TranceAddict Forums (www.tranceaddict.com/forums)
- Canada - Toronto & Southern Ont.
-- Critical Flaw Found in Firefox
Pages (2): [1] 2 »
Critical Flaw Found in Firefox
| quote: |
Matthew Broersma, Techworld.com Mon May 9,11:00 AM ET Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned. The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system. A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts. The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating. In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser. Two Vulnerabilities Found The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist. The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers. Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned. "We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org. |
Who the crap uses Javascript anyway?
| quote: |
| Originally posted by VERTiG0 Who the crap uses Javascript anyway? |
| quote: |
| Originally posted by VERTiG0 Who the crap uses Javascript anyway? |
| quote: |
| Originally posted by VERTiG0 Who the crap uses Javascript anyway? |
| quote: |
| Originally posted by rabbitjoker You're kidding, right. |
lol, I have javascript turned off anyway lol
*bump*
Just a reminder
...be careful
Thanks for the info. Still beats IE, even with its flaws.
Check this graph out!
Since March 2005 - IE has only had 8 security issues.
Since March 2005 - Firefox has had 44 security issues!
hah I love "researchers", yeah researchers probably funded by Microsoft. LOL Greyhats security group my arse.
| quote: |
| Originally posted by rabbitjoker Check this graph out! Since March 2005 - IE has only had 8 security issues. Since March 2005 - Firefox has had 44 security issues! |
| quote: |
| Originally posted by Matt lol, I have javascript turned off anyway lol |
Has anyone ever been affected by these "High Risk" security threats? I mostly just get
spyware/adware on my computer and thats about it. But seriously, if your on the internet without
a firewall/anti-virus tool, I suggest you get off while you can and save your computers life.
My norton firewall stops on average 5 high risk attacks per day, and who knows how many moderate to low.
most of those high risk alerts are related to phishing attempts..
as long as you are smart enough not to click on a link to; paypal, ebay, your bank, etc. from some random email saying your password has expired, you are pretty safe..
| quote: |
| Originally posted by joinT yes, but keep in mind - patches for FF arrive very quickly, whereas patches for IE can take months!! not only that, but how old is IE 6? been out since 2001. after 4 years they better not have many bugs left.. |
I haven't had a single security problem with firefox since i've been using it anyways. IE on the other hand...
| quote: |
| Originally posted by Swamper Lots of things on the net won't work for you then. |
| quote: |
| Originally posted by Swamper Lots of things on the net won't work for you then. |
| quote: |
| Originally posted by joinT most of those high risk alerts are related to phishing attempts.. as long as you are smart enough not to click on a link to; paypal, ebay, your bank, etc. from some random email saying your password has expired, you are pretty safe.. |
I love all the "yeah, but"'s... LOL!
Bottom line - within the last 6 months Firefox has 550% more security problems than IE.
wait. wait for it. wait.
"Yeah, but..."
| quote: |
| Originally posted by rabbitjoker Bottom line - within the last 6 months Firefox has 550% more security problems than IE. |
| quote: |
| Originally posted by rabbitjoker I love all the "yeah, but"'s... LOL! Bottom line - within the last 6 months Firefox has 550% more security problems than IE. wait. wait for it. wait. "Yeah, but..." |
How about looking at total security flaws between IE 6.0 and Firefox 1.0. I believe Firefox wins hands down.
| quote: |
| Originally posted by tw1tch Picking a time line that best suits your argument. How about looking at total security flaws between IE 6.0 and Firefox 1.0. I believe Firefox wins hands down. |
| quote: |
| Originally posted by DigiNut this trend |
| quote: |
| Originally posted by VERTiG0 I like Firefox because it's faster and tabbed browsing rocks my socks |
| quote: |
| Originally posted by VERTiG0 Al Capowned |
Powered by: vBulletin
Copyright © 2000-2021, Jelsoft Enterprises Ltd.