• Welcome to DNForum.com - Domain Investor Forum, Free Domain Marketplace and a community for 45+ domain pros
    If you are new to domains and looking to buy, sell and learn about domains then you have come to the right place. DNForum is the oldest global domain name community on the internet and continues to grow every day. There are over 45,000 domainers on DNForum doing everything from buying domains, selling domains, using our free in-house built tools, learning about domains and discussing domains. Take a minute and Register.

For firefox users

Status
Not open for further replies.

stevey

DNF Regular
The Originals
Legacy Exclusive Member
Joined
Aug 23, 2004
Messages
679
Reaction score
0
Description:
Two vulnerabilities have been discovered in Firefox, which can be exploited by malicious people to conduct cross-site scripting attacks and compromise a user's system.

1) The problem is that "IFRAME" JavaScript URLs are not properly protected from being executed in context of another URL in the history list. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site.

2) Input passed to the "IconURL" parameter in "InstallTrigger.install()" is not properly verified before being used. This can be exploited to execute arbitrary JavaScript code with escalated privileges via a specially crafted JavaScript URL.

Successful exploitation requires that the site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org").

A combination of vulnerability 1 and 2 can be exploited to execute arbitrary code.

NOTE: Exploit code is publicly available.

The vulnerabilities have been confirmed in version 1.0.3. Other versions may also be affected.

Solution:
Disable JavaScript.
 
This sucks, Almostall my sites use Javascript,any idea when there will be a fix for this? I cant turn off javscript as it will really cause problems to how I run my sites.
 
The good news is that those vulnerabilities are very "exotic" and require a rare number of events to coincede. Also, the Mozilla team is quick in acknowledging and addressing them with updates/fixes. Compare this to Microsloth that can take months without as much as a hotfix.
 
RADiSTAR said:
The good news is that those vulnerabilities are very "exotic" and require a rare number of events to coincede. Also, the Mozilla team is quick in acknowledging and addressing them with updates/fixes. Compare this to Microsloth that can take months without as much as a hotfix.
lmao...Microsloth...haha never heard of that one before. :p
 
:-D

Regardless, I use Winblows.
 
Thanks for the information. Although I keep using firefox. I'm sure they'll bring out a fix very soon?.
 
Kishin said:
This sucks, Almostall my sites use Javascript,any idea when there will be a fix for this? I cant turn off javscript as it will really cause problems to how I run my sites.
Don't worry, people will disable Firefox rather than Javascript. ;)
 
Status
Not open for further replies.
Back
Top Bottom