Closed Thread
Results 1 to 3 of 3

Thread: FireFox Spoofing Bug

  1. #1
    Jordan Guest

    FireFox Spoofing Bug

    A serious flaw in how Firefox handles log-ons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday.

    Aviv Raff, an Israeli researcher best known for ferreting out browser flaws, revealed the Firefox spoofing vulnerability on his personal blog, and posted a demonstration video there. He did not go public with any proof-of-concept code or working exploit, however.

    According to Raff, Firefox 2.0.0.11 -- Mozilla Corp.'s most current version -- fails to sanitize single quotation marks and spaces in what's called the "Realm" value of an authentication header. "This makes it possible for an attacker to create a specially crafted Realm value which will look as if the authentication dialog came from a trusted site," said Raff.

    Raff outlined a pair of possible attack vectors. One would rely on a malicious site that included a link to a trusted site -- a well-known bank, say, or a Web e-mail service such as Gmail or Hotmail -- that when clicked would display its usual log-on dialog. In the background, however, the attacker would have crafted a script that exploited the Firefox vulnerability to redirect the username and password entered by the user to the hacker's server instead of the real deal.

    More

  2. CODECALL Circuit advertisement

     
  3. #2
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Dam. Is this only with the 2.0.0.11 version of FF?

    anyone seen the video or has a link to his blog? I would love to see the video.

  4. #3
    Jordan Guest
    Here is the original (added yesterday) I think: Yet another Dialog Spoofing - Firefox Basic Authentication

Closed Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. sniffing and spoofing?
    By Hamed in forum Computer Software/OS
    Replies: 4
    Last Post: 06-08-2011, 02:32 PM
  2. Raw Sockets Ip Spoofing
    By Kuto in forum C and C++
    Replies: 5
    Last Post: 03-14-2011, 07:12 PM
  3. Webcam Spoofing
    By whomp in forum General Programming
    Replies: 0
    Last Post: 06-28-2010, 12:11 AM
  4. Replies: 3
    Last Post: 11-24-2009, 06:15 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts