What is the BigBlueNetwork?

Go Back   BigBlueBall Forums > Computer Support > Computer Support Discussion

Join today and you won't have to look at these ads any more. Learn more.
Reply
 
LinkBack Topic Tools
  #1 (permalink)  
Old 05-09-2005, 07:26 PM
SS_AntiHacker's Avatar
SS_AntiHacker SS_AntiHacker is offline
Senior Member
 
Join Date: Oct 2004
Location: .
Posts: 141
SS_AntiHacker is on a distinguished road (10)
Firefox is not safe as everyone thought it would be !!!

__________________________________________________ _____________
Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.


The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.



A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.



The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.



In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.

Two Vulnerabilities Found



The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.



The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.



Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.



"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.
__________________________________________________ _______________

Source: PC World

QT
Reply With Quote
  #2 (permalink)  
Old 05-14-2005, 06:05 PM
Rusty's Avatar
Rusty Rusty is offline
Senior Member
 
Join Date: Dec 2004
Location: texas
Posts: 579
Rusty is an unknown quantity at this point
Send a message via AIM to Rusty Send a message via MSN to Rusty
OMFG I have been using it and it just updated today do you think its ok to you like since it updated?
Reply With Quote
  #3 (permalink)  
Old 05-14-2005, 06:13 PM
DJHyperbyte DJHyperbyte is offline
Senior Member
 
Join Date: Jan 2003
Location: Netherlands.
Posts: 2,587
DJHyperbyte will become famous soon enough (50)
In any case, get Opera. #*)!$*!~

Last edited by DJHyperbyte : 05-14-2005 at 06:16 PM.
Reply With Quote
  #4 (permalink)  
Old 05-14-2005, 07:22 PM
Tigerblade's Avatar
Tigerblade Tigerblade is offline
the infiniteth monkey with the infiniteth typewriter
 
Join Date: Aug 2003
Location: Terra, Sol System
Posts: 3,780
Tigerblade has left a lasting impression (500)Tigerblade has left a lasting impression (500)Tigerblade has left a lasting impression (500)Tigerblade has left a lasting impression (500)Tigerblade has left a lasting impression (500)Tigerblade has left a lasting impression (500)
As long as you dont unnecessarily add other sites to that 'whitelist' you're still fine. i compare it to IE... they have some kind of "critical security patch" every week or so... what a terrific product, eh?

the thinking man's only relief is insanity... escape to insanity
[ twitter ]

Reply With Quote
  #5 (permalink)  
Old 05-15-2005, 01:37 AM
EliteNick's Avatar
EliteNick EliteNick is offline
Senior Member
 
Join Date: Jul 2004
Posts: 343
EliteNick is on a distinguished road (10)
Send a message via AIM to EliteNick Send a message via Yahoo to EliteNick
Quote:
Originally Posted by SS_AntiHacker
__________________________________________________ _____________
However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.
Exactly. Any 'ol browser can be less vulnerable than IE simply because people won't try to find the exploits and vulnerabilities on it because it has so many less users than something like IE...which they know a LOT of people use...so they find every vulnerable point in it.


Art is my life
Reply With Quote
  #6 (permalink)  
Old 05-15-2005, 09:18 AM
amy_d_g's Avatar
amy_d_g amy_d_g is offline
Senior Member
 
Join Date: Jul 2004
Location: USA
Posts: 605
amy_d_g has a spectacular aura about (100)amy_d_g has a spectacular aura about (100)
Send a message via Yahoo to amy_d_g
Seems they have fixed this, with a new update, 1.0.4.


Yahoo! Messenger Skins
Reply With Quote
  #7 (permalink)  
Old 05-15-2005, 09:22 AM
Rusty's Avatar
Rusty Rusty is offline
Senior Member
 
Join Date: Dec 2004
Location: texas
Posts: 579
Rusty is an unknown quantity at this point
Send a message via AIM to Rusty Send a message via MSN to Rusty
See I thought so but then you want to know what I already got rid of it and I really liked it.
Reply With Quote
Reply



Currently Active Users Viewing This Topic: 1 (0 members and 1 guests)
 
Topic Tools

Posting Rules
You may not post new topics
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Topics
Topic Topic Starter Forum Replies Last Post
Firefox Questions amy_d_g Computer Support Discussion 6 11-12-2004 08:38 PM
slow user input in firefox Tigerblade Computer Support Discussion 3 07-20-2004 02:28 AM
Firefox help: URL link problems for AIM plastidcells Computer Support Discussion 2 06-29-2004 02:58 AM
Mozilla Firebird? Not anymore..read to find out... EvilSeph Computer Support Discussion 16 03-09-2004 04:12 AM
Is RegSeeker safe ? shivalinga The BigBlueBall Lounge 1 12-01-2003 02:08 AM

All times are GMT -5. The time now is 01:52 PM.
Return to the BigBlueBall.com homepageHome | Contact Us | Privacy Statement | Advertise | Top
Powered by vBulletin® Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 RC6
Content Relevant URLs by vBSEO 3.0.0 RC6
©1999 - 2008 BigBlueBall.com All rights reserved.