Social

How to disable JavaScript in PDF documents in Firefox

How to disable JavaScript in PDF documents in Firefox

The security and feature update for the organization’s Firefox web browser introduced a major change in the native PDF viewer of the browser. Up until now, JavaScript was ignored by Firefox when PDF documents were viewed in the browser. The execution displayed the JavaScript document in the browser but ignored any JavaScript code that it contained.

Mozilla enabled the execution of JavaScript in PDF documents in Firefox 88; this means that JavaScript code will be executed if it is present in a PDF file that is viewed in Firefox. There are legitimate reasons for supporting JavaScript in PDF documents, for instance to verify the input in form fields or to make changes to a document based on data when it is opened or when certain events happen.

Unfortunately, JavaScript in PDFs may also be used to execute malicious code. In other words: JavaScript is a security risk when it is executed in PDF documents. Most Firefox users may not need the feature, and it is a good idea to disable the execution of JavaScript in PDF documents in the browser to protect the system against JavaScript-based attacks.

Disable JavaScript execution in PDF documents

Firefox users may disable the execution of JavaScript by the browser’s native PDF viewer in the following way. Note that there is no option to turn it off in the main settings of the browser.

  1. Load about:config in the web browser’s address bar.
  2. Confirm that you will be careful to proceed.
  3. Use the search at the top to find pdfjs.enableScripting.
  4. Set the preference to FALSE with a click on the toggle button at the end of the line.
    1. A status of FALSE disables JavaScript execution in PDF files.
    2. A status of TRUE enables the execution of JavaScript in PDF documents (default)

Firefox will ignore JavaScript in PDF documents if the preference is set to FALSE.

Testing

You can test the effect by loading PDF documents that include scripting from a site like PDF Scripting. Just download the sample PDF documents and check them in the native PDF viewer of Firefox to see if the execution is blocked.

[mai mult...]

All Windows 10 upgrade safeguards have been lifted

All Windows 10 upgrade safeguards have been lifted

Microsoft resolved the last long-standing upgrade issues in Windows 10 version 2004 and 20H2 this week. The company uses upgrade safeguards to block updates to newer versions of its Windows 10 and Windows Server operating systems to prevent issues during or after the installation of the updates.

Downside to the safeguards is that some devices are not offered the upgrade to a new version of Windows 10. In this particular case, it meant that affected devices running Windows 10 version 1909 could not be upgraded to newer versions of Windows 10 using Windows Update.

Windows 10 version 1909 consumer editions — Home, Pro, Education and Workstations — reach end of life in May 2021. Microsoft plans to release a last batch of security patches for Home versions of the operating system on May 11, 2021, the May 2021 Patch Tuesday before support ends.

Microsoft lifted the last safeguards on May 7, 2021 which prevented the upgrade to newer Windows 10 versions using Windows Update for devices with certain Conexant audio drivers and Conexant ISST audio drivers.

The safeguard hold with safeguard IDs 25702617, 25702660, 25702662, and 25702673 has been removed for all devices as of May 7, 2021, including devices with affected drivers. If updated drivers are not available for your device and you are offered Windows 10, version 2004 or Windows 10, version 20H2, a small number of devices might roll back to the previous version of Windows 10 when attempting to update. If this occurs, you should attempt to update to Windows 10, version 2004 or Windows 10, version 20H2 again.

The issues were opened a year ago in May 2021. Microsoft published a workaround but the issue was not fixed until this month. Some devices may be rolled back according to the resolution and Microsoft asks administrators to run the update again when that happens.

Windows 10 administrators may select Start > Settings > Update & Security to find out if new feature updates are available. Other updating options include using Microsoft’s Windows Media Creation Tool to upgrade a PC or create installation media.

The two upgrade safeguards were the last two listed by Microsoft on the known issues pages of Windows 10 version 2004 and 20H2. Affected devices should receive update options within 48 hours of the lifting of the safeguard.

[mai mult...]

4GHz CPU Battle: Ryzen 3900X vs. 3700X vs. Core i9-9900K

Intel Core i9-9900K este procesorul ideal atât pentru cei care își doresc un plus de putere și timpi foarte mici de așteptare atunci când se joacă, cât și pentru cei pasionați de tot ce înseamnă editare grafică, randare 2D și 3D sau pentru realizări și actualizări ale unor baze de date foarte stufoase.

In cazul in care se doreste un processor de la AMD, se recomanda un AMD ryzen 7  3700 , un processor cu un raport calitate pret foarte bun.Cu un consum de doar 65w.

[mai mult...]

Atacurile cibernetice. Sau cum a ajutat pandemia hackerii

De la atacuri de tip ransomware, care îţi blochează sistemele până când plăteşti recompensa, la atacuri în lanţ care ţintesc întâi companiile mici, şi până la ameninţări de tip „sextorsion”, pericolele din mediul cibernetic s-au înmulţit în ultimii ani şi au căpătat noi dimensiuni în 2020. Odată cu trecerea la şcoala online, munca online, viaţa online, s-au deschis mai multe „ferestre” prin care atacatorii pot intra în „casa” noastră şi în compania noastră.

Cea mai sigură ţintă a unui atac cibernetic este angajatul din companie, din perspectiva unui hacker. Prin ţintirea unui singur angajat, hackerul poate introduce cu uşurinţă sisteme maliţioase care duc la pierderi de date sau la atacuri mai grave.

[mai mult...]

IOS 14.5 si setari confidentialitate

iOS 14 aduce câteva funcții noi, printre care și “Apple’s App Tracking Transparency (ATT)” prin care utilizatorii au opțiunea de a-și da sau nu acordul pentru ca datele lor sa fie urmărite de catre site-urile care fac cross-website tracking. Exact cum procedează Facebook prin Pixel. Prin ATT, Apple include un nou format prin care informează utilizatorii despre datele ce sunt urmărite prin aplicație, înainte ca acestea să fie instalată, iar ulterior oferă opțiunea de a permite sau nu urmărirea acestor date.

Pentru a oferi sau refuza accesul aplicatiilor la anumite date procedam astfel

  • Intram in configurari

  • Dupa ce se deschide meniul selectam intimitate

  • Alegem Urmarire si activam “Permitere solicitari urmarire”

[mai mult...]

How to Connect Google Home to Sonos Speakers

How to Set up Your Sonos Speaker or Device
Before linking to Google Assistant or Google Home, you need to make sure your Sonos device is up and running with the latest update. You’ll also need an internet connection with a Wi-Fi router.

Download the Sonos app to a phone, tablet, or computer. The Sonos app is available from Google Play or Amazon (Android) and from Apple App Store (iOS).

[mai mult...]