» Search Used Cars
Search for used vehicles by ZIP, please enter Zipcode below:
Google Links

» Wheel & Tire Center

» Log in
User Name:

Password:

Not a member yet?
Register Now!
Sponsors

Sponsors


Go Back   NissanForums.com :: Nissan Forum > General > Off Topic
Register Home Forum Gallery Active Topics Search Today's Posts Mark Forums Read

       
Reply
 
LinkBack Thread Tools Display Modes
Old May 9th, 2005, 03:16 PM   #1 (permalink)
Jeff
In Ur Threadz - Deleting!
 
Jeff's Avatar
 
Join Date: Oct 2002
Location: Dallas
Posts: 1,645
Send a message via AIM to Jeff Send a message via MSN to Jeff Send a message via Yahoo to Jeff
Firefox Vulnerability...

http://news.yahoo.com/s/pcworld/120756

Quote:
Critical Flaw Found in Firefox Matthew Broersma, Techworld.com
Mon May 9,11:00 AM ET

Firefox has unpatched "extremely critical" security holes and exploit code is already circulating on the Net, security researchers have warned.

The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your system.

A patch is expected shortly, but in the meantime users can protect themselves by switching off JavaScript. In addition, the Mozilla Foundation has now made the flaws effectively impossible to exploit by changes to the server-side download mechanism on the update.mozilla.org and addons.mozilla.org sites, according to security experts.

The flaws were confidentially reported to the Foundation on May 2, but by Saturday details had been leaked and were reported by several security organizations, including the French Security Incident Response Team (FrSIRT). Danish security firm Secunia marked the exploit as "extremely critical", its most serious rating, the first time it has given a Firefox flaw this rating.

In recent months Firefox has gained significant market share from Microsoft's Internet Explorer, partly because it is considered less vulnerable to attacks. However, industry observers have long warned that the browser is more secure partly because of its relatively small user base. As Firefox's profile grows, attackers will increasingly target the browser.

Two Vulnerabilities Found
The exploit, discovered by Paul of Greyhats Security Group and Michael "mikx" Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a "trusted" site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.

The second part of the exploit triggers software installation using an input verification bug in the "IconURL" parameter in the install mechanism. The effect is that a user could click on an icon and trigger the execution of malicious JavaScript code. Because the code is executed from the browser's user interface, it has the same privileges as the user running Firefox, according to researchers.

Mozilla Foundation said it has protected most users from the exploit by altering the software installation mechanism on its two whitelisted sites. However, users may be vulnerable if they have added other sites to the whitelist, it warned.

"We believe this means that users who have not added any additional sites to their software installation whitelist are no longer at risk," Mozilla Foundation said in a statement published on Mozillazine.org.
__________________
HIS: '07 Mazda CX-7 Touring...20% tint all around
HERS: '06 Mazda 3s...tint/CAI/Mazda3 pedals
GONE: '99 Maxima...i/h/e/eibachs/b&m/17s
Jeff is offline   Reply With Quote
Old May 9th, 2005, 05:03 PM   #2 (permalink)
Teh00Alty
woo..im 25 dollars poorer
 
Teh00Alty's Avatar
 
Join Date: Jan 2005
Location: Jersey
Posts: 473
Send a message via AIM to Teh00Alty
awwww fkuc
__________________
Rafik....
Quote:
Originally Posted by myoung on NF OT
The worst of the worse of NF reside here .. not the place to come for a hug
Teh00Alty is offline   Reply With Quote
Old May 9th, 2005, 06:16 PM   #3 (permalink)
Slayer2003
Peek-a-boo....
 
Slayer2003's Avatar
 
Join Date: Jun 2003
Location: New Hampshire
Posts: 1,714
Send a message via AIM to Slayer2003 Send a message via Yahoo to Slayer2003
I'll leave mine busted, the last 'flaw' patch for FF made it act like a dousche.
__________________
Quote:
Originally Posted by RoadWarrior - ocforums.com
Yes, SATA is faster however..... putting full spec formula one tires on a 1.6L stock honda civic will not make it capable of 200Mph......
SEARCH BUTTON. USE IT OFTEN!
Slayer2003 is offline   Reply With Quote
Reply

  NissanForums.com :: Nissan Forum > General > Off Topic



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
for firefox users krylonkoopaa Off Topic 31 Dec 14th, 2005 09:43 AM
What Firefox Extentions are you rocking? UnkalledFor Off Topic 11 May 10th, 2005 09:49 AM
Firefox Marvin Off Topic 5 Jul 25th, 2004 11:53 PM

Powered by vBadvanced CMPS v3.0.1

All times are GMT -5. The time now is 05:39 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0
© 2006 NissanForums.Com