Serious Firefox Vulnerability Leaked

Discussion in 'Serious' started by quack, 9 May 2005.

  1. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
    Original Exploit Discovery

    The Mozilla Team and Greyhats Security wanted to keep this one under wraps till a fix was available, but as usual the best laid plans etc.

    Now the world knows, and how long before unsuspecting people get caught out?

    Thankfully, Mozilla have made some changes to their Addons website so that the official site can no longer be involved, but if you add another site (such as extensionmirror) to your whitelist you can be hacked.

    Secunia has this to report.

    Firefox 1.0.4 will be on its way soon, but before that comes out, if you remove all entries from your whitelist apart from addons.mozilla.org then you should be safe - or you can disable "Allow websites to install software".
     
  2. Herbicide

    Herbicide Lurktacular

    Joined:
    27 May 2004
    Posts:
    1,533
    Likes Received:
    17
    mmm... whitelist clearing it is then.

    - H.
     
  3. TheAnimus

    TheAnimus Banned

    Joined:
    25 Dec 2003
    Posts:
    3,214
    Likes Received:
    8
    intresting, seams FF needs to have a fuller version of proccess management that is present, either that or virus scanners need to start checking for malicous code in add-ins.

    a lot of network admins allow people to customise FF, including addins, i wounder how many pay propper attention to the fact their letting (often idoits) install programs, same goes with konfabulator. Once again, i doubt the virus scanners bother to scan them.
     
  4. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
  5. RotoSequence

    RotoSequence Lazy Lurker

    Joined:
    6 Jan 2004
    Posts:
    4,588
    Likes Received:
    7
    All fixed :D
     
  6. Dodge

    Dodge What's a Dremel?

    Joined:
    10 Oct 2003
    Posts:
    1,184
    Likes Received:
    0
    English English 1.0.4
    English (British) English (British) 1.0.3

    :eyebrow:
     
  7. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
    It always takes a few days for the British release. I'm not entirely sure what they change, apart from where it says en-US to en-GB, and us ending up on Google UK instead. Can't be that hard really, can it?
     
  8. Henchman:crg

    Henchman:crg What's a Dremel?

    Joined:
    9 Feb 2005
    Posts:
    749
    Likes Received:
    0
    British 1.0.4 is now there.
    I'm using it right now :D
     
  9. quack

    quack Minimodder

    Joined:
    6 Mar 2002
    Posts:
    5,240
    Likes Received:
    9
    Cheers for the update! Downloading now!!
     
  10. Henchman:crg

    Henchman:crg What's a Dremel?

    Joined:
    9 Feb 2005
    Posts:
    749
    Likes Received:
    0
    Hey, you know when Firefox is getting as popular as IE, when you get weekly updates :hehe:
     

Share This Page