| We hope you enjoy your visit. You're currently viewing our forum as a guest. This means you are limited to certain areas of the board and there are some features you can't use. If you join our community, you'll be able to access member-only sections, and use many member-only features such as customizing your profile, sending personal messages, and voting in polls. Registration is simple, fast, and completely free. Join our community! If you're already a member please log in to your account to access all of our features: |
| Critical Flaw In Firefox | |
|---|---|
| Tweet Topic Started: May 9 2005, 10:49 PM (1,251 Views) | |
| Gornakle | May 10 2005, 11:26 AM Post #16 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
"Anything made by human hands can be broken." - Someone on someplace I don't remember I don't consider this a real threat though, the exploit used the Mozilla update site, which is now turned off, so even unpatched users aren't affected anymore. |
![]() |
|
| Rory | May 10 2005, 11:39 AM Post #17 |
|
i;m a mess
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
No one does say that FireFox is exploit free, especially not the Mozilla Foundation. It is just people picking on the fact that FireFox is more secure than IE. You can read into that how you like, but there will always be bugs and exploits in any software. |
![]() |
|
| Platyna | May 10 2005, 01:38 PM Post #18 |
|
Lady Lazarus
![]() ![]() ![]() ![]() ![]()
|
*Platyna rolls her eyes and looks on Rory. Regards. |
![]() |
|
| tropicaldawn (CC) | May 10 2005, 02:40 PM Post #19 |
|
Member
![]() ![]() ![]()
|
I stopped suing firefox ages ago because of security reasons! Its back to IE for 3 mths now and i even uninstalled my spyware software coz its no use to me now! |
![]() |
|
| Maelroth | May 10 2005, 02:41 PM Post #20 |
|
Keeping an eye on you
![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Uhoh i dont want a flaw in FF ... lets hope it will be solved fast ^^Where was that topic with making FF faster? |
![]() |
|
| Matthew | May 10 2005, 03:46 PM Post #21 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Yeah, I read about those security flaws. It was gonna happen sometime, every piece of software has it's flaws. The great thing is that it's been fixed/will be fixed really soon/can't remember :blink: -- much faster than MS. You'd probably have to wait for another 'service pack' from MS before any problem in IE would be fixed, if not, months on end. That's the good thing about open-source of course, like Rory said
How come? Were you actually getting spyware/adware and stuff?
Already has I think (according to what Seth said), they just need to release an update In the meantime it's not as bad as you think, the Icon/Javascript one is the worst - and if you haven't altered the whitlisted sites allowed to install software, because Mozilla have protected their own update sites, I think you're alright - as it says at the end of the article
http://support.invisionfree.com/index.php?showtopic=128673
|
![]() |
|
| Maelroth | May 10 2005, 03:55 PM Post #22 |
|
Keeping an eye on you
![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Thanks, and which is the best browser on the net? i heard that it was Opera but i wanna know which is the best according to lots of software companys |
![]() |
|
| Rory | May 10 2005, 04:19 PM Post #23 |
|
i;m a mess
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Roll your eyes all you want, but if you would have read my post after that, i pointed out that no one from Mozilla has ever said that, which i believe is more important than people going around saying it. "Wow, looks like it is not only fanatism but communistic propaganda!" You will always have fan-boys and fan-girls. For IE, Opera, FireFox etc. Oh, on a side note, why not add 'Regards' to your signature? Seeing as you say it every time
|
![]() |
|
| Platyna | May 10 2005, 04:29 PM Post #24 |
|
Lady Lazarus
![]() ![]() ![]() ![]() ![]()
|
Well, looks like we are talking about two different things. I was talking about Firefox fanatism and spreading along a myth that it is exploit free by the people. Anyway whole that stuff about a Fox hugging the Internet and birds guarding your emails with their wings seems like Mozilla strongly encourages its users for such abnormal behaviour I am recently seeings spreading all over the Internet. It seems to be, for me, the same ridiculous hysteria like "IF support volunteering"...
Hmz, perhaps because it is not my name? :o Anyway is that polite form bothering you? Regards. |
![]() |
|
| Rory | May 10 2005, 04:33 PM Post #25 |
|
i;m a mess
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
How on earth do the logo's for FireFox and ThunderBird encourage its users to have abnormal behaviour? That is just bizarre logic right there. Oh, and your signature isn't just for your name saves you writing out something over and over.
|
![]() |
|
| Platyna | May 10 2005, 04:37 PM Post #26 |
|
Lady Lazarus
![]() ![]() ![]() ![]() ![]()
|
Well, I explained it in a post above, and it was only an example, I already saw FF as Jesus, as an anime character hugging the computer and trying to kick IE out there, drawings with popular cartoon characters helping Fire Fox to hug the Internet or hugging Fire Fox etc. Anyway we are going far offtopic now. ![]() Regards. |
![]() |
|
| JoeC | May 10 2005, 06:16 PM Post #27 |
|
Euch! IE tastes horrible!
![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
But, to be fair, that wasn't created by Mozilla, that's just Fan art that can't be kept off the web ![]() FF was never bug free, anyone who says something is is asking for it to be hacked. Anyway, hardcore FFer here. Glad it's fixed. |
![]() |
|
| desdemona | May 11 2005, 05:50 AM Post #28 |
|
Member
![]() ![]() ![]() ![]()
|
Hey, the web is full of idiots, eventually some of them are gonna get Firefox... And to be honest I think the fuss about Firefox is well deserved, since it really is a great step forward from IE. There will always be the fanatics that see everything in black and white, but those are on both sides of the fence. Have you ever listened to them defending IE? Believe me, they are no more stupid than those saying FF is exploitfree... Saying Mozilla encourages this kind of behavoir or believes is not fair. (Reminds me that I ought to put my little Firefox fanart dollie in my sig, hehe) |
![]() |
|
| AndrewF31 | May 11 2005, 03:32 PM Post #29 |
![]()
Otorrinolaringologista
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
more on the flaw: 'Extremely Critical' Bugs Found In Firefox By Gregg Keizer, TechWeb News http://www.techweb.com/wire/security/163100258 A pair of unpatched vulnerabilities in Mozilla's Firefox Web browser -- rated as "extremely critical" by one security firm -- could allow an attacker to take control of a PC simply by getting a user to visit a malicious Web site, Mozilla said Sunday. Because proof-of-concept code has been leaked -- as were the vulnerabilities -- before a patch was ready, Mozilla recommended that Firefox users either disable JavaScript or lock down the browser so it doesn't install additional software, such as extensions or themes, from Web sites. The vulnerabilities were discovered by a pair of security researchers, who had notified Mozilla earlier in the month, but were keeping mum until a patch was written. However, details of the vulnerabilities were leaked by someone close to one of the researchers. According to Danish security vendor Secunia, which tagged the bugs with a highest "extremely critical" warning -- the first time it's used that to describe a Firefox flaw -- a hacker can trick the browser into thinking a download is coming from one of the by-default sites permitted to install software automatically: addons.mozilla.org or update.mozilla.org. "Changes to the Mozilla Update web service have been made to mitigate the risk of an exploit," the Foundation announced on its security site Sunday. Specifically, Mozilla re-pointed the two update sites to a new URL, and instructed users not to add that new site to their list of Allowed Sites. The change, however, only defends against the current proof-of-concept that's circulating, not the vulnerabilities themselves. While that reduced the risk of an immediate attack, Mozilla doesn't have control over the numerous sites that users might have added to their Allow, or whitelist, list. Popular plug-ins, called "extensions" by Firefox, could also be the root of attacks, since users must give an extension site installation permission. To close all possible doors, Mozilla recommended that users either disable JavaScript or turn off installation from Web sites. To disable Web site software installs, users can select Tools/Options/Preferences in Firefox 1.0.3, the current edition. Users can still install extensions or user interface themes manually by first downloading the file, then running them from Firefox's File menu. A security update -- which will be dubbed Firefox 1.0.4 -- will be issued as soon as possible. "Mozilla is aggressively working to provide a more comprehensive solution to these potential vulnerabilities and will provide that solution in a forthcoming security update," the organization's security alert continued. While the leaked information included proof-of-concept code that demonstrated how a malicious site could run code of the attacker's choice and install it on machines using Firefox, Mozilla discounted the risk. "There are currently no known active exploits of these vulnerabilities," it said Sunday. The release of Firefox 1.0.4 would be the fourth security update to the browser since the beginning of the year. Others appeared in late February, late March, and mid-April. In that time, Microsoft has released two patches for its Internet Explorer browser. The same email also included something about the google outage over the weekend which some may have noticed via the absence of google ads on IF boards. Apparently it was "Google spokesman David Krane is quoted as saying the problem was related to the Domain Name System (DNS), which maps web names to the numerical Internet Protocol (IP) addresses used by computers. The story also has Netcraft's Paul Mutton saying suggesting the Google DNS server suffered a malfunction, meaning local DNS servers weren't able to resolve www.google.com. "The outage has nonetheless drawn attention to widespread reliance of many web users and services on Google and highlights existing concerns over the stability of DNS infrastructure," says New Scientist, adding." |
![]() |
|
| Matthew | May 12 2005, 02:42 PM Post #30 |
|
Member
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]()
|
Well, Firefox 1.0.4 has just been released which fixes both these security issues. 2 days after they were discovered. You can't argue with that Firefox!
|
![]() |
|
| 1 user reading this topic (1 Guest and 0 Anonymous) | |
| Go to Next Page | |
| « Previous Topic · Community Chat · Next Topic » |
| Track Topic · E-mail Topic |
11:07 PM Jul 10
|



![]](../../../../0/1/0/p601690/pipright.png)



lets hope it will be solved fast ^^


Firefox!
11:07 PM Jul 10