|
![]() |
|
Sapere Aude
Join Date: Jun 2001
Casino cash: $427937
|
FireFox Browsers Suceptible to Malicious Code... Here's the temp fix...
The fix: Users can protect themselves by temporarily disabling JavaScript, according to Mozilla.
The problem: May 9, 2005 Two Holes Poke Firefox Veneer By Tim Gray It seems Mozilla's Firefox, the undisputed darling of the alternative browser set, isn't immune after all to the slings and arrows suffered by other popular interfaces. On Saturday the Greyhats Security Group punctured the browser's aura of invincibility after it released details of two flaws that allow a malicious site to execute arbitrary code. The advisory explains that the successful attacks involve two elements. The first flaw fools the browser into thinking software is being installed by a "whitelisted site." The second flaw occurs when the software installation trigger does not sufficiently check icon URLs containing JavaScript code. Users can protect themselves by temporarily disabling JavaScript, according to Mozilla. Less than a week after the foundation trumpeted breaking the 50 million download mark, the browser is dealing with what has been called by Danish security firm Secunia its first "extremely critical" bug. The Mozilla Foundation said there are currently no known active exploits of these vulnerabilities, although a "proof of concept" has been reported. Greyhats said an attacker can first use frames and a JavaScript history flaw to make it appear that a software installation is being triggered from add-ons.update.mozilla.org. As the JavaScript is executed from the chrome, it has "full chrome privileges" and can "do anything that the user running Firefox can." "Mozilla is aggressively working to provide a more comprehensive solution to these potential vulnerabilities and will provide that solution in a forthcoming security update," the foundation said on its Web site. Numerous security outfits agree with the foundation's suggestions of disabling JavaScript as a workaround. "We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement. http://www.internetnews.com/security...le.php/3503506 |
Posts: 79,765
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#2 |
Sapere Aude
Join Date: Jun 2001
Casino cash: $427937
|
You probably won't have to worry about it if you don't surf for porn, warez, or serialz.
__________________
Ehyeh asher ehyeh. Donger's Razor: "The most establishment-friendly explanation that gives leftist and neocon politicians the most amount of cover is the only possible explanation, even when gaping holes and leaps of logic are required to get there." |
Posts: 79,765
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#3 | |
Please squeeze
Join Date: Jul 2003
Location: Clinton, MO
Casino cash: $114644
|
Quote:
Anyway shouldn't this be in Geeksplanet? |
|
Posts: 67,118
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#4 | |
Most Valuable Poster
Join Date: Oct 2003
Casino cash: $8993042
|
Quote:
|
|
Posts: 36,832
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#5 | |
v^V^v^V^v^V^
Join Date: Aug 2001
Location: Holland*
Casino cash: $10005177
|
Quote:
![]()
__________________
![]() |
|
Posts: 39,518
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#6 | |
Y'all are brutalizin' me!
Join Date: Jan 2004
Location: Jim Bob Cooter 4 Heisman
Casino cash: $10000985
|
Quote:
Thanks for the heads up.
__________________
![]() MASTER CYLINDER! |
|
Posts: 1,096
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#7 | |
Please squeeze
Join Date: Jul 2003
Location: Clinton, MO
Casino cash: $114644
|
Quote:
|
|
Posts: 67,118
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#8 | |
Don't Tease Me
Join Date: Dec 2000
Location: KS
Casino cash: $11047037
|
Quote:
"buh,buh, but ... everyone here says firefox is perfect" "everyone knows that only IE has security issues ..." "only the geniouses says that ..." ![]()
__________________
|
|
Posts: 95,626
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#9 |
...
Join Date: Nov 2001
Casino cash: $-1907500
|
The invincible Firefox, busted AGAIN!!!
![]() (Sorry, wanted to be the first to do that.) |
Posts: 56,727
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#10 |
World's finest morphius
Join Date: Aug 2000
Casino cash: $5725027
|
I believe the MAC Safari browser was shown to have a mighty huge whole in it as well.
http://it.slashdot.org/it/05/05/08/2...&tid=179&tid=3 |
Posts: 26,023
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#11 |
For The Glory Of The City
Join Date: Sep 2002
Location: Kansas City
Casino cash: $3016768
|
I still love me some Firefox.
|
Posts: 54,737
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#12 |
Starter
Join Date: Mar 2005
Casino cash: $10004900
|
Gotta agree.
Anyone blind enough to still think IE is better than FireFox is a fool. A damn fool. |
Posts: 41
![]() ![]() |
![]() |
![]() |
#13 |
That's just f***in' stupid
Join Date: Aug 2000
Location: suburbia
Casino cash: $3687107
|
The greater the distribution of the product, the more likely flaws/security 'holes' will be uncovered. It's the nature of the beast.
__________________
"Gentlemen, you can't fight in here, this is the war room!" |
Posts: 12,355
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#14 | |
For The Glory Of The City
Join Date: Sep 2002
Location: Kansas City
Casino cash: $3016768
|
Quote:
![]() |
|
Posts: 54,737
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() |
#15 |
Veteran
Join Date: Oct 2000
Location: Springfield, MO
Casino cash: $5058192
|
I use Camino and don't have any problems.
|
Posts: 2,284
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() |
|
|