Osprey: Browser Protection

Discussion in 'other anti-malware software' started by Sampei Nihira, Apr 17, 2025.

  1. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    Osprey is a browser extension that protects you from malicious websites:

    https://github.com/Foulest/Osprey

    currently installable in Chrome/Edge but will soon be available in the Mozilla Store.
    The developer Foulest is very helpful in solving any problems.
     
  2. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,590
    Thank you. Just installed it on Edge. I do not see any "Settings" as mentioned to configure it. So currently running with the default protection.
     
  3. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    :thumb:;):)

    You can remove the Microsoft Smartscreen filter,even if the developer writes that it doesn't matter it seems illogical to me not to let Edge have this possible block.

    Another option is to delete notifications.
    Otherwise you will also be bombarded with notifications in the bottom right corner when in my opinion the extension's blocking page is already sufficient.

    Another aspect to consider:


    https://github.com/Foulest/Osprey/issues/5
     
  4. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,158
    Location:
    UK
    Have installed this just now in Vivaldi (version 1.0.9) to give it a run.
     
  5. warrior99

    warrior99 Registered Member

    Joined:
    Nov 21, 2014
    Posts:
    110
    Osprey, this looks inspiring in stalling it in Google Chrome
     
  6. Marcelo

    Marcelo Registered Member

    Joined:
    Oct 11, 2005
    Posts:
    288
    Location:
    Rio de Janeiro, Brazil.
    I noticed the Chrome extension is more up to date than the version in the Edge store. Is there any reason not to use it on Edge?
     
    Last edited: Apr 18, 2025 at 5:58 AM
  7. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,158
    Location:
    UK
  8. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    In addition to the link brought to attention by
    @stapp,
    @Vitali Ortzi

    whom I salute, did a 0-day test taken only from DNS.eu.

    I don't know if you noticed that in the 60 link test, Symantec seems to be the one blocking everything.
    But it is interesting to verify that disabled Symantec other protections intervene.

    I did a different test always with Phishtank + AA419 I checked which websites are blocked by my DNS protection.

    All but 2 links escaped.

    So I checked in Osprey which protection was blocking those links.

    I disabled all protections and left Quad9DNS + DNS0.eu on.


    P.S.

    I will include the fake links not blocked by my DNS protection and taken from Quad9 DNS (but other Osprey protections may block such links)

    Fake links (beware of entering sensitive data):

    https://www.regionalcfb.com/


    https://www.teencanceraid.com/

    _____________________________________________________________________


    Although the extension is very light,I assume that too many active protections can lead to a few too many FPs.
    So it is good to choose Osprey protections "cum grano salis".

    P.S1

    Now I will check how long the links escaped blocking when and especially if they will be blocked by my DNS.

    1) One link is already blocked by my DNS protection:

    https://ibb.co/20bkBsDr
     
    Last edited: Apr 18, 2025 at 2:50 PM
  9. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    I did some testing in URLhaus database with multiple exe links.

    Obviously those using Osprey with a few protections selected might see that the blocks are lower than with all protections on.

    But by using HTTPS always on and decreasing Insecure Cipher Suites you can get good direct protection.
    Obviously using an adblocker decreases the chance of going up against these malwares links.
     
  10. mantra

    mantra Registered Member

    Joined:
    Jan 25, 2005
    Posts:
    6,320
    nice extension
    sadly there isn't still avaible for firefox
    would like to watch a video
    how many malwares and malicious websites can stop ?
     
  11. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    3,097
    Location:
    the Netherlands
    Over at MalwareTips Forums, someone posted three "Osprey against ..." videos: [1], [2], [3].
    I haven't watched the videos. I like to read about things, not watch videos.
     
  12. Stupendous Man

    Stupendous Man Registered Member

    Joined:
    Aug 1, 2010
    Posts:
    3,097
    Location:
    the Netherlands
    @mantra,
    One more video review over at MalwareTips Forums.

    MalwareTips Forums now also has an Osprey thread incorporating the different information sources, including the reviews.
     
  13. bjm_

    bjm_ Registered Member

    Joined:
    May 22, 2009
    Posts:
    4,529
    Location:
    .
    where's the allowlist?
     
    Last edited: Apr 18, 2025 at 7:56 PM
  14. Foulest

    Foulest Registered Member

    Joined:
    Friday
    Posts:
    7
    Location:
    United States
  15. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,158
    Location:
    UK
  16. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    759
    Location:
    Earth
    Osprey 1.1.1 out on ChromeWebStore
     
  17. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,158
    Location:
    UK
  18. Brummelchen

    Brummelchen Registered Member

    Joined:
    Jan 3, 2009
    Posts:
    6,289
    its like results on VT, those scary native users. from my view: osprey is definitely an extension for experienced users.
     
  19. TairikuOkami

    TairikuOkami Registered Member

    Joined:
    Oct 10, 2005
    Posts:
    3,596
    Location:
    Flat Earth Matrix
    Blocked by NextDNS AI, other links mostly by NRDs.

    capture_04192025_103506.jpg
     
  20. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    759
    Location:
    Earth
  21. Rules

    Rules Registered Member

    Joined:
    Mar 3, 2009
    Posts:
    759
    Location:
    Earth
    Version 1.1.2 out few hours ago on ChromeWebStore
     
  22. Foulest

    Foulest Registered Member

    Joined:
    Friday
    Posts:
    7
    Location:
    United States
    It's definitely like VirusTotal, but for web-based lookups in real-time. I haven't come to a consensus on what providers to keep enabled for default use. It's hard to do false-positive testing.
     
  23. stapp

    stapp Global Moderator

    Joined:
    Jan 12, 2006
    Posts:
    27,158
    Location:
    UK
    The only way to become experienced with it is to install it first, look around it, and ask questions about it. People are kind and will help and then you become more experienced with it.
    On the right of the page @Foulest posted are more helpful hints.

    https://github.com/Foulest/Osprey/wiki/Modifying-the-Cache

    When you first install you see this (note there are 2 pages)
    Screenshot 2025-04-19 111337.jpg


    The next thing I tried was the test page
    Screenshot 2025-04-19 111605.jpg

    Nothing wrong with testing , looking and asking.
     
  24. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    Yes, that is the case today.
    It has been 5 1/2 hours and the first link has been blocked by NextDNS.
    There is no doubt about that.

    More hours certainly for NextDNS blocking of the second link but I went to sleep.
     
  25. Sampei Nihira

    Sampei Nihira Registered Member

    Joined:
    Apr 7, 2013
    Posts:
    3,800
    Location:
    Italy
    @Foulest

    Yes, it is difficult to come to a conclusion of which protections to enable by default.
    In my opinion it is great to check for fake links + phishing links and this has already been done by you,me and a few other users.

    I believe, however, that it is predominate to perform tests in links with malwares content.
    I recommend here:


    https://urlhaus.abuse.ch/browse.php?search=exe

    P.S.

    For example, the first active link is blocked (now) only by Bitdefender,GData,Emsisoft (my verification is with Symantec disabled at default).

    Also the second link (with different dns) the same.
    So I assume that these 3 protections would be left on by default for malwares.

    Probably other protections are more specific and perform better for phishing + fake sites.

    P.S.1

    Quad9 is great for fake sites blocked here:

    https://db.aa419.org/fakebankslist.php


    You did the phishing test yourself as well.:thumb:

     
    Last edited: Apr 19, 2025 at 11:09 AM
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.