Dino 的个人资料This is it照片日志列表更多 工具 帮助

日志


2月15日

Browser beware: Unpatched holes in Firefox, IE 7

Pick a blog category Uncategorized Patch Watch Hackers Zero-day attacks Apple Microsoft Windows Vista Browsers Oracle Cisco Rootkits Vulnerability research Punditocracy Responsible disclosure Spam and Phishing Spyware and Adware Botnets Exploit code Black Hat Viruses and Worms Piracy Data theft Open source Pen testing Digital rights management Mozilla
February 15th, 2007

Browser beware: Unpatched holes in Firefox, IE 7

Posted by Ryan Naraine @ 12:31 pm Categories: Patch Watch, Hackers, Zero-day attacks, Microsoft, Browsers, Vulnerability research, Responsible disclosure, Exploit code, Viruses and Worms, Open source, Mozilla
 

Firefox and Internet Explorer users beware: There are serious, unpatched flaws in both browsers that could allow the manipulation of authentication cookies and the hijacking of files from your Windows machine.

Details on both vulnerabilities have already been posted to the Full Disclosure mailing list by Polish researcher Michal Zalewski. SecurityFocus provides coverage of the issue, which dates back to 2006.

According to Zalewski, a well-known hacker credited with several major flaw discoveries, there are two very different issues affecting Firefox and IE 7.

First up is a brand-new IE 7 bug that could be used to divert keystrokes from Web-based games, blog entries and comment forms, online chats. In certain scenarios, an attacker could exploit the flaw to read sensitive local files on a computer. “Some user interaction is required, but only to an extent commonly expected on some popular Web site. XSS attacks make it far worse,” Zalewski said.

Click here for an online demonstration of the IE 7 (and prior) vulnerability.

Firefox 1.5 and 2.0 users can test for the flaw here.

Separately, Zalewski also warned about a new bug in the way Firefox handles writes to the ‘location.hostname’ DOM property. The bug could allow for the browser to appear as if were connecting to a bank, when in fact it would instead be receiving data from a bad guy, according to a note on the F-Secure blog.

Click here for a demo of the Firefox 2.0.01 bug, which requires JavaScript. Mozilla’s security response team is already working on a patch.

I have a query in to Microsoft for a comment on the IE 7 issue. Will update as necessary.

评论

请稍候...
很抱歉,您输入的评论太长。请缩短您的评论。
您没有输入任何内容,请重试。
很抱歉,我们当前无法添加您的评论。请稍后重试。
若要添加评论,需要您的家长授予您相应权限。请求权限
您的家长禁用了评论功能。
很抱歉,我们当前无法删除您的评论。请稍后重试。
您已超过了一天之内允许提供的评论数上限。请在 24 小时后重试。
因为我们的系统表明您可能在向其他用户提供垃圾评论,您的帐户已禁用了评论功能。如果您认为我们错误地禁用了您的帐户,请联系 Windows Live 支持部门
完成下面的安全检查,您提供评论的过程才能完成。
您在安全检查中键入的字符必须与图片或音频中的字符一致。

若要添加评论,请使用您的 Windows Live ID 登录(如果您使用过 Hotmail、Messenger 或 Xbox LIVE,您就拥有 Windows Live ID)。登录


还没有 Windows Live ID 吗?请注册

引用通告

此日志的引用通告 URL 是:
http://nolie2.spaces.live.com/blog/cns!74B4AA1F43D99723!321.trak
引用此项的网络日志