The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Researcher: Firefox vulnerable to ID spoofing
Time: 12:45 EST/17:45 GMT | News Source: ZDNet | Posted By: Jonathan Tigner

Firefox 2.0 has a vulnerability that can leave its users susceptible to an identity theft attack, according to Aviv Raff, a security researcher based in Israel.

Raff outlined a bug in Firefox that allows spoofing and enables an attacker “to conduct phishing attacks, by tricking the user to believe that the authentication dialog box is from a trusted website.” The versions affected include Firefox v2.0.0.11 and prior versions. Ryan Naraine got a private demo of Raff’s work and noted that this attack is easy to fall for.

Write Comment
Return to News

  Displaying 1 through 25 of 324
Last | Next
  The time now is 1:53:16 PM ET.
Any comment problems? E-mail us
#1 By 3653 (65.80.181.153) at 1/3/2008 8:50:52 PM
"a safer way to browse the web"

#2 By 37047 (99.241.37.218) at 1/3/2008 10:29:11 PM
#1: Yes, because Mozilla won't make us wait for some random "Patch Tuesday" for an update that fixes the problem. We will have a fix pushed out to us as soon as it is ready, and not held onto until the next official patch cycle.

#3 By 3653 (65.80.181.153) at 1/3/2008 10:57:53 PM
"some random Patch Tuesday"

Is 'every second tuesday of the month' really so random?

"We will have a fix pushed out to us as soon as it is ready"

I'm reminded of those long lists of firefox bugs that notparker has shown us. "as soon as it is ready" too often means "never" in the firefox world.

mystic, what company in their right mind would PREFER the haphazard mozilla patch scheduling (lack of) compared to a normal regular schedule (patch tuesday)?

This post was edited by mooresa56 on Thursday, January 03, 2008 at 23:00.

#4 By 2960 (72.196.195.185) at 1/4/2008 7:59:18 AM
I have YET to see a drive-by spyware install completed under FireFox.

I still consider this the biggest problem with IE.

TL

#5 By 37047 (216.191.227.68) at 1/4/2008 8:34:54 AM
#3: By "random Patch Tuesday", I meant exactly what I said. With an IE patch, you might get it the next Patch Tuesday, the one after that, the one after that one, etc. A random one. Thus, "random Patch Tuesday" does not equal "some random Tuesday, which might or might not be a Patch Tuesday". Learn to parse better before making asinine statements.

"I'm reminded of those long lists of firefox bugs that notparker has shown us. "as soon as it is ready" too often means "never" in the firefox world."

Of course, in the IE world, you never even find out about it until the patch is ready, so bugs lay undisclosed and unfixed for months and even years, some never getting fixed at all, due to the lack of importance Microsoft places on IE and the IE users. Heck, Microsoft didn't even care about making IE 7 until Firefox woke them up by stealing 10+% of the IE market share.

#6 By 15406 (216.191.227.68) at 1/4/2008 10:47:55 AM
#3: I'm reminded of those long lists of firefox bugs that notparker has shown us.

You're reminded of things that never happened? The best that parkkker can do is offer up a bug or two, usually something ancient that has long since been fixed, or something so insignificant that nobody cares about.

Why are you even commenting on this? Shouldn't you be in full apologist mode, busily crafting a response to the critical bug in Vista that allows remote code execution? Luckily it's being patched this Tuesday, but who knows what other hole the patch will open? And weren't you one of the Ketchum Kidz that claimed Vista would never fall victim to a remote code execution bug due to Vista's security awesomeness?

#7 By 92283 (64.180.196.143) at 1/4/2008 12:17:29 PM
The last critical security patch for Firefox was 2007-35

http://www.mozilla.org/security/announce/2007/mfsa2007-35.html

https://bugzilla.mozilla.org/show_bug.cgi?id=387881

It only took them 3 months to figure out this bug this fix was needed because of another bug - 369211.

Unfortunately, that bug is EMBARGOED.

You are not authorized to access bug #369211.

https://bugzilla.mozilla.org/show_bug.cgi?id=369211

So much for OPEN!

This post was edited by NotParkerToo on Friday, January 04, 2008 at 12:18.

#8 By 92283 (64.180.196.143) at 1/4/2008 12:35:49 PM
Then there is the next critical security bug: 2007-29

http://www.mozilla.org/security/announce/2007/mfsa2007-29.html

It leads to: https://bugzilla.mozilla.org/buglist.cgi?bug_id=309322,330563,341858,344064,348126,354645,361745,362901,378670,378682,379799,382376,384105,386382,386914,387033,387460,387844,391974,392285,393770,394014,394418

1st in the long list: https://bugzilla.mozilla.org/show_bug.cgi?id=309322

2005-09-20

TWO YEARS to fix

Would the asshats please now shut up.


#9 By 15406 (216.191.227.68) at 1/4/2008 12:55:16 PM
#7: As usual ad infinitum, you're referencing FF bugs that have already been fixed.

So much for OPEN!

When you come to a closed, unlocked door, you still have to turn the knob to get in. Did you login with your Bugzilla account to see that bug you're complaining about? Yo know, the free account that you've been told about many times before but for some reason still can't get your head around? That free account? Man, you can lead a fool to ActiveWin but you can't make him think.

#8: Hmm, all I see in that list you linked to are a bunch of fixed bugs.

It certainly is funny how FF can go 2 years without fixing a bug and it's STILL more secure than IE.

#10 By 92283 (64.180.196.143) at 1/4/2008 1:11:51 PM
Tsk tsk. Trying to change the rules Asshat.

You stated "The best that parkkker can do is offer up a bug or two, usually something ancient that has long since been fixed, or something so insignificant that nobody cares about. "

1) Both are critical.
2) They are not ancient. They are the two most recent critical fixes.

You, as usual, are a loser.

#11 By 37047 (99.241.37.218) at 1/4/2008 6:49:08 PM
Parker:

Why not do something useful, like showing us a few bugs that are a year or two old, that is critical or higher, and still unresolved. That would be far more useful to your argument than simply showing bug reports that are marked as fixed. And while you're at it, how about showing us how much more secure IE is by giving us a link to the Microsoft bug tracking system, so we can see how IE has fewer outstanding bugs, and how there are no open bugs that are 1+ years old and still unresolved?

I won't be holding my breath waiting for that Microsoft defect tracking system link.

#12 By 3653 (65.80.181.153) at 1/4/2008 7:53:57 PM
lol. you guys are hillarious. Why not change the subject a few more times.

"It certainly is funny how FF can go 2 years without fixing a bug"

Friend, there's nothing "funny" about that.

#13 By 92283 (64.180.196.143) at 1/4/2008 10:11:55 PM
#11 https://bugzilla.mozilla.org

I found 1630 Unconfirmed Critical bugs without resolution. Some are 5 or 6 years old.

I tried the Advanced Search and found 736 NEW Critical bugs with the word Crash in them meaning they potentially could allow code excution.

I'm sure hackers are working their way through the new ones right now looking for ones to exploit.


#14 By 3653 (65.80.181.153) at 1/5/2008 4:11:05 PM
[cricket chirp]

#15 By 15406 (216.191.227.68) at 1/7/2008 9:29:25 AM
#13: And yet, through all those myriad bugs, FF was still only exposed to critical bugs for 9 days last year, compared to IE's 200+ days. Funny how the world works, isn't it?

#16 By 92283 (64.180.196.143) at 1/7/2008 10:05:44 AM
Latch, see #8.

The bug was two years old when fixed.

You lied.

#17 By 3653 (65.80.181.153) at 1/8/2008 3:17:45 PM
latch is using dog years, where 9 days = 2 years.

#18 By 563062 (70.32.38.83) at 7/13/2011 11:01:40 PM
http://www.anydress.co.uk/quinceanera-dress-function-occasion.html quinceanera dress http://www.anydress.co.uk/prom-dress-function-occasion.html prom dresses http://www.anydress.co.uk/prom-dress-function-occasion.html formal prom dresses http://www.anydress.co.uk/celebrity-dress-function-occasion.html celebrity maternity dresses http://www.anydress.co.uk/quinceanera-dress-function-occasion.html quinceanera dresses

#19 By 563062 (70.32.38.83) at 7/13/2011 11:04:00 PM
http://www.beeweddingdress.com/evening.html prom evening dresses http://www.beeweddingdress.com/evening.html evening dress http://www.beeweddingdress.com/bridal-party-flower-girls.html flower girl dresses http://www.beeweddingdress.com plus size dresses http://www.beeweddingdress.com/prom.html bridesmaid prom dresses http://www.beeweddingdress.com/accessories-headpieces.html wedding headpieces http://www.beeweddingdress.com/bridal-party.html party dress http://www.beeweddingdress.com/bridal-party.html bridal party http://www.beeweddingdress.com/evening.html cheap evening dresses

#20 By 4240821 (213.139.195.162) at 10/27/2023 6:04:56 AM
https://sexonly.top/get/b885/b885usqtrsqvieonpmy.php
https://sexonly.top/get/b404/b404qieqqmsamdtpjkd.php
https://sexonly.top/get/b422/b422vevqyaynvkgmhyg.php
https://sexonly.top/get/b950/b950udduzittrpexcfb.php
https://sexonly.top/get/b17/b17enjjprdxmveaooa.php
https://sexonly.top/get/b672/b672hciihaaxkouogvz.php
https://sexonly.top/get/b950/b950psyrlwclzzqrvrn.php
https://sexonly.top/get/b98/b98lacmocbdldtsqlg.php
https://sexonly.top/get/b16/b16bewyigraqcizrhx.php
https://sexonly.top/get/b653/b653rgejbeshztzlopo.php
https://sexonly.top/get/b431/b431orvddvrslirybmp.php
https://sexonly.top/get/b827/b827azwqnqgamxkdglg.php
https://sexonly.top/get/b540/b540vbhojwhbrgbruap.php
https://sexonly.top/get/b831/b831kklaswurzxnwlvp.php
https://sexonly.top/get/b292/b292hebggwcmwgjinwf.php
https://sexonly.top/get/b157/b157qclthxilrfcxdjl.php
https://sexonly.top/get/b572/b572wbpaetuxhhgzxqt.php
https://sexonly.top/get/b68/b68dvblxsthpxhnkjy.php
https://sexonly.top/get/b421/b421zircevajkwfzacm.php
https://sexonly.top/get/b861/b861jtknpalqotqfbya.php
https://sexonly.top/get/b889/b889ijlbtokmsihaljb.php
https://sexonly.top/get/b335/b335zhobrgqhwxyebpk.php
https://sexonly.top/get/b74/b74qlbscttuvrypfsz.php
https://sexonly.top/get/b378/b378cdxyohugfntmvvb.php
https://sexonly.top/get/b78/b78bixlxilrnstyego.php
https://sexonly.top/get/b702/b702ueqsnxailcaadzs.php
https://sexonly.top/get/b305/b305mokfhoyzlfkeqrz.php
https://sexonly.top/get/b323/b323bdouvasaszrwfao.php
https://sexonly.top/get/b32/b32wmiwscebpcddqyf.php
https://sexonly.top/get/b190/b190dmrcgdstrwlvbyc.php
https://sexonly.top/get/b406/b406tzpvzbowdhtigpz.php
https://sexonly.top/get/b244/b244zizhfhkccoxrdtr.php
https://sexonly.top/get/b532/b532ojjfnegddvqvgah.php
https://sexonly.top/get/b270/b270yihvqxmkqevjbdn.php
https://sexonly.top/get/b474/b474jelfgylmkzxicnp.php
https://sexonly.top/get/b686/b686rqepqtrfjthdtql.php
https://sexonly.top/get/b660/b660watgejlsxjyyoax.php
https://sexonly.top/get/b264/b264hechiayzwvxtasq.php
https://sexonly.top/get/b993/b993ewvmtxhehmwkbbx.php
https://sexonly.top/get/b23/b23yskszyqscqyrvco.php
https://sexonly.top/get/b186/b186wltalfxtlbzlbvn.php
https://sexonly.top/get/b71/b71cqkmfswwmehdfbo.php
https://sexonly.top/get/b425/b425ienjqscphcpfrdc.php
https://sexonly.top/get/b736/b736afzlcyezixnqbiu.php
https://sexonly.top/get/b354/b354uzbfojrvjvxhblp.php
https://sexonly.top/get/b624/b624lynegvjdujseech.php
https://sexonly.top/get/b654/b654iakvjbadjlswbgm.php
https://sexonly.top/get/b465/b465tiunhtgjkiasjpv.php
https://sexonly.top/get/b125/b125jyktbqwpzwzwniw.php
https://sexonly.top/get/b72/b72nwwjnagqmzcmllj.php

#21 By 4240821 (103.151.103.150) at 10/30/2023 4:12:40 PM
https://www.quora.com/profile/RhondaSmith234/francesca-felucci-BlueGirlXOXO-LudoAndVika-Sophia-Jade-Texasgirl91-Moonbaby8992-eden-west-angel496-Queen
https://www.quora.com/profile/KristenDavila285/keith_0609-SlumalienB-taraSpankalicious-Brooke-Brewy-Kissplum-Sugary-Tits-casperquartz-Bunnyxl19-bunnicu
https://www.quora.com/profile/InicioKadlec935/aikanoheya-VictoriaDivine-Veronica-Maxxxim-Shadowknight521-kruexgore-Emoliente18-Briannacastillo5-Bree-Win
https://www.quora.com/profile/JohnJeppi252/HarleyQute-No07names-Chubbyprincess222-victoria-villarim-Lyla_Bliss-Bebe-Minou-yomysmilkers-TsunTsenpai
https://www.quora.com/profile/NicoleVenkatesh512/WinterEstelle-crystal3332804-novasinsane-Katykoxxxtx-lisacdere-MissLilahLove-smuttpuppy-SaccharoseDaddy
https://www.quora.com/profile/JuniorPartybus598/Hasanati-dani-bananinha-1-KookiieSoWet-Droplet420-MangosKiss-YUKADOTA-Sugarcoral-MissFernanda-Lorena-Aqu
https://www.quora.com/profile/SueSharma640/Lizlilith-Anya-Cullen-Delia-DGAF-Roxximaroon-AltErnativeWaifu-Biinks-Emoni-Brown-tinytoesXO-camila-bello
https://www.quora.com/profile/ScottDimatulac721/Bxddie-Bangs-aya-nanjo-Curvyelvishgirl-Laylah-Diamond-Nora-Sparkle-yoursnowbunny-Kara-Kane-silvia-grisso
https://www.quora.com/profile/KateJensen915/Toxicouple-Tcope654-ScarlettMaddison-Scorpioveronica-Listen-and-Talk-vanessaplays-ingridhaze420-Qunistars
https://www.quora.com/profile/AnnieSchneider430/Luna-Villa-emmyamelia_xx-Beautii212-Misty_Phoenix-Hornygermans-white_mexican-twicexxbitten-VictoriaVega

#22 By 4240821 (103.152.17.80) at 10/31/2023 7:04:04 AM
https://app.socie.com.br/read-blog/98270
https://app.socie.com.br/read-blog/97425
https://app.socie.com.br/Amethyst16liciousgia
https://app.socie.com.br/RezidentyPornocamilapasion
https://app.socie.com.br/read-blog/97321
https://app.socie.com.br/read-blog/97399
https://app.socie.com.br/read-blog/97681
https://app.socie.com.br/read-blog/98292
https://app.socie.com.br/SamanthavideosDixielynn2919
https://app.socie.com.br/itsbambibaoRoachWitch

#23 By 4240821 (103.151.103.150) at 10/31/2023 6:15:33 PM
https://app.socie.com.br/read-blog/97532
https://app.socie.com.br/read-blog/98203
https://app.socie.com.br/PregnantPeachesTarkustrooper
https://app.socie.com.br/read-blog/98874
https://app.socie.com.br/teenc0upleSamanthaJhonnson
https://app.socie.com.br/CharmshyPrincessVinaKai
https://app.socie.com.br/read-blog/97517
https://app.socie.com.br/read-blog/97652
https://app.socie.com.br/TauryelHerekitty
https://app.socie.com.br/cutekitten23SpankMyFeet

#24 By 4240821 (62.76.146.75) at 11/1/2023 9:39:15 AM
http://activewin.com/mac/comments.asp?ThreadIndex=18768&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=62377&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=3145&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=9830&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=943&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=24125&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=75388&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=40136&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=2303&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=7748&Group=Last

#25 By 4240821 (2.57.151.31) at 11/2/2023 5:57:12 AM
http://activewin.com/mac/comments.asp?ThreadIndex=29263&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=82268&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=22153&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=83189&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=21860&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=7128&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=72636&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=71470&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=66085&Group=Last
http://activewin.com/mac/comments.asp?ThreadIndex=49572&Group=Last

Write Comment
Return to News
  Displaying 1 through 25 of 324
Last | Next
  The time now is 1:53:16 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *