Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | New vulnerabilities in various browsers,


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Internet Discussion

New vulnerabilities in various browsers,
Reply
 
Thread Tools
Old 03-11-2004, 13:19   #1
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
New vulnerabilities in various browsers,

Yep. Someone has found two vulnerabilities that can basically affect any browser that supports tabbed browsing (Current versions of Opera and Firefox are apparently affected).

Now, I do find it slightly ironic that there is a security vulnerability out there that IE isn't affected by...

http://secunia.com/secunia_research/2004-10/advisory/

Quote:
Originally Posted by secunia.com
Vulnerability "A":
It is possible for a inactive tab to spawn dialog boxes e.g. the
JavaScript "Prompt" box or the "Download dialog" box, even if the user
is browsing/viewing a completely different web site in another tab.

The problem is that the browsers does not indicate, which tab launched
the dialog boxes, which therefore could lead the user into disclosing
information to a malicious web site or to download and run a program,
which the user thought came from another trusted web site e.g. their
bank.

Demonstration:
http://secunia.com/multiple_browsers...spoofing_test/

Vulnerability "A" Affects:
Mozilla 1.7.3
Mozilla Firefox 0.10.1
Camino 0.8
Opera 7.54
Konqueror 3.2.2-6
Netscape 7.2
Avant Browser 9.02 build 101
Avant Browser 10.0 build 029
Maxthon (MyIE2) 1.1.039


Vulnerability "B":
It is possible for a inactive tab to always gain focus on a form
field in the inactive tab, even if the user is browsing/viewing a
completely different web site in another tab.

This is escalated a bit by the fact that most people do not look at
the monitor while typing data into a form field, and therefore might
send data to the site in the inactive tab, instead of the
intended/viewed tab.

Demonstration:
http://secunia.com/multiple_browsers...ld_focus_test/

Vulnerability "B" Affects:
Mozilla 1.7.3
Mozilla Firefox 0.10.1
Netscape 7.2
Avant Browser 9.02 build 101
Avant Browser 10.0 build 029
Maxthon (MyIE2) 1.1.039
Solutions or Workarounds are in the article..
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 03-11-2004, 13:34   #2
[NTHW] pc clan
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 41
Services: Be* Unlimited ADSL2+ BB
Posts: 17,740
Ramrod is seeing silvered starsRamrod is seeing silvered starsRamrod is seeing silvered starsRamrod is seeing silvered starsRamrod is seeing silvered starsRamrod is seeing silvered starsRamrod is seeing silvered stars
Ramrod is seeing silvered stars
Re: New vulnerabilities in various browsers,

Biftas sig says it all
__________________
Step by step, walk the thousand mile road...
-----------------------------------------------------
Are you a mature PC gamer? Then go to the mature gamers site: nthwgaming.co.uk
Ramrod is offline   Reply With Quote
Old 03-11-2004, 13:37   #3
cf.mega poster
 
Bifta's Avatar
 
Join Date: Jul 2003
Location: Derry
Posts: 7,597
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: New vulnerabilities in various browsers,

Bifta is offline   Reply With Quote
Old 03-11-2004, 13:42   #4
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: New vulnerabilities in various browsers,

Lol
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 03-11-2004, 13:55   #5
Electrolyte01
Guest
 
Posts: n/a
Re: New vulnerabilities in various browsers,

I think FireFox is starting to loose the internet public now since M$ have got IE with a pop-up blocker (in XP SP2 only though) and various other improvements.

I ditched FireFox ages ago, after it used 100% CPU just to load a web page up (and take it from any other apps that were open)
  Reply With Quote
Old 03-11-2004, 14:01   #6
Eric Cartman Wannabe
 
punky's Avatar
 
Join Date: Jun 2003
Location: Cockney geeza land
Age: 27
Services: c:\> net start punky
Posts: 12,086
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
punky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver blingpunky has a lot of silver bling
Re: New vulnerabilities in various browsers,

I still think you'd have to be a bit dim to fall for it.

"Oh yes, let me just type in my passwords and credit card number into a standard javascript prompt box..."

Anyone that does deserves to get done. The best it could be used for is for collecting e-mail address for spam.
__________________
"We're not here for a long time, we're here for a good time" - Mike Ness (Social Distortion)
"Reach for the sky, 'cause tomorrow may never come" - Reach For The Sky (Social Distortion)
punky is offline   Reply With Quote
Old 03-11-2004, 14:02   #7
cf.mega poster
 
Bifta's Avatar
 
Join Date: Jul 2003
Location: Derry
Posts: 7,597
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by punky
I still think you'd have to be a bit dim to fall for it.

"Oh yes, let me just type in my passwords and credit card number into a standard javascript prompt box..."

Anyone that does deserves to get done. The best it could be used for is for collecting e-mail address for spam.
Most people that use the Internet don't know what javascript is, let alone a javascript alert, if browsers like Firefox want to become the norm. they need to cater to these people.
Bifta is offline   Reply With Quote
Old 03-11-2004, 14:10   #8
Meningitis sucks
 
zovat's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 38
Services: NTL Telephone 3M Broadband - CM Sky TV
Posts: 1,246
zovat has reached the bronze age
zovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze age
Send a message via MSN to zovat
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by scastle
Yep. Someone has found two vulnerabilities that can basically affect any browser that supports tabbed browsing (Current versions of Opera and Firefox are apparently affected).

Now, I do find it slightly ironic that there is a security vulnerability out there that IE isn't affected by...

http://secunia.com/secunia_research/2004-10/advisory/



Solutions or Workarounds are in the article..
so now we are supposed to thank M$ for never implementing the most useful of browsing features..

No thanks

so there is a new vulnerability - this is not uncommon... There are still less for Firefox than for IE.

Quote:
Originally Posted by Scott
I think FireFox is starting to loose the internet public now since M$ have got IE with a pop-up blocker (in XP SP2 only though) and various other improvements.

I ditched FireFox ages ago, after it used 100% CPU just to load a web page up (and take it from any other apps that were open)
I would disagree - the fact that M$ have implemented these features shows that Firefox (and other browsers) is having an effect - I have been running Firefox since Version 0.6 (or possibly earlier) and have had no issues with it.

My wife, who is no techie (but knows more about M$ office etc than me) is now using it, and thinks it is far better than IE.

As long as products like Firefox keep adding features and improving the "user experience", then there will always be a market for them.
__________________
All opinions stated here are just that opinions - feel free to ignore them or disagree with them.
I speak for myself and no-one else.
http://www.danasoft.com/sig/ZovatSig.jpg
zovat is offline   Reply With Quote
Old 03-11-2004, 14:22   #9
cf.mega poster
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 43
Posts: 2,575
Aragorn is cast in bronzeAragorn is cast in bronzeAragorn is cast in bronzeAragorn is cast in bronze
Aragorn is cast in bronzeAragorn is cast in bronze
Re: New vulnerabilities in various browsers,

There is a reference to these in a Reg article :

Quote:
... So here we have problems in some very popular tabbed browsers. Secunia's advice is logical: either disable JavaScript (which will cause problems using a vast number of web sites, so it's not likely), or avoid opening a trusted web site in a tab when other tabs already contain untrusted websites. OK. Not bad advice. So if you want to use PayPal or eBay or your bank, open up a new Firefox window first. No problem. A fix, of course, would be better.

In the usual open source tradition of fixing flaws quickly, Konqueror released a version of the browser that was patched against the vulnerabilities, and Firefox promised that it would be secured by the time 1.0 is released, sometime in the new few weeks. On the other hand, Netscape, now owned by AOL, and Avant never bothered to respond to Secunia when it contacted them. Guess I know which browsers to avoid.

I'm not trying to discredit Secunia or these vulnerabilities. They are definitely problems that need to be fixed. It's just that there's a big difference between the almost torturous series of steps required to exploit users with these vulnerabilities as compared to the recent IE exploit that involved simply visiting your bank's website.
...
I agree with the writer - you have to be pretty 'taken in' to go to a phished website and open the real website in another tab of the same browser!

I've been Mozilla/Firefox ing for over a year now and have no plans to change.
Aragorn is offline   Reply With Quote
Old 03-11-2004, 14:30   #10
Cable Forum Team
 
Stuart C's Avatar
 
Join Date: Jun 2003
Location: It's Lahndun, Innit?
Age: 37
Services: Virgin for TV, BT for phone and Be* for Broadband.
Posts: 17,465
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Stuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny starsStuart C has a pair of shiny stars
Send a message via MSN to Stuart C Send a message via Yahoo to Stuart C Send a message via Skype™ to Stuart C
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by zovat
so now we are supposed to thank M$ for never implementing the most useful of browsing features..

No thanks

so there is a new vulnerability - this is not uncommon... There are still less for Firefox than for IE.

Calm down..

Athough I phrased the post in a jokey way, there was a serious message. People COULD get caught by this.

FYI, I am currently using one of the affected browsers: Opera.

BTW, IMO, tabbed browsing is not a useful feature. It's a pain. IE (in combination with XP) does do something similar. Open three (or more) IE windows, and you should find them nicely grouped as a menu on the one task bar button, although, that's not (strictly speaking) a feature of IE.
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.

"This is an important announcement. This is flight 121 to Los Angeles. If your travel plans today do not include Los Angeles, now would be a perfect time to disembark.”
Stuart C is offline   Reply With Quote
Old 03-11-2004, 14:42   #11
Meningitis sucks
 
zovat's Avatar
 
Join Date: Oct 2003
Location: Bracknell
Age: 38
Services: NTL Telephone 3M Broadband - CM Sky TV
Posts: 1,246
zovat has reached the bronze age
zovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze agezovat has reached the bronze age
Send a message via MSN to zovat
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by scastle
Calm down..
Sorry - I need to make the smilie bigger next time....


Quote:
Originally Posted by scastle
Athough I phrased the post in a jokey way, there was a serious message. People COULD get caught by this.
And it is a valid warning

Quote:
Originally Posted by scastle
FYI, I am currently using one of the affected browsers: Opera.
Must look at opera again - havn't used it for at least a year...

Quote:
Originally Posted by scastle
BTW, IMO, tabbed browsing is not a useful feature. It's a pain. IE (in combination with XP) does do something similar. Open three (or more) IE windows, and you should find them nicely grouped as a menu on the one task bar button, although, that's not (strictly speaking) a feature of IE.

each to their own - I like having the abitility to have 2 firefox windows open - 1 secure and one not, then have as many tabs within that as I need within each window..

Normally I have my Secure window containing tabs for banking and work (vpn/net connected), and the other window for insecure stuff like this site, dilbert, El Reg, etc.
__________________
All opinions stated here are just that opinions - feel free to ignore them or disagree with them.
I speak for myself and no-one else.
http://www.danasoft.com/sig/ZovatSig.jpg
zovat is offline   Reply With Quote
Old 03-11-2004, 16:01   #12
cf.mega poster
 
Salu's Avatar
 
Join Date: Jun 2003
Location: Yorks
Age: 41
Services: Sky+ with full package. VM phone and 20MB internet
Posts: 2,236
Salu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronze
Salu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronzeSalu is cast in bronze
Send a message via MSN to Salu
Re: New vulnerabilities in various browsers,

There is a security update for IE6 with XP SP2 released today.

http://www.neowin.net/comments.php?i...&category=main
__________________
CF Resident Medic

Salu is offline   Reply With Quote
Old 03-11-2004, 16:06   #13
cf.mega poster
 
Bifta's Avatar
 
Join Date: Jul 2003
Location: Derry
Posts: 7,597
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by Salu
There is a security update for IE6 with XP SP2 released today.

http://www.neowin.net/comments.php?i...&category=main
You should probably have read the link you posted, it's NOT a security update.
Bifta is offline   Reply With Quote
Old 03-11-2004, 18:13   #14
Graham
Guest
 
Posts: n/a
Re: New vulnerabilities in various browsers,

Quote:
Originally Posted by scastle
BTW, IMO, tabbed browsing is not a useful feature. It's a pain.
And IMO tabbed browsing is an *incredibly* useful feature!

Instead of having my task bar cluttered with a button for each browser window you have open, I can have just two or three, but each one of those is linked to two or three other tabs for google searches, sites where I'm downloading stuff from or anything else I want to look at, all I need to know is which button is CF, which is google and which is misc other.

I'd *never* go back to an untabbed browser and, to get back on topic, these "vulnerabilities" are, frankly, pretty unlikely to be exploitable in any meaningful way.
  Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 04:40.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)