Firefox Security

crbuys

Legal Expert: Internet
Joined
Sep 23, 2004
Messages
126
Reaction score
1
Location
South Africa.
Hi all,

I picked this up on the SANS website (www.sans.org):

Firefox Users Urged to Uninstall Newer Versions of Greasemonkey Due
to Critical Vulnerability

A severe flaw in the Greasemonkey Firefox browser extension has prompted
developers to strongly recommend that users uninstall all versions of
Greasemonkey prior to 0.3.5. Greasemonkey allows users to run user
scripts on web pages they visit to modify their surfing experience.
Running Greasemonkey scripts on websites could expose every file on
local hard drives to that site. The flaw could be exploited to steal
word-readable files.

http://www.eweek.com/print_article2/0,1217,a=156314,00.asp

http://greasemonkey.mozdev.org/

SpreadFirefox.com Taken Offline After Security Breach

SpreadFirefox.com was taken off line after evidence of a July 10
intrusion surfaced on July 12. The attackers exploited an unpatched
hole in the software that runs the site; patches have now been applied.
Mozilla says the machine that was attacked was likely used to send spam,
but acknowledged that it is possible that the attackers had access to
usernames, passwords and other information that people may have provided
on the web site. Mozilla is encouraging SpreadFirefox.com users to
change their passwords.

http://networks.silicon.com/webwatch/0,39024667,39150463,00.htm

Regards,
 
please don't let this thread degenerate into a mud slinging contest about how "bad" IE or FireFox is.
FWIW, GreaseMonkey is an *extension* and *not* developed by the Firefox team.

Thx for the heads up crbuys :)
 
Then you obviously didn't read the 2nd part of the posting where it said :

SpreadFirefox.com was taken off line after evidence of a July 10
intrusion surfaced on July 12. The attackers exploited an unpatched
hole in the software that runs the site; patches have now been applied.
Mozilla says the machine that was attacked was likely used to send spam,
but acknowledged that it is possible that the attackers had access to
usernames, passwords and other information that people may have provided
on the web site. Mozilla is encouraging SpreadFirefox.com users to
change their passwords.

There's a big difference in having a security leak in an extension and one in firefox.
 
Top
Sign up to the MyBroadband newsletter
X