Closed Thread
Page 1 of 4 123 ... LastLast
Results 1 to 10 of 32

Thread: Critical Firefox hole allows password theft

  1. #1
    Jordan Guest

    Critical Firefox hole allows password theft

    November 23, 2006 (IDG News Service) -- A flaw in Mozilla Corp.'s Firefox browser makes it easy for cybercriminals to steal user information on Web sites where users create their own pages, such as MySpace.com.
    The flaw lies in Firefox's Password Manager software, which can be tricked into sending password information to an attacker's Web site, said Robert Chapin, president of Chapin Information Services Inc. For this attack to work, attackers need to be able to create HTML forms on the Web site, which is allowed on blogging and social networking sites.


    The attack was used in a MySpace phishing attack reported in late October. In that attack, users registered a MySpace account named login_home_index_html and used it to host a fake log-in page that exploited the flaw.


    This page sent MySpace username and password information to another Web site, and MySpace users who visited the page using Firefox could have easily had their information compromised, said Chapin.


    Firefox developers rate this bug critical, according to an entry in the project's Bugzilla database.


    The flaw arises because Firefox's Password Manager does not perform a thorough enough check when deciding whether to send password information and then does not ensure that password information is being sent to the server that requested it, Chapin said. In the MySpace attack, for example, Firefox would check to see if the form was coming from the MySpace.com domain but did not make sure that the password information was being sent back to a MySpace server.

    Full Story

  2. CODECALL Circuit advertisement

     
  3. #2
    Join Date
    Oct 2006
    Location
    Hendersonville, NC
    Posts
    1,700
    Blog Entries
    3
    Rep Power
    0
    Not good.... Not good at all... So they didn't state a fix for it...


  4. #3
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Is this in the version of 2.0? dam it.. what about a fix?
    Dam I'm gonna delete the saved passwords NOW!
    EDIT:-
    Yes its 2.0 ( I found it on a site )

  5. #4
    Jordan Guest
    Yes, this is 2.0 and no, there is no fix right now. Best thing you can do is not save your passwords in the manager.

  6. #5
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Yup I deleted them that instance that I read the post!

  7. #6
    TkTech's Avatar
    TkTech is offline The Crazy One
    Join Date
    Jun 2006
    Location
    Canada
    Posts
    1,412
    Blog Entries
    1
    Rep Power
    31
    Two of them are now shutdown. Mysteriously they got 40 000 request a second If you find any sites exploiting my favorite browser, do so feel pleased to post them here.

  8. #7
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Quote Originally Posted by TkTech View Post
    If you find any sites exploiting my favorite browser
    Yeah mine too! at first I didn't like it that much but after 3 days I was really attracted from it!! and now with the 2.0 and spell check!! WOO!!

  9. #8
    DevilsCharm's Avatar
    DevilsCharm is offline Programming God
    Join Date
    Jul 2006
    Posts
    884
    Rep Power
    0
    So, as long as you are on the right website, nothing bad will happen. Just make sure that you are on the right site, not that hard.

  10. #9
    Join Date
    Oct 2006
    Location
    Hendersonville, NC
    Posts
    1,700
    Blog Entries
    3
    Rep Power
    0
    Man i guess no more porn sites for me...



  11. #10
    Join Date
    Aug 2006
    Posts
    11,209
    Blog Entries
    6
    Rep Power
    101
    Hmm with that Huge monitor...Wew porn in detail, close up!! loool
    Too sad for ya man! well why don't you just delete the passwords and still see it?

Closed Thread
Page 1 of 4 123 ... LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Big security hole?
    By Rabscuttle in forum Linux/Unix General
    Replies: 5
    Last Post: 02-01-2009, 10:15 AM
  2. Do you need help with identity theft??
    By etraffic in forum Hosting and Registrars
    Replies: 0
    Last Post: 05-04-2006, 01:12 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts