We hope you enjoy your visit.

You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free.


Join our community!


If you're already a member please log in to your account to access all of our features:

Username:   Password:
Add Reply
  • Pages:
  • 1
  • 3
Critical Flaw In Firefox
Topic Started: May 9 2005, 10:49 PM (1,250 Views)
Daniel Talbot
Member Avatar
Semper Fidelis
[ *  *  *  *  *  * ]
Quote:
 
Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.

The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.

A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.

The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.



Well all i have to say is that sucks for the Firefox users for now
Offline Profile Quote Post Goto Top
 
Das
Member Avatar
Smells of rich mahogany
[ *  *  *  *  *  *  * ]
Ba it will be fixed soon enough. I fell safer then IE either way .. wait I am on ubuntu so any virus wouldn't do much :D I fell safe now :P
Offline Profile Quote Post Goto Top
 
Daniel Talbot
Member Avatar
Semper Fidelis
[ *  *  *  *  *  * ]
I just thought that the FF users would like to read that.
Offline Profile Quote Post Goto Top
 
doug05257-ZNS
http://www.gepforum.com
[ *  * ]
There goes FF's reputation for being virus and exploit free... ;)
Offline Profile Quote Post Goto Top
 
Seth
Member Avatar
I has a pony
[ *  *  *  *  *  *  *  *  * ]
If you haven't noticed, it's already fixed :P MozNet pushed the patch upstream about 5-6 hours after it was reported from what I can gather. u.m.o is no longer exploitable.

Compare that to an average bugfix time of 1-2 months for any IE bug.
Offline Profile Quote Post Goto Top
 
Das
Member Avatar
Smells of rich mahogany
[ *  *  *  *  *  *  * ]
Seth
May 9, 2005 08:17 PM
If you haven't noticed, it's already fixed :P MozNet pushed the patch upstream about 5-6 hours after it was reported from what I can gather. u.m.o is no longer exploitable.

Compare that to an average bugfix time of 1-2 months for any IE bug.

IE pwnt again
Offline Profile Quote Post Goto Top
 
Lothlómendil
Member Avatar
Spam Queen
[ *  *  *  *  *  *  * ]
Das Ein
May 9, 2005 11:21 PM
Seth
May 9, 2005 08:17 PM
If you haven't noticed, it's already fixed :P MozNet pushed the patch upstream about 5-6 hours after it was reported from what I can gather. u.m.o is no longer exploitable.

Compare that to an average bugfix time of 1-2 months for any IE bug.

IE pwnt again

:drool:

Even with the uber flaw that's already gone FX is safer. :rofl:
Offline Profile Quote Post Goto Top
 
Zero Resistance-ZNS
eÜil Zero lÖrd™
[ *  *  *  * ]
Seth
May 9, 2005 10:17 PM
If you haven't noticed, it's already fixed :P MozNet pushed the patch upstream about 5-6 hours after it was reported from what I can gather. u.m.o is no longer exploitable.

Compare that to an average bugfix time of 1-2 months for any IE bug.

Hoorah for Spyware Biasness!

that's bad.

that'll make viruses go to the biggest browser when IE falls.












Firefox. :ermm:
Offline Profile Quote Post Goto Top
 
Zach
Member Avatar
Missjayness
[ *  *  *  *  * ]
But still, with numerous users able to make patches to the browser, a system could be introduced (if not implemented currently) that constantly updates the browser to identify and perhaps, block completely, spyware.
Offline Profile Quote Post Goto Top
 
dbzlotrfan
Member
[ *  *  *  *  *  *  * ]
guess there are some uses to open source. You'd think since firefox is open source, hackers coudl crerate virus that crash firefox, but I think it's unhappend as of till now (may be wrong).
Offline Profile Quote Post Goto Top
 
desdemona
Member
[ *  * ]
thanks for the info... I had 2 more sites on my white list, I've now removed them untill the patch is ready :)
Quote:
 
There goes FF's reputation for being virus and exploit free...

Just the same... if people believe any browser is exploit free they are naive. I stick with FF beacuse it's the best and safest (along with many other reasons) and a lot better than IE in many ways (that's the short version ;) )
Offline Profile Quote Post Goto Top
 
Rory
i;m a mess
[ *  *  *  *  *  *  * ]
doug05257
May 10, 2005 04:12 AM
There goes FF's reputation for being virus and exploit free... ;)

When has it ever been like that?

This isn't the first exploit found in FireFox, it just happens to have come after the FireFox brand is becoming more recognised.

As Seth said, it was fixed extremely quickly, which is one of the great benefits of an open source browser, people can find the fix's and submit them to be verified and added to the main code base :)
Offline Profile Quote Post Goto Top
 
Platyna
Lady Lazarus
[ *  *  * ]
FF has reputation of being exploit free? Wow, looks like it is not only fanatism but communistic propaganda! :D
http://securityfocus.com/bid/

Regards.
Offline Profile Quote Post Goto Top
 
Deleted User
Deleted User

Quote:
 
As Seth said, it was fixed extremely quickly, which is one of the great benefits of an open source browser, people can find the fix's and submit them to be verified and added to the main code base
I'm sure it probably also has something to do with Firefox being coded so much better than IE too.
I can only imagine the horror of having to go mucking about in any Microsoft code mess trying to find, let alone fix anything.
Quote Post Goto Top
 
Platyna
Lady Lazarus
[ *  *  * ]
Hehe, everything is coded better than IE, there are no any doubts. I prefer telnet to port 80 than IE.
But telling that some software is exploit free is serious offence.

Regards.
Offline Profile Quote Post Goto Top
 
1 user reading this topic (1 Guest and 0 Anonymous)
Go to Next Page
« Previous Topic · Community Chat · Next Topic »
Add Reply
  • Pages:
  • 1
  • 3