Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Firefox Exploit Targets Zero Day Vulns


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Firefox Exploit Targets Zero Day Vulns
Reply
 
Thread Tools
Old 09-05-2005, 12:50   #1
.
 
Join Date: Jun 2003
Posts: 6,239
Neil has a bronze arrayNeil has a bronze arrayNeil has a bronze array
Neil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze array
Firefox Exploit Targets Zero Day Vulns

Quote:
Originally Posted by El Reg
Security researchers have discovered two unpatched vulnerabilities in Firefox, the popular alternative web browser. The security bugs affect even the latest version of Firefox (version 1.0.3) and create a means for attackers to seize control of vulnerable systems using cross-site scripting attacks.

One vulnerability enables arbitrary JavaScript code with escalated privileges to be executed via a specially crafted JavaScript URL. Successful exploitation requires that a site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org"). This would normally drastically reduce the scope for mischief - but for a second security bug, involving "IFRAME" JavaScript URLs, which creates a means to execute arbitrary HTML and script code in the context of an arbitrary site.
More Info Here....
Neil is offline   Reply With Quote
Old 09-05-2005, 12:51   #2
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,929
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Exclamation New FF vulnerability found

0 Day exploit
Quote:
Security researchers have discovered two unpatched vulnerabilities in Firefox, the popular alternative web browser. The security bugs affect even the latest version of Firefox (version 1.0.3) and create a means for attackers to seize control of vulnerable systems using cross-site scripting attacks.

One vulnerability enables arbitrary JavaScript code with escalated privileges to be executed via a specially crafted JavaScript URL. Successful exploitation requires that a site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org"). This would normally drastically reduce the scope for mischief - but for a second security bug, involving "IFRAME" JavaScript URLs, which creates a means to execute arbitrary HTML and script code in the context of an arbitrary site.

A combination of the two vulnerabilities can be exploited to execute arbitrary code on vulnerable systems, according to Danish security firm Secunia. Exploit code is publicly available greatly increasing the chance of attack, it warns. The vulnerabilities - described by Secunia as "extremely critical" - have been confirmed in version 1.0.3 of Firefox. Other versions may also be affected.

Users are advised to disable JavaScript and the software installation option within Firefox pending a more comprehensive fix from the Mozilla Foundation. ®
__________________
Paul is offline   Reply With Quote
Old 09-05-2005, 12:53   #3
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,929
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Firefox Exploit Targets Zero Day Vulns

Beat me by a minute
http://www.cableforum.co.uk/board/sh...923#post466923
__________________
Paul is offline   Reply With Quote
Old 09-05-2005, 12:58   #4
.
 
Join Date: Jun 2003
Posts: 6,239
Neil has a bronze arrayNeil has a bronze arrayNeil has a bronze array
Neil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze arrayNeil has a bronze array
Re: Firefox Exploit Targets Zero Day Vulns

Quote:
Originally Posted by Paul
And I posted it in the correct forum too.....
Neil is offline   Reply With Quote
Old 09-05-2005, 13:01   #5
Mal
We are watching...
 
Mal's Avatar
 
Join Date: Jun 2003
Location: Swinton
Age: 34
Services: Virgin Media
Posts: 7,802
Mal has a nice shiny star
Mal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny star
Re: Firefox Exploit Targets Zero Day Vulns

More info here
__________________
The road to hell is paved with good intentions
Mal is offline   Reply With Quote
Old 10-05-2005, 17:30   #6
Mal
We are watching...
 
Mal's Avatar
 
Join Date: Jun 2003
Location: Swinton
Age: 34
Services: Virgin Media
Posts: 7,802
Mal has a nice shiny star
Mal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny star
Re: Firefox Exploit Targets Zero Day Vulns

...and a bit more info here
__________________
The road to hell is paved with good intentions
Mal is offline   Reply With Quote
Old 10-05-2005, 20:14   #7
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,929
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Firefox Exploit Targets Zero Day Vulns

Already seen reports of 1.0.4 version that is patched against the vulnerability. Wonder when they will release it?
__________________
Paul is offline   Reply With Quote
Old 10-05-2005, 21:29   #8
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Firefox Exploit Targets Zero Day Vulns

I think this could be a good opportunity for demonstrating how quickly a fix can be prepared within the open source community. I'm not surprised there are flaws in Firefox (I would be surprised if there weren't any!), so the key is getting the fixes shipped quickly.
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 11-05-2005, 21:13   #9
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Firefox Exploit Targets Zero Day Vulns

Well, almost 24 hours since my last post, you can now get FF 1.04 from here: http://ftp.mozilla.org/pub/mozilla.o...t-aviary1.0.1/

Alternatively, this will filter through the normal channels over the next few hours, so you'll be able to upgrade from getfirefox.com soon too.
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 11-05-2005, 21:20   #10
Mal
We are watching...
 
Mal's Avatar
 
Join Date: Jun 2003
Location: Swinton
Age: 34
Services: Virgin Media
Posts: 7,802
Mal has a nice shiny star
Mal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny starMal has a nice shiny star
Re: Firefox Exploit Targets Zero Day Vulns

Quote:
Originally Posted by Gareth
Well, almost 24 hours since my last post, you can now get FF 1.04 from here: http://ftp.mozilla.org/pub/mozilla.o...t-aviary1.0.1/

Alternatively, this will filter through the normal channels over the next few hours, so you'll be able to upgrade from getfirefox.com soon too.
Those are release candidates that are available.
__________________
The road to hell is paved with good intentions
Mal is offline   Reply With Quote
Old 11-05-2005, 21:51   #11
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Firefox Exploit Targets Zero Day Vulns

Yet another example of how Firefox is better, security wise.
Not one IT professional I know runs IE.
Richard M is offline   Reply With Quote
Old 11-05-2005, 22:10   #12
Karateka
 
Gareth's Avatar
 
Join Date: Dec 2003
Age: 33
Posts: 7,098
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Gareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny starsGareth has a pair of shiny stars
Re: Firefox Exploit Targets Zero Day Vulns

Quote:
Originally Posted by Mal
Those are release candidates that are available.
Heh, yeah... forgot to mention that. Best wait if you don't like installing RC's
__________________
Quidquid latine dictum sit, altum sonatur.
Gareth is offline   Reply With Quote
Old 12-05-2005, 07:18   #13
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,929
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Firefox Exploit Targets Zero Day Vulns

Release version is out
http://ftp.mozilla.org/pub/mozilla.o...eleases/1.0.4/
__________________
Paul is offline   Reply With Quote
Old 12-05-2005, 09:30   #14
Google it!!
 
Paul's Avatar
 
Join Date: Jun 2003
Location: Essex
Age: 34
Services: Sky Digital + 16Mb ADSL BT Telephone
Posts: 14,929
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Firefox Exploit Targets Zero Day Vulns

Also alvailable from the main page now as well
http://download.mozilla.org/?product...win&lang=en-US
__________________
Paul is offline   Reply With Quote
Old 12-05-2005, 10:34   #15
cf.mega poster
 
Join Date: Jun 2003
Age: 29
Posts: 6,273
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Re: Firefox Exploit Targets Zero Day Vulns

Kinda unrelated but I found this comment in the Firefox source code:
Quote:
// C++ sucks! There's no way to do this with a macro, at least not
// that I know, if you know how to do this with a macro then please do
// so...
static const PRUnichar sHTMLTagUnicodeName_a[] =
{'a', '\0'};
static const PRUnichar sHTMLTagUnicodeName_abbr[] =
{'a', 'b', 'b', 'r', '\0'};
static const PRUnichar sHTMLTagUnicodeName_acronym[] =
{'a', 'c', 'r', 'o', 'n', 'y', 'm', '\0'};
It then goes on to list hundreds more HTML tags.
Richard M is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 19:54.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)