ChiefsPlanet

ChiefsPlanet (https://chiefsplanet.com/BB/index.php)
-   Nzoner's Game Room (https://chiefsplanet.com/BB/forumdisplay.php?f=1)
-   -   FireFox Browsers Suceptible to Malicious Code... Here's the temp fix... (https://chiefsplanet.com/BB/showthread.php?t=116030)

Taco John 05-09-2005 02:40 PM

FireFox Browsers Suceptible to Malicious Code... Here's the temp fix...
 
The fix: Users can protect themselves by temporarily disabling JavaScript, according to Mozilla.




The problem:


May 9, 2005
Two Holes Poke Firefox Veneer
By Tim Gray


It seems Mozilla's Firefox, the undisputed darling of the alternative browser set, isn't immune after all to the slings and arrows suffered by other popular interfaces.

On Saturday the Greyhats Security Group punctured the browser's aura of invincibility after it released details of two flaws that allow a malicious site to execute arbitrary code.

The advisory explains that the successful attacks involve two elements. The first flaw fools the browser into thinking software is being installed by a "whitelisted site." The second flaw occurs when the software installation trigger does not sufficiently check icon URLs containing JavaScript code.

Users can protect themselves by temporarily disabling JavaScript, according to Mozilla.

Less than a week after the foundation trumpeted breaking the 50 million download mark, the browser is dealing with what has been called by Danish security firm Secunia its first "extremely critical" bug.

The Mozilla Foundation said there are currently no known active exploits of these vulnerabilities, although a "proof of concept" has been reported.

Greyhats said an attacker can first use frames and a JavaScript history flaw to make it appear that a software installation is being triggered from add-ons.update.mozilla.org.

As the JavaScript is executed from the chrome, it has "full chrome privileges" and can "do anything that the user running Firefox can."

"Mozilla is aggressively working to provide a more comprehensive solution to these potential vulnerabilities and will provide that solution in a forthcoming security update," the foundation said on its Web site.

Numerous security outfits agree with the foundation's suggestions of disabling JavaScript as a workaround.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement.


http://www.internetnews.com/security...le.php/3503506

Taco John 05-09-2005 02:41 PM

You probably won't have to worry about it if you don't surf for porn, warez, or serialz.

dirk digler 05-09-2005 02:44 PM

Quote:

Originally Posted by ENDelt260
Start the countdown to Parker's appearance in this thread.

No shit I am glad I didn't post this. He rips me every time when I mention FireFox.

Anyway shouldn't this be in Geeksplanet?

teedubya 05-09-2005 02:46 PM

Quote:

Originally Posted by dirk digler
No shit I am glad I didn't post this. He rips me every time when I mention FireFox.

Anyway shouldn't this be in Geeksplanet?

It will be, Dirk... IT WIIIIILLL BEEEEEEEE. [/ yoda]

Ultra Peanut 05-09-2005 02:46 PM

Quote:

Originally Posted by ENDelt260
Start the countdown to Parker's appearance in this thread.

ROFL

Chest Rockwell 05-09-2005 02:47 PM

Quote:

Originally Posted by Taco John
You probably won't have to worry about it if you don't surf for porn, warez, or serialz.

Yeah, what am I, made of stone?

Thanks for the heads up.

dirk digler 05-09-2005 02:48 PM

Quote:

Originally Posted by Ali Chi3fs
It will be, Dirk... IT WIIIIILLL BEEEEEEEE. [/ yoda]

Thanks Yoda!

Mr. Laz 05-09-2005 02:51 PM

Quote:

Originally Posted by ENDelt260
Start the countdown to Parker's appearance in this thread.

russ or parker ... who shows themselves first?




"buh,buh, but ... everyone here says firefox is perfect"

"everyone knows that only IE has security issues ..."

"only the geniouses says that ..."


:rolleyes:

tk13 05-09-2005 03:01 PM

The invincible Firefox, busted AGAIN!!! :)

(Sorry, wanted to be the first to do that.)

morphius 05-09-2005 03:04 PM

I believe the MAC Safari browser was shown to have a mighty huge whole in it as well.

http://it.slashdot.org/it/05/05/08/2...&tid=179&tid=3

|Zach| 05-09-2005 03:10 PM

I still love me some Firefox.

PhogPhanTim 05-09-2005 03:12 PM

Gotta agree.

Anyone blind enough to still think IE is better than FireFox is a fool. A damn fool.

HC_Chief 05-09-2005 03:13 PM

The greater the distribution of the product, the more likely flaws/security 'holes' will be uncovered. It's the nature of the beast.

|Zach| 05-09-2005 03:13 PM

Quote:

Originally Posted by PhogPhanTim
Gotta agree.

Anyone blind enough to still think IE is better than FireFox is a fool. A damn fool.

http://www.learntarot.com/bigjpgs/maj00.jpg

ChiefsOne 05-09-2005 03:19 PM

I use Camino and don't have any problems.

Kerberos 05-09-2005 03:39 PM

I use firefox and IE and I like firefox allot. (tabbed browsing is the shit)

BUT... When firefox has been around as long as IE with as many users as IE then talk to me about how many holes it has and have been patched.

:whackit:

Microsoft gets picked on by hackers cause there are MILLIONS of people using it. So comparing firefoxes 5 exploits to microsofts 10,344,697 it is really stupid to think that its a fair comparison. :shake:

I will keep using firefox till IE has tabbed browsing. And I would bet my best friends paycheck that Microsoft will have it on IE 7 when it is released in the not so distant future. IMO

:D



.

KCFalcon59 05-09-2005 03:48 PM

Quote:

Originally Posted by rxrider
And I would bet my best friends paycheck that Microsoft will have it on IE 7 when it is released in the not so distant future..

Stay away from my paycheck man!!

Simplex3 05-09-2005 04:02 PM

Quote:

Originally Posted by rxrider
Microsoft gets picked on by hackers cause there are MILLIONS of people using it...

...and because it's easy to hack by any 12 year old with a copy of notepad.

irishjayhawk 05-09-2005 04:18 PM

Quote:

Originally Posted by tk13
The invincible Firefox, busted AGAIN!!! :)

(Sorry, wanted to be the first to do that.)

Again, may i point out that the code is on the internet. Therefore finding bugs HELPS them. No one said it was immune but its not that hard for hackers to find flaws when they have the programs code in their possession.

FloridaChief 05-09-2005 04:21 PM

I just shutoff "Enable Java" on Firefox. Temporary fix to a temporary problem.

morphius 05-12-2005 07:37 AM

It looks like the fix is out already!

Just download and install 1.0.4.

http://www.mozilla.org/products/firefox/

jarjar 05-12-2005 08:00 AM

50 million downloads of firefox, it's getting up there. In the meanwhile we still get patches almost faster than the story breaks the media.

Ultra Peanut 05-13-2005 02:59 AM

Bumped to let everyone know that the fix is indeed out.


All times are GMT -6. The time now is 02:18 PM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.