title
Products            Buy            Support Forum            Professional            About            Codec Central
 

More security flaws in Firefox

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ChristinaS
    dBpoweramp Guru

    • Apr 2004
    • 4097

    More security flaws in Firefox

    More problems for Firefox!

    http://www.internetnews.com/security...le.php/3503506 :
    It seems Mozilla's Firefox, the undisputed darling of the alternative browser set, isn't immune after all to the slings and arrows suffered by other popular interfaces.

    On Saturday the Greyhats Security Group punctured the browser's aura of invincibility after it released details of two flaws that allow a malicious site to execute arbitrary code.

    The advisory explains that the successful attacks involve two elements. The first flaw fools the browser into thinking software is being installed by a "whitelisted site." The second flaw occurs when the software installation trigger does not sufficiently check icon URLs containing JavaScript code.
    Flexera provides software licensing management, software compliance, installation and application packaging solutions to developers and their customers.

    Two vulnerabilities have been discovered in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.

    1) The problem is that "IFRAME" JavaScript URLs are not properly protected from being executed in context of another URL in the history list. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site.

    2) Input passed to the "IconURL" parameter in "InstallTrigger.install()" is not properly verified before being used. This can be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL.
    Apparently the immediate solution requires disabling of javascript pending a proper fix.

    Nice, isn't it? So, what happens to all those fancy rollover effects?
  • Joseph
    dBpoweramp Enthusiast

    • Oct 2002
    • 211

    #2
    Re: More security flaws in Firefox

    They fix flaws very very fast. There will be a new version out within the next 2 weeks

    Comment

    • Razgo
      Administrator
      • Apr 2002
      • 2532

      #3
      Re: More security flaws in Firefox

      i think we will see a lot more of this happening showing firefox browser can be just as insecure and have flaws like any other browser.

      the reason being is that the more popular firefox becomes the more attention hackers give it.

      i am pretty much just using the opera browser now.

      Comment

      • Joseph
        dBpoweramp Enthusiast

        • Oct 2002
        • 211

        #4
        Re: More security flaws in Firefox

        I also use Opera. It's fantastic for slower machines

        Comment

        • LtData
          dBpoweramp Guru

          • May 2004
          • 8288

          #5
          Re: More security flaws in Firefox

          I still use Firefox, as I have been for a while, mostly because I'm used to it now and know all the shortcuts for it by heart. I tried Opera but didn't really care for it like I do for Firefox. But, as always, Opera does have its place, as browswer opinions are all up to personal taste.

          Comment

          • Joseph
            dBpoweramp Enthusiast

            • Oct 2002
            • 211

            #6
            Re: More security flaws in Firefox

            Firefox has already been updated to 1.0.4 and addresses the above issues. Now wasn't that fast. :smile2: www.GetFirefox.com

            Comment

            • ChristinaS
              dBpoweramp Guru

              • Apr 2004
              • 4097

              #7
              Re: More security flaws in Firefox

              Joseph, I really hate that service you're using for a signature.
              To think everybody is so worried about security and here's this thing shouting at me my vital statistics! I know it's oly for me to see, but still, it feels like it's a breech somewhere - it is remotely hosted after all :D

              Comment

              • LtData
                dBpoweramp Guru

                • May 2004
                • 8288

                #8
                Re: More security flaws in Firefox

                Its just printing out to you what your computer tells it.

                Comment

                • ChristinaS
                  dBpoweramp Guru

                  • Apr 2004
                  • 4097

                  #9
                  Re: More security flaws in Firefox

                  Originally posted by LtData
                  Its just printing out to you what your computer tells it.
                  I know - but it's not what my computer tells me, it's what a remotely hosted script masquerading as an image file tells my computer to tell me and its host. I still don't like it :D


                  Thank you Joseph

                  Comment

                  • donny
                    dBpoweramp Guru

                    • Oct 2002
                    • 761

                    #10
                    Re: More security flaws in Firefox

                    is somebody else using the Opera email client? it's nice I also tried out IRC from Opera... the built in FTP is not so fab but it does work nicely

                    and I adore the moue gestures... I know that there are plugs for Firefox and mozila, but they are not so efficient...

                    Comment

                    • Razgo
                      Administrator
                      • Apr 2002
                      • 2532

                      #11
                      Re: More security flaws in Firefox

                      is somebody else using the Opera email client?
                      i gave it a test run but the filters don't seem to be as good as the bat! or thunderbird. it took 26hrs to import 60,000 emails. but without good filters it looses me and i hate having to reset up mail filters which is shame they can't be imported. or more importantly no email client seems to let you use an external file for some filters. like if i want to delete certain emails off the server before they get downloaded i can do that by listing all the emails in a txt file that the email client will look at first.

                      but to do the same thing with email already downloaded doesn't seem possible. well no one smart enough has worked it out yet anyway.

                      Comment

                      Working...

                      ]]>