|
|||||||
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Pewlius Caesar
bit-tech Staff
Join Date: Nov 2001
Location: Ascot, Berks
Posts: 18,021
![]() ![]() ![]() ![]() ![]() |
Firefox is critically flawed
__________________
|
|
|
|
|
|
#2 |
|
I pwn all your storage
Join Date: Jul 2005
Location: Southampton
Posts: 13,933
![]() ![]() ![]() ![]() |
No biggie in my view, I reckon "some time" to Mozilla is two weeks. It'd take that long for some annoying **** to devise a virus to attack this section.
And I don't go on nefarious websites. |
|
|
|
|
|
#3 |
|
I Mod, Therefore I Own
Join Date: Feb 2002
Location: Somewhere in the south
Posts: 3,460
![]() ![]() |
Ooooohhh dear. Thats really not good
Shame that a good chunk of people using firefox possibly won't know how to turn Javascript off. Guess I best do that..
__________________
|
|
|
|
|
|
#4 | |
|
Banned
Join Date: Feb 2005
Location: Aberdeen, UK, EU
Posts: 7,614
![]() ![]() |
Quote:
edit: should add, there's a fix here
|
|
|
|
|
| specofdust |
| View Public Profile |
| Find More Posts by specofdust |
|
|
#5 | |
|
Pewlius Caesar
bit-tech Staff
Join Date: Nov 2001
Location: Ascot, Berks
Posts: 18,021
![]() ![]() ![]() ![]() ![]() |
Quote:
__________________
|
|
|
|
|
|
|
#6 |
|
I Mod, Therefore I Own
Join Date: Feb 2002
Location: Somewhere in the south
Posts: 3,460
![]() ![]() |
Worst part though spec is if you read the whole article on Zdnet they apparently know of 30 unpatched issues but they aren't willing to disclose them to the Mozilla team and instead wish to use them to their own advantage when they could be earning $500 per exploit under the bounty system the team has..
Kinda sad really.
__________________
|
|
|
|
|
|
#7 | |
|
Banned
Join Date: Feb 2005
Location: Aberdeen, UK, EU
Posts: 7,614
![]() ![]() |
Quote:
|
|
|
|
|
| specofdust |
| View Public Profile |
| Find More Posts by specofdust |
|
|
#8 | |
|
Mod Master
Join Date: Mar 2005
Location: Aberdeen, Scotland
Posts: 2,088
![]() |
NoScript is a great extension for FF which should help with this issue.
Its basically white-listing for javascripts. You only run the ones from site you trust.
__________________
Laptop:C2D P8600 2.4GHz, 4GB, 9800GTS, 120GB SSD, 15" 1680x1050, Vista64 Projects: 1.2TB Fileserver housed in a cardboard box!|Retro HTPC for my GF. Quote:
|
|
|
|
|
|
|
#9 | |
|
What owl?
Join Date: May 2005
Location: Edinburgh
Posts: 3,986
![]() ![]() ![]() |
Quote:
__________________
No boom today, boom tomorrow... there's always a boom tomorrow. |
|
|
|
|
| steveo_mcg |
| View Public Profile |
| Find More Posts by steveo_mcg |
|
|
#10 | |
|
Minimodder
Join Date: May 2004
Location: Oxford, UK
Posts: 43
![]() |
Quote:
|
|
|
|
|
|
|
#11 |
|
Minimodder
Join Date: Jan 2006
Location: Loughborough, UK
Posts: 44
![]() |
Given that the problem is a stack overflow, wouldn't turning on DEP (in Windows) or the appropriate feature for every other program prevent this from actually working? Assuming that a stack overflow is similar to a buffer overflow, which is what Data Execution Prevention is meant to prevent.
|
|
|
|
| Laitainion |
| View Public Profile |
| Find More Posts by Laitainion |
|
|
#12 |
|
Hypermodder
Join Date: Jun 2004
Location: Cleveland, OH
Posts: 672
![]() |
At first glance I would have to call BS, since it's not possible for something to be "impossible to patch." It just doesn't make sense. Yes, difficult, perhaps not feasible in the face of a complete rewrite, but impossible? What?
Without knowing the details of this exploit, which I'm too lazy to look into, I can't say anything assuredly. However I'd like to point out that just because an exploit exists, doesn't mean it's ever been used or that your previous browsing experiences haven't been more secure for using Firefox. Afterall, if the exploit was just recently discovered, and is quickly patched, what's the harm? I'm sure pro-MS zealots will use this as ammo against Mozilla, which I think is just a mistake. As is so often pointed out, it's not just the issue of exploits, but how well known they are and how quickly they are patched. OSS has a much better history of that than Microsoft. Oh, and for the record, I'm not some anti-MS or Linux zealot. MS makes some great products. .NET is completely amazing. I use Ubuntu Server on my personal web server and XP for all my workstations. Just trying to put myself in the clear to avoid possible derailination of this thread.
|
|
|
|
|
|
#13 |
|
rox
Join Date: Apr 2003
Location: /home
Posts: 2,696
![]() |
Window Snyder is the best name ever.
|
|
|
|
|
|
#14 |
|
I pwn all your storage
Join Date: Jul 2005
Location: Southampton
Posts: 13,933
![]() ![]() ![]() ![]() |
There's a difference between patching and rewriting the javascript implementation, since this appears to be a fundamental flaw, its like having a problem with research, you have to restart from the beginning.
|
|
|
|
|
|
#15 |
|
Multimodder
Join Date: Nov 2004
Location: uk
Posts: 131
![]() |
Interesting article..
There is an interesting article at http://arstechnica.com/news.ars/post/20060925-7818.html. Looks like opera is the clear winner, although not perfect.
|
|
|
|
| trailblazer |
| View Public Profile |
| Find More Posts by trailblazer |
|
|
#16 |
|
Can't mod my way out of a paper bag
Join Date: Aug 2005
Location: Bellingham, WA
Posts: 4,473
![]() |
Sounds to me like growing pains in the open source community. They have gone from being a nieche product to mainstream and are having trouble adjusting to all the attention, both from users and from attackers. I think in the end Open source is the best model for software develpment, especially from a security standpoint, but because of it's more diffuse organization it will take longer for the development base to change and adapt.
__________________
Notice: If we see you flaming we will assume you are on fire and take appropriate measures
- The Bit-Tech Fire Brigade. |
|
|
|
|
|
#17 |
|
Multimodder
Join Date: Nov 2004
Location: uk
Posts: 131
![]() |
Firefox...
The general perception was that while Firefox had a small user base it would be left alone by hackers, but, if/when it started to become popular they would look for vulnerabilitys in the software. Looks like they are tearing it to bits, worse still, saying that the code is a mess and may be a challenge to fix. Until then,I will use Opera, if it works and is reasonably secure, that's fine by me. I am no fan of any particular web browser.
|
|
|
|
| trailblazer |
| View Public Profile |
| Find More Posts by trailblazer |
|
|
#18 |
|
Hypermodder
Join Date: Oct 2003
Location: sadffffff
Posts: 676
![]() |
as much as i would love to point at this and be all like "hahahah, take that firefox fanboys, browser's not so secure now is it!" i really cant. i mean, my attitude has always been, "youre too paranoid" these exploits will never get you unless youre visiting some very questionable sites... IE hasnt failed me yet. never get any adware/spyware/viruses etc etc.. just be carefull and about any browser will work, despite SECURITY ISSUES OMG NO!!! so basically, meh...
i assume that by "unpatchable" they mean that patching it would actually have to be a total rewrite.. like the way they implemented java is wrong in the way they wrote it, so to fix it they have to write it differently. |
|
|
|
|
|
#19 |
|
Multimodder
Join Date: Feb 2006
Location: Surrey, UK
Posts: 248
![]() |
I have never faced any of these kind of attacks with any browser. I really don't see where the attacks come from because I don't know of anyone who has been attacked. Even if hackers write the attacks, who is going to use them? Any sites that wish to cause harm will still be attacking IE becuase it is used by more people. Added to that, the type of people who use FF are more careful in their browsing habits anyway. Technology isn't the only factor to consider when looking at security. The human side of things is much more important.
|
|
|
|
|
|
#20 |
|
Supermodder
Join Date: Apr 2006
Location: US Memphis, TN
Posts: 292
![]() |
if i turn off javascript, how will that affect my browsing?
__________________
My gun kata is greater than your kung fu.
|
|
|
|
| Lazarus Dark |
| View Public Profile |
| Find More Posts by Lazarus Dark |
![]() |
| Thread Tools | |
|
|