Even if you don't use a firewall you might use a non-filtering proxy. If so you might be able to filter just "/favicon.ico" from every web site.
I discovered a Zero-Day in the wild this morning. It exploits your browser, quite possibly your entire system through the favicon.ico that is placed at the root directory of many web sites:
It is already public knowledge that neither Chrome nor Firefox place size file size on favicons
, thus a very large one - even a standards-compliant graphic document - could crash your browser, possibly crash your computer by running it completely out of virtual memory (ie. swap space). Large favicons exploit dialup modem users via the Denial Of Service that results from downloading a very large file without the end-users knowledge or permission.
I am already developing a Firefox and Chrome Add-Ons as well as Safari and Internet Explorer Plug-Ins that will block all favicons in their initial releases; later versions will user a separate process - a sandbox - to validate the document format of each favicon.ico, render its pixels in a memory buffer then display the now-safe image in the browser's address bar.
My Add-Ons and Plug-Ins will warn the user of invalid documents and display Message Boxes - Alerts - if the favicon.ico document actually does contain a Virus, Trojan Horse or Worm.
If you speculate that you already know what I am referring to please don't discuss it in public until Apple, Microsoft, Google and Mozilla have released patches that verifiably fix this. If you want to discuss it in private either mail me at email@example.com or post to the Mozilla bug report I shall submit this evening then link in a reply to this here article.
Yes there are many other browser vendors but Firefox, Safari, Chrome and Internet Explorer cover the majority of the end-users who would be otherwise unable to protect themselves by configuring their own firewalls.
I will reply with the relevant CERT Incident Number; eventually a CERT Advisory Number will arrive too.
If you think you can write better Add-Ons or Plug-Ins than I can or if you can write them for other browsers than I have experience with, I invite you to Do Yer Worst
Have A Nice Day.
(Soggy Wizards is a new domain and so its web site is still parked. Its web server will be active by tomorrow afternoon, Tuesday, August 18 2015.)
While I will publish my Add-Ons and Plug-Ins under the Affero General Public License version 3 and will supply ready-to-use Add-Ons and Plug-Ins free of charge, you are welcome to facilitate their development with a modest monetary contribution. Please mail a check or money order payable to "Solving the Software Problem" for what you can reasonably part with to:
Michael David Crawford
650 NW Irving St
Portland OR 97209
I do not yet have a BitCoin nor Litecoin wallet but I will set those up then supply them in a reply.
I don't use PayPal; if you would like to contribute via PayPal, donate to your choice of the Free Software Foundation, Creative Commons, Electronic Privacy Information Center, the American Civil Liberties Union or the Leftist organization of your choice.
Have A Nice Day.
If I understand correctly that's $99.00 for an unlimited number of Plug-Ins but for just one year.
Safari Plug-Ins must be digitally signed by Apple. That's mostly a good thing but until now I have been reluctant to pay Apple anything at all, for many reasons unrelated to my present security report.
I expect I can implement my Plug-In for older versions of Safari. Apple will release a Security Update if, in its own judgement, Safari exhibits this problem. I don't know yet but I will test it myself.
However Apple's Software Quality Assurance will require some time to validate any such fix. I was once a Senior Engineer at Apple, they have a process for new products and new revisions of old products which is quite good but not as fast as what the independent developer can pull off.
If I find that I must pay the Safari Developer Program fee for you to install my Plug-In, and in my own opinion you should install it, then I will pay the fee. But I will start my Safari work on Mac OS X Tiger 10.4.11 PowerPC and Safari 3.1.1.
If Apple has any objection to my use of the Affero GPLv3 I will post its source code at http://soggywizards.com/code/source/security/browser/safari/ but will not release an executable build that end-users can install directly.
$ curl http://soggywizards.com/favicon.ico
$ wget http://soggywizards.com/favicon.ico
Resolving soggywizards.com... 220.127.116.11
Connecting to soggywizards.com|18.104.22.168|:80... connected.
HTTP request sent, awaiting response... 404 Not Found
07:24:05 ERROR 404: Not Found.
The parking website - not just a single page - provided by my domain registrar does not include a favicon, but it does have a custom 404 Error Document that I expect uses Apache Server-Side Includes to produce "No favicon" if one tries to load it.
I will 200 OK Response Code payload data to consist of standards-compliant graphic documents that are 16 by 16 pixels or - maybe I am as yet uncertain - 16x16 or smaller, but NOT larger.