From http://www.itwire.com.au/content/view/5965/53/ .Firefox vulnerable to JavaScript hackers
By Stan Beer
Tuesday, 03 October 2006
Two hackers have detailed a serious security flaw in the Firefox web browser that would enable attackers to gain control of any computer running the Internet Explorer rival regardless the underlying operating system.
According to Mischa Spiegelmock and Andrew Wbeelsoi, who gave a detailed presentation at the ToorCon hacker conference in San Diego on Saturday, the vulnerability is not able to be patched unless Mozilla rewrites key sections of its JavaScript code.
The two hackers gave a detailed presentation on stage showing a slide with key information on how to exploit the vulnerability. They said that a hacker could gain control of a computer which visits a web page containing malicious JavaScript code.
Mozilla is taking the presentation seriously and is reportedly annoyed at the way the hackers disclosed the exploit in enough detail for a hacker to repoduce it.
What was even more disturbing to Mozilla is that Spiegelmock and Wbeelsoi claim to have knowledge of about 30 Firefox vulnerabilities and have no intention of responsibly disclosing them to Mozilla.
It seems that the US$500 a flaw bounty that Mozilla is willing to pay hackers who find genuine vulnerabilities was not enough incentive to dissuade the two hackers from contributing to the sort of environment that forces internet users to be wary of what sites they visit.
Nasty FireFox security hole..
-
- Forum User
- Posts: 378
- Joined: Thu Aug 24, 2006 12:41 pm
- Location: MA, USA
Nasty FireFox security hole..
I know some people here are big fans. Beware JavaScript at sites you're not familiar with...
- [JiF][AARP]Grimp
- Moderator
- Posts: 3803
- Joined: Thu Aug 24, 2006 9:23 pm
- Location: Massachusetts
-
- Forum User
- Posts: 378
- Joined: Thu Aug 24, 2006 12:41 pm
- Location: MA, USA
JubJub sent it to me - that may be the problem..
Actually, I think the site is down. Could get there earlier but now it looks like it's gonna timeout.
edit: different source at http://news.com.com/Hackers+claim+zero- ... 21608.html
Actually, I think the site is down. Could get there earlier but now it looks like it's gonna timeout.
edit: different source at http://news.com.com/Hackers+claim+zero- ... 21608.html
- [JiF][AARP]Grimp
- Moderator
- Posts: 3803
- Joined: Thu Aug 24, 2006 9:23 pm
- Location: Massachusetts
- [JiF]ALargeWoodenBadger
- Forum User
- Posts: 774
- Joined: Thu Aug 24, 2006 12:56 am
- Location: Ontario, Canada
Re: Nasty FireFox security hole..
Seeing as today is Monday, 02 October 2006 maybe these hackers can still be stopped before they discover the flaw.[JiF]Timmay! wrote:I know some people here are big fans. Beware JavaScript at sites you're not familiar with...
Firefox vulnerable to JavaScript hackers
By Stan Beer
Tuesday, 03 October 2006
Two hackers have ...
-
- Forum User
- Posts: 632
- Joined: Thu Aug 24, 2006 4:57 pm
- Location: Dwarf Pine Forest
-
- Forum User
- Posts: 632
- Joined: Thu Aug 24, 2006 4:57 pm
- Location: Dwarf Pine Forest
http://www.heise-security.co.uk/news/78970 ... a hoax?
- [JiF][AARP]Grimp
- Moderator
- Posts: 3803
- Joined: Thu Aug 24, 2006 9:23 pm
- Location: Massachusetts
- [JiF]Stepovich
- Forum User
- Posts: 1292
- Joined: Thu Aug 24, 2006 1:46 pm
- Location: MA
-
- Forum User
- Posts: 76
- Joined: Fri Aug 25, 2006 12:45 pm
- [JiF][AARP]Grimp
- Moderator
- Posts: 3803
- Joined: Thu Aug 24, 2006 9:23 pm
- Location: Massachusetts
- [JiF][AARP]Tissueman
- Moderator
- Posts: 2784
- Joined: Thu Aug 24, 2006 1:19 am
- Location: Cincinnati