Security.html 7.7 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158
  1. <!DOCTYPE html>
  2. <html dir="ltr">
  3. <head>
  4. <meta http-equiv="content-type" content="text/html;charset=UTF-8" />
  5. <title>Help/Security - XOWA</title>
  6. <link rel="shortcut icon" href="https://gnosygnu.github.io/xowa/xowa_logo.png" />
  7. <link rel="stylesheet" href="https://gnosygnu.github.io/xowa/xowa_common.css" type="text/css">
  8. </head>
  9. <body class="mediawiki ltr sitedir-ltr ns-0 ns-subject skin-vector action-submit vector-animateLayout" spellcheck="false">
  10. <div id="mw-page-base" class="noprint"></div>
  11. <div id="mw-head-base" class="noprint"></div>
  12. <div id="content" class="mw-body">
  13. <h1 id="firstHeading" class="firstHeading"><span>Help/Security</span></h1>
  14. <div id="bodyContent" class="mw-body-content">
  15. <div id="siteSub">From XOWA: the free, open-source, offline wiki application</div>
  16. <div id="contentSub"></div>
  17. <div id="mw-content-text" lang="en" dir="ltr" class="mw-content-ltr">
  18. <h2>
  19. <span class="mw-headline" id="Java">Java</span>
  20. </h2>
  21. <p>
  22. Java vulnerabilities (and the resulting patches) are often in the news. However, most of these vulnerabilities affect machines with the Java browser plugin. <b>A machine can have Java installed and be largely unaffected by these vulnerabilities -- so long as the Java browser plugin is disabled</b>. If you want to check that the Java browser plugin is disabled, you can review the instructions at this link: <a href="http://www.java.com/en/download/help/disable_browser.xml" rel="nofollow" class="external free">http://www.java.com/en/download/help/disable_browser.xml</a>
  23. </p>
  24. <p>
  25. For Firefox, these are the steps I used to verify that the Java browser plugin is disabled.
  26. </p>
  27. <ul>
  28. <li>
  29. From the Menu Bar, do "Tools" -&gt; "Add-ons"
  30. </li>
  31. <li>
  32. The next page will list "Add-ons". For my machine, "Java(TM) Platform SE 6 U32 6.0.320.5" was listed. It was marked "(disabled)"
  33. </li>
  34. </ul>
  35. <dl>
  36. <dd>
  37. Note that recent builds of Firefox will disable the Java browser plugin by default.
  38. </dd>
  39. </dl>
  40. <p>
  41. Finally, although XOWA uses Java and is a browser-based app, it does not use the Java browser plugin in any manner.
  42. </p>
  43. <h2>
  44. <span class="mw-headline" id="Javascript">Javascript</span>
  45. </h2>
  46. <p>
  47. XOWA uses Javascript throughout the app for MathJax, sortable tables, reference tool-tips, and many other functions. Javascript is a versatile language for working with web pages, but that same versatility also makes it a vector for attack. There is always a possibility that malicious Javascript could be added to a wiki page, and that this malicious Javascript could make its way to your machine.
  48. </p>
  49. <p>
  50. XOWA tries to control this situation in the following ways:
  51. </p>
  52. <ul>
  53. <li>
  54. XOWA uses the same whitelisting approach that MediaWiki uses to block Javascript from being executed on wiki pages.
  55. </li>
  56. <li>
  57. XOWA filters out javascript again just before rendering pages
  58. </li>
  59. <li>
  60. XOWA has a flag to disable javascript entirely. Note that this will reduce much of the functionality of XOWA. It can still be used to read wiki pages, but the functions listed above will not work.
  61. </li>
  62. </ul>
  63. <p>
  64. In order to disable Javascript, you can uncheck the Javascript option at <a href="http://xowa.org/wiki/home/page/Options/Security.html" id="xolnki_2" title="Options/Security" class="xowa-visited">Options/Security</a>
  65. </p>
  66. </div>
  67. </div>
  68. </div>
  69. <div id="mw-head" class="noprint">
  70. <div id="left-navigation">
  71. <div id="p-namespaces" class="vectorTabs">
  72. <h3>Namespaces</h3>
  73. <ul>
  74. <li id="ca-nstab-main" class="selected"><span><a id="ca-nstab-main-href" href="index.html">Page</a></span></li>
  75. </ul>
  76. </div>
  77. </div>
  78. </div>
  79. <div id='mw-panel' class='noprint'>
  80. <div id='p-logo'>
  81. <a style="background-image: url(https://gnosygnu.github.io/xowa/xowa_logo.png);" href="http://xowa.org/" title="Visit the main page"></a>
  82. </div>
  83. <div class="portal" id='xowa-portal-home'>
  84. <h3>XOWA</h3>
  85. <div class="body">
  86. <ul>
  87. <li><a href="http://xowa.org/index.html" title='Visit the main page'>Main page</a></li>
  88. <li><a href="http://xowa.org/screenshots.html" title='See screenshots of XOWA'>Screenshots</a></li>
  89. <li><a href="http://xowa.org/wiki/home/page/Help/Download_XOWA.html" title='Download the XOWA application'>Download XOWA</a></li>
  90. <li><a href="http://xowa.org/wiki/home/page/Dashboard/Image_databases.html" title='Download offline wikis and image databases'>Download wikis</a></li>
  91. </ul>
  92. </div>
  93. </div>
  94. <div class="portal" id='xowa-portal-stargin'>
  95. <h3>Getting started</h3>
  96. <div class="body">
  97. <ul>
  98. <li><a href="http://xowa.org/wiki/home/page/App/Setup/System_requirements.html" title='Get XOWA&apos;s system requirements'>Requirements</a></li>
  99. <li><a href="http://xowa.org/wiki/home/page/App/Setup/Installation.html" title='Get instructions for installing XOWA'>Installation</a></li>
  100. <li><a href="http://xowa.org/wiki/home/page/App/Import/Simple_Wikipedia.html" title='Learn how to set up Simple Wikipedia'>Simple Wikipedia</a></li>
  101. <li><a href="http://xowa.org/wiki/home/page/App/Import/English_Wikipedia.html" title='Learn how to set up English Wikipedia'>English Wikipedia</a></li>
  102. <li><a href="http://xowa.org/wiki/home/page/App/Import/Other_wikis.html" title='Learn how to set up other Wikipedias'>Other Wikipedias</a></li>
  103. </ul>
  104. </div>
  105. </div>
  106. <div class="portal" id='xowa-portal-help'>
  107. <h3>Help</h3>
  108. <div class="body">
  109. <ul>
  110. <li><a href="http://xowa.org/wiki/home/page/Help/About.html" title='Get more information about XOWA'>About</a></li>
  111. <li><a href="http://xowa.org/wiki/home/page/Help/Contents.html" title='View a list of help topics'>Contents</a></li>
  112. <li><a href="http://xowa.org/wiki/home/page/Help/Media.html" title='Read what others have written about XOWA'>Media</a></li>
  113. <li><a href="http://xowa.org/wiki/home/page/Help/Feedback.html" title='Questions? Comments? Leave feedback for XOWA'>Feedback</a></li>
  114. </ul>
  115. </div>
  116. </div>
  117. <div class="portal" id='xowa-portal-blog'>
  118. <h3>Blog</h3>
  119. <div class="body">
  120. <ul>
  121. <li><a href="http://xowa.org/wiki/home/page/Blog.html" title='Follow XOWA''s development process'>Current</a></li>
  122. </ul>
  123. </div>
  124. </div>
  125. <div class="portal" id='xowa-portal-links'>
  126. <h3>Links</h3>
  127. <div class="body">
  128. <ul>
  129. <li><a href="http://dumps.wikimedia.org/backup-index.html" title="Get wiki datababase dumps directly from Wikimedia">Wikimedia dumps</a></li>
  130. <li><a href="https://archive.org/search.php?query=xowa" title="Search archive.org for XOWA files">XOWA @ archive.org</a></li>
  131. <li><a href="http://en.wikipedia.org" title="Visit Wikipedia (and compare to XOWA!)">English Wikipedia</a></li>
  132. </ul>
  133. </div>
  134. </div>
  135. <div class="portal" id='xowa-portal-donate'>
  136. <h3>Donate</h3>
  137. <div class="body">
  138. <ul>
  139. <li><a href="https://archive.org/donate/index.php" title="Support archive.org!">archive.org</a></li><!-- listed first due to recent fire damages: http://blog.archive.org/2013/11/06/scanning-center-fire-please-help-rebuild/ -->
  140. <li><a href="https://donate.wikimedia.org/wiki/Special:FundraiserRedirector" title="Support Wikipedia!">Wikipedia</a></li>
  141. <!-- <li><a href="" title="Support XOWA! (but only after you've supported archive.org and Wikipedia)">XOWA</a></li> -->
  142. </ul>
  143. </div>
  144. </div>
  145. </div>
  146. </body>
  147. </html>