critical flaw in firefox

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • SmokeyTheBear
    ►SouthOfHeaven
    • Jun 2004
    • 28609

    #1

    critical flaw in firefox

    http://story.news.yahoo.com/s/pcworld/120756

    Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.



    The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.

    A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

    The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

    In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.

    Two Vulnerabilities Found
    The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

    The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

    Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.

    "We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.
    hatisblack at yahoo.com
  • SmokeyTheBear
    ►SouthOfHeaven
    • Jun 2004
    • 28609

    #2
    heres a test to see if your vulnerable
    here
    hatisblack at yahoo.com

    Comment

    • MrJackMeHoff
      Confirmed User
      • Mar 2004
      • 4569

      #3
      the exploit was already fixed long ago

      Comment

      • SmokeyTheBear
        ►SouthOfHeaven
        • Jun 2004
        • 28609

        #4
        Originally posted by MrJackMeHoff
        the exploit was already fixed long ago
        they patched part of it, and it was only a few days ago
        hatisblack at yahoo.com

        Comment

        • GatorB
          The Demon & 12clicks
          • Oct 2001
          • 18208

          #5
          Originally posted by MrJackMeHoff
          the exploit was already fixed long ago
          Yeah today at the earliest if it has been. Nice try. First reported a week ago, but not to public. So your computer has been vunerable for a week.

          Comment

          • pornguy
            Too lazy to set a custom title
            • Mar 2003
            • 62910

            #6
            Thanks for the info smokey.
            PornGuy skype me pornguy_epic

            AmateurDough The Hottes Shemales online!
            TChicks.com | Angeles Cid | Mariana Cordoba | MAILERS WELCOME!

            Comment

            • Furious_Female
              Confirmed User
              • Oct 2002
              • 8187

              #7
              It was only a matter of time... at the people who think Firefox is God's gift to the internet.

              IE 4 lyfe
              Skype: j3nn.com
              ICQ 160370494

              My current favorite high-converting sponsor: CrakRevenue

              Comment

              • Spunky
                I need a beer
                • Jun 2002
                • 133978

                #8
                I gave up on it after it took control of too many things and I couldn't change it back

                Comment

                • reynold
                  Too lazy to set a custom title
                  • Oct 2002
                  • 51271

                  #9
                  thanks for the info smokey bear!

                  Comment

                  Working...