Multiple Browsers Dialog Origin Vulnerability Test
23-06-2005, 03:22
|
#1
|
|
Karateka
Join Date: Dec 2003
Age: 33
Posts: 7,098
|
Multiple Browsers Dialog Origin Vulnerability Test
Multiple Browsers Dialog Origin Vulnerability Test
source: http://secunia.com/multiple_browsers...rability_test/
Quote:
Secunia Research has discovered a vulnerability in various browsers, which can be exploited by malicious web sites to spoof dialog boxes.
The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open e.g. a prompt dialog box, which appears to be from a trusted site.
|
Test if you're vulnerable.
__________________
Quidquid latine dictum sit, altum sonatur.
|
|
|
23-06-2005, 08:44
|
#2
|
|
looking about
Join Date: Jun 2003
Location: Teesside
Age: 43
Posts: 7,553
|
Re: Multiple Browsers Dialog Origin Vulnerability Test
Yep certainly am, will read more, thanks for the heads up Gareth
__________________
|
|
|
23-06-2005, 08:52
|
#3
|
|
vista home premium user
Join Date: Jul 2004
Location: chavy Nottingham
Age: 24
Services: Freeview, Sky+ on big TV, 2 Mb/s NTL BB, mega PC, PSP, PDA, N95
Posts: 6,349
|
Re: Multiple Browsers Dialog Origin Vulnerability Test
FF 1.0.4 vulnerable... but it's easy. Don't do yer shopping or owt else secure at the same time as when you're doing "less secure" things... that's what the Secunia article said anyway.
__________________
PC: X2 4200+, 2GB RAM, X1650, 940GB HDDs, Audigy2ZS Platinum, HVR1100, Vista Home Premium Laptop: Advent 7203 (T5300, 2GB RAM, 80GB HDD, VHP) Server: WHS (XP 2800+, 1GB RAM, 820GB HDD)
 10111 pts
|
|
|
23-06-2005, 17:49
|
#4
|
|
We are watching...
Join Date: Jun 2003
Location: Swinton
Age: 34
Services: Virgin Media
Posts: 7,802
|
Re: Multiple Browsers Dialog Origin Vulnerability Test
Mozillazine stated a few days ago that FF 1.05 is due soon (links to test builds there) and it is a minor security update. It's doesn't say what though, so it could be something else
v1.04 here and it's vulnerable
__________________
The road to hell is paved with good intentions
|
|
|
24-06-2005, 02:36
|
#5
|
|
cf.mega poster
Join Date: Jun 2003
Location: heckmondwike
Age: 22
Posts: 10,768
|
Re: Multiple Browsers Dialog Origin Vulnerability Test
http://www.microsoft.com/technet/sec...ry/902333.mspx
i cant see a fix anywhere, reports say microsoft wont fix this, proberbly because its a javascript popup.
|
|
|
|
Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 19:51.
|