you dislike it. As I do, there is an addon called "Desktop by Default" that will always keep the tick on for you. You may instead try creating a new string called "general.useragent.override" adding a desktop OS signature but it won't work (tested by me) for exactly the same websites I had issues with above, so do use the addon instead. It will however work for all other websites that don't have issues with Desktop mode on other browsers.
There is another string that I disabled also called general.useragent.site_specific_overrides.
Tweaking with the Chrome for Android settings seems to require root so Firefox in my case is a God bless. I hope this is helpful to all others with my issue...

Question How to disable Built in PDF viewer

Hi,
On my S22 Ultra when I am using either Chrome or Opera and click on a web link that contains a pdf the phone will:
Automatically open the PDF in the browser
Proceed to lag for 30 seconds
Tell me the app (either Chrome or Opera) is not responding
Fix itself and go on as if nothing happened
My question is:
How do I restore the question prompt "Would like to: Download, Open the file"
I would like to download the files and look at them with the Adobe Acrobat Reader
This is horrible. I specifically purchased this phone for work and I often need to look up equipment specifications from their respective manufacturer's websites.
So every time now I need to look at a PDF its a whole ordeal.
Please help!
Thanks
Have you installed Adobe reader? Install it if not that will allow you to chose actions
Otherwise see
How to change default apps in Android
Does your smartphone keep using the wrong app to open files and execute procedures? Learn how to change your default apps in this guide.
www.androidauthority.com
raul6 said:
Have you installed Adobe reader? Install it if not that will allow you to chose actions
Otherwise see
How to change default apps in Android
Does your smartphone keep using the wrong app to open files and execute procedures? Learn how to change your default apps in this guide.
www.androidauthority.com
Click to expand...
Click to collapse
Thanks for the reply!
I have Adobe installed and have Installed / Uninstalled it a few times to try and maybe trigger a change in the behavior, to no avail.
Unfortunately default apps doesn't seem to be the issue I am having.
I will try to describe the problem more clearly:
Lets say I go to a website that sells electronic equipment.
I find the specific equipment I am interested in.
Click on "PDF Specifications sheet"
My Opera or Chrome browsers proceed to immediately open the PDF file in a tab.
That renders the browser unusable for about 30 seconds while its trying to load the PDF basically bricking my phone because I have to wait for the PDF to load to be able to navigate to "Download PDF" so I can later view it in my adobe app.
(don't know what the behavior is with the samsung browser since I am not interested in using it)
I understand the issue. The article covers what to do, look towards the 2nd part of the article
raul6 said:
I understand the issue. The article covers what to do, look towards the 2nd part of the article
Click to expand...
Click to collapse
Apologize, was on a work call so I forgot to mention I followed the default app steps a few times.
I reset all default app settings.
So it doesn't seem to be a default app issue.
The android system does not seem to notice the opening of the PDF file inside the browsers at all.
That leads me to believe this is a browser problem, so I tried finding settings in the browsers themselves, but could not.
I posted a "How to disable the built in PDF view in Opera" question in the Opera Android forums, but nobody has answered for the last 2 days.
This is very frustrating since I believe I can't be the only person with this issue, but I can't find a single trace of info on it on the internet.
Thanks!
I only use Chrome and never had this issue, it always asks what i want to open a PDF with.
Maybe cause I never checked the "use this as default" thing since I use a couple of different methods depending.
Try with Better Open With app to control the default action(s)

Categories

Resources