Become a part of the TranceAddict community!Frequently Asked Questions - Please read this if you haven'tSearch the forums
TranceAddict Forums > Local Scene Info / Discussion / EDM Event Listings > Canada > Canada - Toronto & Southern Ont. > Critical Flaw Found in Firefox
Pages (3): [1] 2 3 »   Last Thread   Next Thread
Share
Author
Thread    Post A Reply
starsearcher
DigitalPunk on Flight643



Registered: Jan 2003
Location: Toronto
Read This! Critical Flaw Found in Firefox

quote:

Matthew Broersma, Techworld.com Mon May 9,11:00 AM ET

Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.

The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.

A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.
Two Vulnerabilities Found

The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.


Source: http://news.yahoo.com/s/pcworld/120756


___________________
Photo Album: *Click*

Old Post May-10-2005 02:53  Israel
Click Here to See the Profile for starsearcher Click here to Send starsearcher a Private Message Visit starsearcher's homepage! Add starsearcher to your buddy list Report this Post Reply w/Quote Edit/Delete Message
VERTiG0
cunning linguist.



Registered: Dec 2003
Location: no longer Cambridge, Ontario, Canada

Who the crap uses Javascript anyway?

Old Post May-10-2005 03:42  Canada
Click Here to See the Profile for VERTiG0 Click here to Send VERTiG0 a Private Message Add VERTiG0 to your buddy list Report this Post Reply w/Quote Edit/Delete Message
Jem_hadar
I remember...



Registered: Nov 2003
Location: Pandora (South of Nowhere)
Question

quote:
Originally posted by VERTiG0
Who the crap uses Javascript anyway?


___________________
TECHNO IS THE BEST NOISE ON EARTH.
Save Techno - Stop Minimal / Tech-House

Old Post May-10-2005 03:43  Canada
Click Here to See the Profile for Jem_hadar Click here to Send Jem_hadar a Private Message Visit Jem_hadar's homepage! Add Jem_hadar to your buddy list Report this Post Reply w/Quote Edit/Delete Message
rabbitjoker
aural sadist



Registered: Aug 2002
Location: Toronto, ON, CANADA

quote:
Originally posted by VERTiG0
Who the crap uses Javascript anyway?


You're kidding, right.


___________________
- rabbit.joker [funny¿rabbit] | www.rabbitjoker.com |www.ddtt.org

Dark Dirty Tech Tribal. | Hands in air (trance) and feet on the floor (house).

Old Post May-10-2005 03:44  Canada
Click Here to See the Profile for rabbitjoker Click here to Send rabbitjoker a Private Message Visit rabbitjoker's homepage! Add rabbitjoker to your buddy list Report this Post Reply w/Quote Edit/Delete Message
Surreal JRS
Balearic Sunset



Registered: Jan 2005
Location: Kicking it in Toronto, Canada

quote:
Originally posted by VERTiG0
Who the crap uses Javascript anyway?


sed -e 's/Javascript/ActiveX/g'


___________________
Surreal
Universal Religion


Old Post May-10-2005 03:49  Canada
Click Here to See the Profile for Surreal JRS Click here to Send Surreal JRS a Private Message Visit Surreal JRS's homepage! Add Surreal JRS to your buddy list Report this Post Reply w/Quote Edit/Delete Message
VERTiG0
cunning linguist.



Registered: Dec 2003
Location: no longer Cambridge, Ontario, Canada

quote:
Originally posted by rabbitjoker
You're kidding, right.


HARRRR HAR HARRRRR


Old Post May-10-2005 03:49  Canada
Click Here to See the Profile for VERTiG0 Click here to Send VERTiG0 a Private Message Add VERTiG0 to your buddy list Report this Post Reply w/Quote Edit/Delete Message
Matt
Supreme tranceaddict



Registered: Nov 2001
Location: Toronto, Canada

lol, I have javascript turned off anyway lol


___________________
//..

Old Post May-10-2005 03:50  Canada
Click Here to See the Profile for Matt Click here to Send Matt a Private Message Add Matt to your buddy list Report this Post Reply w/Quote Edit/Delete Message
starsearcher
DigitalPunk on Flight643



Registered: Jan 2003
Location: Toronto

*bump*

Just a reminder ...be careful


___________________
Photo Album: *Click*

Old Post May-10-2005 12:39  Israel
Click Here to See the Profile for starsearcher Click here to Send starsearcher a Private Message Visit starsearcher's homepage! Add starsearcher to your buddy list Report this Post Reply w/Quote Edit/Delete Message
zokissima
Supreme tranceaddict



Registered: Dec 2004
Location: Toronto

Thanks for the info. Still beats IE, even with its flaws.

Old Post May-10-2005 15:00  Yugoslavia
Click Here to See the Profile for zokissima Click here to Send zokissima a Private Message Add zokissima to your buddy list Report this Post Reply w/Quote Edit/Delete Message
rabbitjoker
aural sadist



Registered: Aug 2002
Location: Toronto, ON, CANADA



Check this graph out!

Since March 2005 - IE has only had 8 security issues.

Since March 2005 - Firefox has had 44 security issues!


___________________
- rabbit.joker [funny¿rabbit] | www.rabbitjoker.com |www.ddtt.org

Dark Dirty Tech Tribal. | Hands in air (trance) and feet on the floor (house).

Old Post Sep-29-2005 14:07  Canada
Click Here to See the Profile for rabbitjoker Click here to Send rabbitjoker a Private Message Visit rabbitjoker's homepage! Add rabbitjoker to your buddy list Report this Post Reply w/Quote Edit/Delete Message
jon jon
viva la clubland



Registered: Jan 2001
Location: Footwork

hah I love "researchers", yeah researchers probably funded by Microsoft. LOL Greyhats security group my arse.


___________________
http://www.beatport.com/jonathan-rosa/

Old Post Sep-29-2005 14:25  Canada
Click Here to See the Profile for jon jon Click here to Send jon jon a Private Message Visit jon jon's homepage! Add jon jon to your buddy list Report this Post Reply w/Quote Edit/Delete Message
joinT
haussnob



Registered: Oct 2001
Location: always futurebound....

quote:
Originally posted by rabbitjoker


Check this graph out!

Since March 2005 - IE has only had 8 security issues.

Since March 2005 - Firefox has had 44 security issues!


yes, but keep in mind - patches for FF arrive very quickly, whereas patches for IE can take months!!

not only that, but how old is IE 6? been out since 2001. after 4 years they better not have many bugs left..


___________________
===============
jimmy alliance!

Old Post Sep-29-2005 17:00  Canada
Click Here to See the Profile for joinT Click here to Send joinT a Private Message Add joinT to your buddy list Report this Post Reply w/Quote Edit/Delete Message

TranceAddict Forums > Local Scene Info / Discussion / EDM Event Listings > Canada > Canada - Toronto & Southern Ont. > Critical Flaw Found in Firefox
Post New Thread    Post A Reply

Pages (3): [1] 2 3 »  
Last Thread   Next Thread
Click here to listen to the sample!Pause playbackprogressive tune needs ID [2004] [3]

Click here to listen to the sample!Pause playbackJimmy Van M - Sanctuary (Brancaccio & Aisher Mix) [2005]

Show Printable Version | Subscribe to this Thread
Forum Jump:

All times are GMT. The time now is 17:44.

Forum Rules:
You may not post new threads
You may not post replies
You may not edit your posts
HTML code is ON
vB code is ON
[IMG] code is ON
 
Search this Thread:

 
Contact Us - return to tranceaddict

Powered by: Trance Music & vBulletin Forums
Copyright ©2000-2026, Jelsoft Enterprises Ltd.
Privacy Statement / DMCA
Support TA!