FireFox vulnerabilities FYI

M

MsOsWin

snip

snip



Apparantly , even the default sites are harmless now, as the people at
UMO have redirected the default url to another site. Just don't add
this new url to the white list!

But as pointed out below, the cross script scripting exploit still
allows fairly dangerous actions such as stealing of cookies, phishing
and whatnot, unless Javascript is off.

i wonder if teh IFRAME filter in proxomitron wold block the 1st requirement?

OP
 
M

Mel

elaich said:
Because a Java vulnerability could install malware without user permission.

JavaScript, not Java :)

A detailed explaination, by the chap who discovered the vulnerability
can be found here. He reports that they have discovered other
vulnerabilites that haven't been leaked.

http://www.greyhatsecurity.org/firefox.htm

"There are three core vulnerabilities being used in my example. A friend of mine (Michael Krax, http://www.mikx.de) helped me with
the research.

To understand why the example works, one must understand the basics of how Firefox works. Everything you see in firefox is
essentially a webpage being rendered by a compiler. This is what the gui is made of, and this is why firefox is so easy to
customize. However, it also allows for some security bugs. If one could get one of the chrome pages to request a javascript:[script]
url, that individual would be given complete access to the system because chrome urls are given full rights in firefox. My example
works by tricking the addon install function into displaying an icon with a javascript url. ..."
 
A

Aaron

JavaScript, not Java :)
Another possibility of course is that he might be thinking of the
"firefox can infect IE via Java" case a few months back. But of course,
even in that case he would be mistaken, since Java would ask for permit
to run the applet.
 
A

Aaron

That doesn't follow. Implemetations of JavaScript vary from browser
to browser.

Well change it from Javascript to Java, and maybe that might be a bit
closer to the mark.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top