Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

For you Mozilla Firefox users...

Thread Tools
 
Search this Thread
 
Old 30 July 2004, 10:57 AM
  #1  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default For you Mozilla Firefox users...

... http://bugzilla.mozilla.org/show_bug.cgi?id=244965

Hope you can understand what's going on.
Old 30 July 2004, 11:11 AM
  #2  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

Doesn't seem to be a big issue. . . a javescript that can show passwords that are entered into a box? Surely only an issue if a site has been hijacked?

Or did i miss the point?


Originally Posted by JackClark
... http://bugzilla.mozilla.org/show_bug.cgi?id=244965

Hope you can understand what's going on.
Old 30 July 2004, 11:32 AM
  #3  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

DESCRIPTION:
A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface.

The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface
Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees.

The Mozilla user interface is built using XUL files.

A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website.

This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected.
Old 30 July 2004, 11:42 AM
  #4  
chiark
Scooby Regular
 
chiark's Avatar
 
Join Date: Jun 2000
Posts: 13,735
Likes: 0
Received 0 Likes on 0 Posts
Default

I can't work out if this is potentially very serious (ie whole UI hijack) or trivial. I also can't see if the patch is available for download, although the code change looks extremely simple
Old 30 July 2004, 11:49 AM
  #5  
JackClark
Scooby Senior
Thread Starter
 
JackClark's Avatar
 
Join Date: Dec 2000
Location: Overdosed on LCD
Posts: 20,852
Received 51 Likes on 34 Posts
Default

That's the problem. How can I recommend software like this to my mother when I don't understand what's going on, if it'll be fixed and when.
Old 30 July 2004, 12:25 PM
  #6  
BlkKnight
Scooby Regular
 
BlkKnight's Avatar
 
Join Date: Feb 2004
Location: High Wycombe
Posts: 3,763
Likes: 0
Received 0 Likes on 0 Posts
Default

it would seem to be a problem if a site (or a PC) has already been compromised.

The flaw on it's own is isn't a problem - unless you are a victim of phishing
Old 30 July 2004, 03:37 PM
  #7  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Default

Originally Posted by JackClark
That's the problem. How can I recommend software like this to my mother when I don't understand what's going on, if it'll be fixed and when.
I'd be far more worried if she's still using IE.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
alcazar
Computer & Technology Related
12
29 September 2015 01:44 PM
alcazar
Computer & Technology Related
7
17 September 2015 10:08 PM
farmerwrx
Computer & Technology Related
14
10 September 2015 11:59 AM
slimtim
Computer & Technology Related
10
09 September 2004 02:39 PM



Quick Reply: For you Mozilla Firefox users...



All times are GMT +1. The time now is 03:43 AM.