JAN 06: Firefox vulnerability discovered - BX's Silicon Valley (Computers, Technology) - Boxden Articles




http://www.boxden.com


A diverse, large, and expanding unique urban community that blog and discuss various aspects of life as the young adult. From music, movie, and video game reviews and discussions, to computers, fitness/health, and latest fashion trends. Its all here, and we are constantly expanding with over 100 new members joining daily!

[Free all expense paid membership to BX] 


PDA

View Full Version : JAN 06: Firefox vulnerability discovered


EASTLondon
01-06-2005, 10:51 AM
Ingrid Marson
ZDNet UK

January 05, 2005, 15:30 GMT

A newly discovered flaw in Firefox could allow cybercriminals to take advantage of Web surfers

A vulnerability in Firefox could make users of the open source browser more likely to fall for phishing scams.

The flaw in Mozilla Firefox 1.0, details of which were published by Secunia on Tuesday, allows malicious hackers to spoof the URL in the download dialog box which pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hyppönen, director of antivirus research at F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," said Hyppönen.

To fall victim to such a scam, a Firefox user would have to click on a link in an email that pointed to a spoofed Web site and then download malware from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said it is unlikely that phishers will take advantage of this exploit in Firefox because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," said Emm. "After all, Firefox has a much, much smaller install base than IE and it's likely that hackers will continue to pay more attention to [IE] instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based browsers, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, :( but Mozilla developers plan to fix this bug in an upcoming version of the product.

The Secunia advisory (http://secunia.com/secunia_research/2004-15/advisory/) and Mozilla bug report (https://bugzilla.mozilla.org/show_bug.cgi?id=275417) are available online.

News Article Link (http://news.zdnet.co.uk/internet/0,39020369,39183106,00.htm)

jackus9
01-06-2005, 12:17 PM
sh*t. any ideas how to fix this or how soon do you think it'll be til mozilla fires out a new round of updates? cause i got firefox cause it was supposed to be safe and um....not lookin that way.

EASTLondon
01-07-2005, 06:34 PM
sh*t. any ideas how to fix this or how soon do you think it'll be til mozilla fires out a new round of updates? cause i got firefox cause it was supposed to be safe and um....not lookin that way.

I'm sure there will be a fix sometime next week. At this moment in time Mozilla is still safer (for some users) to use than IE, but as Mozilla get's more and more popular it attract's more attention from hackers that will exploit all vulnerabilities found :(