PDA

View Full Version : Mozilla / Mozilla Firefox Download Dialog Source Spoofing


ronjor
January 4th, 2005, 10:56 AM
-{ Quote: "Secunia Research has discovered a vulnerability in Mozilla / Mozilla Firefox, which can be exploited by malicious people to spoof the source displayed in the Download Dialog box. Do not follow download links from untrusted sources." }-
Secunia (http://secunia.com/advisories/13599/)

ronjor
January 7th, 2005, 02:50 PM
Firefox flaw raises phishing fears

INFO (http://news.zdnet.com/Firefox+flaw+raises+phishing+fears/2100-1009_22-5517149.html?part=rss&tag=feed&subj=zdnn)

lynchknot
January 7th, 2005, 03:11 PM
Thanks for the "heads up".

I suppose there are those that will click anything - however this is a low level "less critical" rating. Bug Filed (https://bugzilla.mozilla.org/show_bug.cgi?id=275417)

-{ Quote: " To fall victim to such a scam, a Firefox user would have to click on a link in an e-mail that pointed to a spoofed Web site and then download malicious software from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia. " }-

IE phish hole as well (http://news.zdnet.com/2100-1009_22-5495719.html)