Pages: 1

Yet another severe security loophole in Firefox

(Click here to view the original thread with full colors/images)


Posted by: Indyan

Quote:
Firefox suffers from a flaw that allows attackers to manipulate the authentication cookies of virtually any website, a vulnerability Bugzilla has deemed severe. It's the second major security lapse for the open-source browser in as many days.

The defect, which stems from the way Firefox writes to the "location.hostname" property of the document object model, can be exploited by a specially doctored script that sets variables that normally wouldn't be accepted when parsing a regular URL, according to researcher Michal Zalewski, who uncovered Monday's vulnerability as well.

By ********* text string that includes "\x00," normal safeguards can be bypassed, allowing the browser to be fooled about the origin of a domain trying to set or modify a cookie. The sleight of hand makes a victim's browser appear to be talking to trustedbank.com when in fact it is receiving data from evilhackers.com.

The attacker would also be able to change the document.domain accordingly. A demonstration of the vulnerability, which has been tested on version 2.0.0.1, is available here.


Source



Posted by: forwardone

I suppose that as Firefox gets bigger the attention of the hackers will be turned to them to do whatever damage they can.



Posted by: Pete Berg

Oh i was not before get this kind of information about firefox..i think this is more protective and having more secure then any other browser but as per i read you passage i found the opposite thing so what i have to think is firefox better for me or not..




eXTReMe Tracker