Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

For you Mozilla Firefox users...

Thread Tools
 
Search this Thread
 
Old Jul 30, 2004 | 10:57 AM
  #1  
JackClark's Avatar
JackClark
Thread Starter
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Default For you Mozilla Firefox users...

... http://bugzilla.mozilla.org/show_bug.cgi?id=244965

Hope you can understand what's going on.
Reply
Old Jul 30, 2004 | 11:11 AM
  #2  
BlkKnight's Avatar
BlkKnight
Scooby Regular
 
Joined: Feb 2004
Posts: 3,763
Likes: 0
From: High Wycombe
Default

Doesn't seem to be a big issue. . . a javescript that can show passwords that are entered into a box? Surely only an issue if a site has been hijacked?

Or did i miss the point?


Originally Posted by JackClark
... http://bugzilla.mozilla.org/show_bug.cgi?id=244965

Hope you can understand what's going on.
Reply
Old Jul 30, 2004 | 11:32 AM
  #3  
JackClark's Avatar
JackClark
Thread Starter
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Default

DESCRIPTION:
A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface.

The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface
Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees.

The Mozilla user interface is built using XUL files.

A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website.

This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected.
Reply
Old Jul 30, 2004 | 11:42 AM
  #4  
chiark's Avatar
chiark
Scooby Regular
 
Joined: Jun 2000
Posts: 13,735
Likes: 0
Default

I can't work out if this is potentially very serious (ie whole UI hijack) or trivial. I also can't see if the patch is available for download, although the code change looks extremely simple
Reply
Old Jul 30, 2004 | 11:49 AM
  #5  
JackClark's Avatar
JackClark
Thread Starter
Scooby Senior
25 Year Member
Liked
Loved
Community Favorite
 
Joined: Dec 2000
Posts: 20,896
Likes: 53
From: Overdosed on LCD
Default

That's the problem. How can I recommend software like this to my mother when I don't understand what's going on, if it'll be fixed and when.
Reply
Old Jul 30, 2004 | 12:25 PM
  #6  
BlkKnight's Avatar
BlkKnight
Scooby Regular
 
Joined: Feb 2004
Posts: 3,763
Likes: 0
From: High Wycombe
Default

it would seem to be a problem if a site (or a PC) has already been compromised.

The flaw on it's own is isn't a problem - unless you are a victim of phishing
Reply
Old Jul 30, 2004 | 03:37 PM
  #7  
stevencotton's Avatar
stevencotton
Scooby Regular
 
Joined: Jan 2001
Posts: 2,710
Likes: 1
From: behind twin turbos
Default

Originally Posted by JackClark
That's the problem. How can I recommend software like this to my mother when I don't understand what's going on, if it'll be fixed and when.
I'd be far more worried if she's still using IE.
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
alcazar
Computer & Technology Related
12
Sep 29, 2015 01:44 PM
alcazar
Computer & Technology Related
7
Sep 17, 2015 10:08 PM
farmerwrx
Computer & Technology Related
14
Sep 10, 2015 11:59 AM
slimtim
Computer & Technology Related
10
Sep 9, 2004 02:39 PM




All times are GMT +1. The time now is 02:56 AM.