Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Mozilla is working to fix a browser flaw that could give attackers unauthorized access to data on a victim's machine. The problem is similar to other data leakage flaws found in the open-source browser, according to researcher Gerry Eisenhaur, who first reported the problem on Saturday. Of course, the issue is affecting certain add-ons, and it's likely it can be dealt with soon, or averted. The add-ons that are affected include Download Statusbar or Greasemonkey, becuase they store scripts in such a way that they could be found on the hard drive. . The link for this article located at www.infoworld.com is no longer available. . The link for this article located at www.infoworld.com is no longer available.. mozilla, working, browser, attackers, unauthorized. . LinuxSecurity.com Team
A serious flaw in how Firefox handles log-ons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday. Aviv Raff, an Israeli researcher best known for ferreting out browser flaws, revealed the Firefox spoofing vulnerability on his personal blog, and posted a demonstration video there. He did not go public with any proof-of-concept code or working exploit, however. Have you heard about the latest FireFox vulnerability? When do you think the developers will release a patch fixing the bug?. The link for this article located at PC World is no longer available. . A critical vulnerability in Firefox has emerged, potentially enabling cybercriminals to trick individuals into disclosing their login credentials. Investigate the implications.. Firefox spoofing threat, identity theft risk, browser flaw discovery. . Bill Locke
Polish hacker Michal Zalewski has found yet another flaw in Mozilla's Firefox browser, this one having to do with memory corruption and possible system takeover. While he was at it, he also found an IE flaw that sets up malicious pages that won't let visitors leave. And that taunt the trapped user while they're at it--at least in his funny demo. . He has posted a demo that displays a crash in Firefox that he says is caused by corrupted pointers. It also caused a crash when I visited it in IE, FWIW. "Firefox is susceptible to a seemingly pretty nasty, and apparently easily exploitable memory corruption vulnerability," he writes. "When a location transition occurs and the structure of a document is modified from within onUnload event handler, freed DOM-related memory structures are left in inconsistent state, possibly leading to a remote compromise." The link for this article located at eweek is no longer available. . He has posted a demo that displays a crash in Firefox that he says is caused by corrupted pointers. . polish, hacker, michal, zalewski, found, another, mozilla's, firefox, browser. . LinuxSecurity.com Team
Security researchers claim to have found ways to exploit a serious bug in Firefox and Mozilla Web browsers, a sign that attacks could be on the way. ... Disclosure of a flaw typically starts a race in the security community to exploit it. In the past few days, at least two security researchers have posted messages to popular security mailing lists claiming they have found ways attackers could take advantage of the vulnerability. . The postings said that exploits that work on Windows and Linux operating systems had been found. At the time the flaw details were disclosed, there were no known exploits for the vulnerability, beyond the one Ferris claimed to have for Windows. The link for this article located at OSDir is no longer available. . The postings said that exploits that work on Windows and Linux operating systems had been found. At . security, researchers, claim, found, exploit, serious, firefox, mozilla. . LinuxSecurity.com Team
Microsoft has denied that a spoofing technique available on its Internet Explorer browser is a security vulnerability. The software giant accepted the possibility that spoofing could occur on version six of IE, but rejected claims that this was a security flaw.< . . .. Microsoft has denied that a spoofing technique available on its Internet Explorer browser is a security vulnerability. The software giant accepted the possibility that spoofing could occur on version six of IE, but rejected claims that this was a security flaw. In a prepared email statement from the company, a spokesperson said: "Microsoft is aware of a security issue reported last week that could allow spoofing the URL a user sees in Internet Explorer's status bar. Users could see a URL in the status bar when the mouse hovers over the link on a webpage, but clicking the link would take the user to a different URL. Our investigation has indicated that this is not a security vulnerability." Last week, a researcher in Germany, Benjamin Tobias Franz, posted warnings on bulletin board Web site Bugtraq, stating that Internet Explorer could spoof links if users put two URLs and a table inside an HTML href tag. The result, Franz claimed, was that malformed links to URLs, could take users to an entirely different Web site without their knowledge. The link for this article located at zdnet.co.uk is no longer available. . Apple refutes claims that a vulnerability in Safari poses a risk, outlining its position regarding the matter.. Internet Explorer Spoofing, Microsoft Response, URL Spoofing Techniques. . LinuxSecurity.com Team
A security flaw in Netscape's Navigator Web browser can let malicious Web site operators view the information stored in cookies on a user's computer, according to a security note published on Netscape's Web site. . . .. A security flaw in Netscape's Navigator Web browser can let malicious Web site operators view the information stored in cookies on a user's computer, according to a security note published on Netscape's Web site. The vulnerability affects Navigator Versions 6 through 6.2, as well as Version 0.9.6 and earlier versions of the open-source version of Navigator, Mozilla, according to an analysis written by Marc Slemko, who discovered the bug. The bug, Slemko said in his analysis, can be exploited by causing users to visit a Web address inserted into HTML code on a Web page or in an HTML-formatted e-mail. If the user were to view the malicious Web site, cookies could be stolen off the user's computer, Slemko said. The link for this article located at NW Fusion is no longer available. . A newly found vulnerability in Netscape Navigator may allow malicious sites to steal user cookies, compromising sensitive information and exposing users to attacks. Netscape Navigator flaw, cookie exposure risk, browser security threat. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.