Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.

Firefox reintroduces 7-year-old security flaw

[es] :: Advocacy :: Firefox reintroduces 7-year-old security flaw

[ Pregleda: 3566 | Odgovora: 6 ] > FB > Twit

Postavi temu Odgovori

Autor

Pretraga teme: Traži
Markiranje Štampanje RSS

xxxrugby

Član broj: 16068
Poruke: 653
*.ericsson.net.

Sajt: www.zagreb-rugby.hr


Profil

icon Firefox reintroduces 7-year-old security flaw25.06.2005. u 17:41 - pre 229 meseci
10.06.2005 - 14:56

Citat:
New versions of the Mozilla Foundation's browsers have reintroduced a seven-year-old flaw that makes them vulnerable to spoofing attacks, security advisory company Secunia said Monday. Secunia first publicized the flaw last summer, warning that a feature that had been built into most browsers for years was in fact a security liability. The firm argued that a feature allowing one Web page to load arbitrary content into a frame of another page could allow an attacker to, for example, substitute his own log-in window on a bank's Web site. The feature was found in IE, Mozilla, Opera, Safari, and Mozilla derivatives such as Konqueror.

"We believe that it is important that Microsoft and the other vendors seriously consider the minor gains from such 'functionality' against the possible consequences for their customers," said Secunia CTO Thomas Kristensen at the time. "In our opinion, this is a vulnerability and should be treated as such, whether the vendors implemented this intentionally or not."

Most browser vendors, including Mozilla, agreed and updated their products to remove the feature. But it has been re-introduced in Firefox 1.0.4, Mozilla 1.7.8, and Camino 0.x, according to the firm. Secunia has published an online demonstration of the flaw at

http://secunia.com/multiple_br..._injection_vulnerability_test/

The new vulnerability is a slight variation of the flaw fixed last year, Secunia said.

The Mozilla Project said it is investigating the report, and a moderator of the organisation's online support site said the flaw had not been exploited.

"To protect yourself, close all other windows/tabs before accessing a site where you routinely put in a secure password (your bank or PayPal account), or your bank or credit card details (e.g. Amazon), or other sensitive data," the moderator said.

Only a handful of other flaws have had an impact reaching across browsers and platforms. Another example is a spoofing flaw involving the use of international domain names, discovered in browsers such as Mozilla, Firefox, and Opera -- though not IE -- in February.

xxxrugby: "We are all philosophers, when question is about politics!"
 
Odgovor na temu

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.



Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:11 - pre 229 meseci
Ništa čudno za open-source đubre od softvera. Taj FF je magnet za sigurnosne propuste svih vrsta. Više ga ni najluđi zealoti ne spominju kao siguran.
 
Odgovor na temu

anon315

Član broj: 315
Poruke: 1657
*.beoland.sezampro.yu.



+13 Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:40 - pre 229 meseci
Ej Sundance, evo ti:

http://www.flexbeta.net/main/c...php?catid=1&shownews=13689

P.S. Pazi da ne svrsis!
 
Odgovor na temu

KOLE89
Nikola Kocić
Altina/Zemun

Član broj: 19253
Poruke: 764
*.neobee.net.



+17 Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 10:48 - pre 229 meseci
Citat:
This test does not work in Mozilla, FireFox, and Camino when opening the web pages in a new tab instead of a window.


 
Odgovor na temu

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.



Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 11:49 - pre 229 meseci
Imam ja u Maxthonu sve što mi treba...i tabove i RSS i language tools, i reducirane privilegije, ActiveX kill bit, filtar za reklame i popupe, auto-kontrola zona za "dobro poznate sajtove"....
 
Odgovor na temu

milke
Dragan Milić

Član broj: 52025
Poruke: 237
*.pat-pool.bgd.sbb.co.yu.



+3 Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 12:33 - pre 229 meseci
Citat:
Vanja Petreski: Ej Sundance, evo ti:

http://www.flexbeta.net/main/c...php?catid=1&shownews=13689

P.S. Pazi da ne svrsis! :D

Bez namere da izazivam flame war, mada je to na ovakvom mestu nemoguće, ako je ovo zaista budući IE7, onda (da probam nekako da pristojno kažem) su bili jaaaaakoo inspirisani načinom na koji je RSS realizovan u Safariju (dobro, tamo je "Sort by" prvo "Date", pa onda "Title" :-)). Verovatno iz istog izvora i inspiracija ikonama/dugmadima (snap back, reload...) kao sastavnim delovima address polja. Da da, znam da Apple nije izmislio RSS i da je daleko nego prvi koji ga je smestio u browser, pričam samo o načinu na koji je RSS reader realizovan. No dobro, "iskorišćavanja" tuđih ideja je uvek bilo i biće, nije MS izuzetak.
 
Odgovor na temu

Sundance

Član broj: 7510
Poruke: 2559
*.sava.sczg.hr.



Profil

icon Re: Firefox reintroduces 7-year-old security flaw26.06.2005. u 12:43 - pre 229 meseci
Citat:
milke: No dobro, "iskorišćavanja" tuđih ideja je uvek bilo i biće, nije MS izuzetak.


Baš kao ni Apple.
 
Odgovor na temu

[es] :: Advocacy :: Firefox reintroduces 7-year-old security flaw

[ Pregleda: 3566 | Odgovora: 6 ] > FB > Twit

Postavi temu Odgovori

Navigacija
Lista poslednjih: 16, 32, 64, 128 poruka.