Seven year old Vulnerability found in Firefox

Vox Populi Vox Dei

High Tory
Joined
Mar 6, 2004
Messages
54,234
Reaction score
39,038
Location
Cape Town
Description:
A seven year old vulnerability has been re-introduced in Mozilla and Firefox, which can be exploited by malicious people to spoof the contents of web sites.

Secunia has constructed a test, which can be used to check if your browser is affected:
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/

The vulnerability has been confirmed in Firefox 1.0.4 and Mozilla 1.7.8. Other versions may also be affected.

Solution:
Do not browse untrusted web sites while browsing trusted sites.

Provided and/or discovered by:
Reported in Firefox by:
brainsoft

Source: Secunia
 
Solution:
Do not browse untrusted web sites while browsing trusted sites.

Wow thats so blatently obvious rofl
 
Methinks it means that the exploit will perhaps bypass the potections afforded trusted sites, e.g. SSL sessions [maybe], will have to read the info though...CSI
 
btw, to those who are wondering, it's not only in Firefox/Mozilla, same thing goes for IE.

Basically the code that "injects" whatever page into it relies on an already open page with frames.

So if you have a website with "leftframe" and "rightframe" and you click a link from my site with the following link : <a href="myporn.com" target="rightframe">Click here for sweet ladies!</a>

My page would open up within your frames... pretty sweet ;)
 
Didnt work for me. Wait - thats a good thing :)

Forgot to say - Safari 2.0
 
noone said:
...
My page would open up within your frames... pretty sweet ;)
Isn't that the cross-domain vulnerability that was fixed in IE quite a long time back...?
 
Top
Sign up to the MyBroadband newsletter
X