Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Firefox reintroduces 7-year-old security flaw

[es] :: Advocacy :: Firefox reintroduces 7-year-old security flaw

[ Pregleda: 1428 | Odgovora: 6 ]

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

xxxrugby

Član broj: 16068
Poruke: 653
*.ericsson.net.

Sajt: www.zagreb-rugby.hr


Profil

icon Firefox reintroduces 7-year-old security flaw25.06.2005. u 17:41

10.06.2005 - 14:56

Citat:
New versions of the Mozilla Foundation's browsers have reintroduced a seven-year-old flaw that makes them vulnerable to spoofing attacks, security advisory company Secunia said Monday. Secunia first publicized the flaw last summer, warning that a feature that had been built into most browsers for years was in fact a security liability. The firm argued that a feature allowing one Web page to load arbitrary content into a frame of another page could allow an attacker to, for example, substitute his own log-in window on a bank's Web site. The feature was found in IE, Mozilla, Opera, Safari, and Mozilla derivatives such as Konqueror.

"We believe that it is important that Microsoft and the other vendors seriously consider the minor gains from such 'functionality' against the possible consequences for their customers," said Secunia CTO Thomas Kristensen at the time. "In our opinion, this is a vulnerability and should be treated as such, whether the vendors implemented this intentionally or not."

Most browser vendors, including Mozilla, agreed and updated their products to remove the feature. But it has been re-introduced in Firefox 1.0.4, Mozilla 1.7.8, and Camino 0.x, according to the firm. Secunia has published an online demonstration of the flaw at

http://secunia.com/multiple_br..._injection_vulnerability_test/

The new vulnerability is a slight variation of the flaw fixed last year, Secunia said.

The Mozilla Project said it is investigating the report, and a moderator of the organisation's online support site said the flaw had not been exploited.

"To protect yourself, close all other windows/tabs before accessing a site where you routinely put in a secure password (your bank or PayPal account), or your bank or credit card details (e.g. Amazon), or other sensitive data," the moderator said.

Only a handful of other flaws have had an impact reaching across browsers and platforms. Another example is a spoofing flaw involving the use of international domain names, discovered in browsers such as Mozilla, Firefox, and Opera -- though not IE -- in February.

xxxrugby: "We are all philosophers, when question is about politics!"
25.06.2005. u 17:41 

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.

ICQ: 106979934


Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:11
Ništa čudno za open-source đubre od softvera. Taj FF je magnet za sigurnosne propuste svih vrsta. Više ga ni najluđi zealoti ne spominju kao siguran.
26.06.2005. u 10:11 

Vanja Petreski
Chief Executive Officer, Oblac

Član broj: 315
Poruke: 1583
*.beoland.sezampro.yu.

Sajt: www.oblac.com


Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:40
Ej Sundance, evo ti:

http://www.flexbeta.net/main/c...php?catid=1&shownews=13689

P.S. Pazi da ne svrsis!
26.06.2005. u 10:40 

KOLE89
Nikola Kocić
ETŠ "Nikola Tesla" Beograd
Altina/Zemun

Član broj: 19253
Poruke: 758
*.neobee.net.

Sajt: www.xprocessteam.net


Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:48
Citat:
This test does not work in Mozilla, FireFox, and Camino when opening the web pages in a new tab instead of a window.



26.06.2005. u 10:48 

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.

ICQ: 106979934


Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 11:49
Imam ja u Maxthonu sve što mi treba...i tabove i RSS i language tools, i reducirane privilegije, ActiveX kill bit, filtar za reklame i popupe, auto-kontrola zona za "dobro poznate sajtove"....
26.06.2005. u 11:49 

milke
Dragan Milić

Član broj: 52025
Poruke: 237
*.pat-pool.bgd.sbb.co.yu.



Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 12:33
Citat:
Vanja Petreski: Ej Sundance, evo ti:

http://www.flexbeta.net/main/c...php?catid=1&shownews=13689

P.S. Pazi da ne svrsis! :D

Bez namere da izazivam flame war, mada je to na ovakvom mestu nemoguće, ako je ovo zaista budući IE7, onda (da probam nekako da pristojno kažem) su bili jaaaaakoo inspirisani načinom na koji je RSS realizovan u Safariju (dobro, tamo je "Sort by" prvo "Date", pa onda "Title" :-)). Verovatno iz istog izvora i inspiracija ikonama/dugmadima (snap back, reload...) kao sastavnim delovima address polja. Da da, znam da Apple nije izmislio RSS i da je daleko nego prvi koji ga je smestio u browser, pričam samo o načinu na koji je RSS reader realizovan. No dobro, "iskorišćavanja" tuđih ideja je uvek bilo i biće, nije MS izuzetak.
26.06.2005. u 12:33 

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.

ICQ: 106979934


Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 12:43
Citat:
milke: No dobro, "iskorišćavanja" tuđih ideja je uvek bilo i biće, nije MS izuzetak.


Baš kao ni Apple.
26.06.2005. u 12:43 

[es] :: Advocacy :: Firefox reintroduces 7-year-old security flaw

[ Pregleda: 1428 | Odgovora: 6 ]

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.