Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old November 21st, 2006, 07:46 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,365
Default Firefox 2.0 Password Manager Bug Exposes Passwords

Quote:
"Today, Mozilla made public bug #360493, which exposes Firefox's Password Manager on many public sites. The flaw derives from Firefox's willingness to supply the username and password stored on one page on a domain to another page on a domain.
Story
  #2  
Old November 25th, 2006, 11:36 AM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

This is quite a serious bug, not? And is it that hard to avoid these kind of programming errors?
  #3  
Old November 26th, 2006, 04:50 AM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

I think you can set firefox to not remember any passwords and other personal details etc etc....
  #4  
Old December 9th, 2006, 05:04 AM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

But does it affect my passwords if I have installed Firefox in my computer, but I use Internet Explorer for sites with password?
  #5  
Old December 9th, 2006, 10:25 AM
Robyn's Avatar
Robyn Robyn is offline
Very Frequent Poster
 
Join Date: Feb 2004
Posts: 1,189
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

If you are running IE7 it is open to the flaw too
Quote:
Both the Mozilla Foundation's Firefox 2 and Microsoft's Internet Explorer 7 web browsers are vulnerable to a flaw that could allow attackers to steal passwords.
http://news.zdnet.co.uk/security/0,1...9284818,00.htm
__________________
Vista-XP forum - xpforum - Windows XP - Vista - HijackThis support
  #6  
Old December 14th, 2006, 10:25 AM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

But if I use Internet Explorer 6, then my passwords are secure? So I should not download Internet Explorer 7?

I downloaded Mozilla Firefox 2.0 but I never used it because I saw this topic. But during installation process it asked if I would transfer information to Mozilla Firefox 2.0 from Internet Explorer. I did and now I have a fear that one password that was saved to remember in Internet Explorer is now known to some other person.
  #7  
Old December 14th, 2006, 11:13 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,467
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Hello,
No need to worry.
Your passwords may be stolen if:
1. You save them in your browser - if you always click 'never' or 'not now' when prompted to save the password, there's nothing to steal.
2. You need to visit a specially crafted page and be duped into interaction with content thereon to get potentially exploited.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #8  
Old December 14th, 2006, 11:39 AM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Quote:
Originally Posted by Mrkvonic
Hello,
No need to worry.
Your passwords may be stolen if:
1. You save them in your browser - if you always click 'never' or 'not now' when prompted to save the password, there's nothing to steal.
2. You need to visit a specially crafted page and be duped into interaction with content thereon to get potentially exploited.
Mrk

Thank you very much. That is really relieving to hear. Although I clicked once yes when prompted to save the password.
  #9  
Old December 14th, 2006, 11:47 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,467
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Hello,
You can delete saved passwords.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #10  
Old December 14th, 2006, 12:01 PM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Quote:
Originally Posted by Mrkvonic
Hello,
You can delete saved passwords.
Mrk

Could you explain me how to do it, please? I think I was able to do it by saving a false password instead the right, but I am not sure did it work correctly.
  #11  
Old December 14th, 2006, 12:11 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,365
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

In Firefox, go to the top menu, tools, options, security, show passwords. You can remove them from the window.
  #12  
Old December 14th, 2006, 12:13 PM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,467
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Hello,
Well, ronjor was faster....
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #13  
Old December 14th, 2006, 12:21 PM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Quote:
Originally Posted by ronjor
In Firefox, go to the top menu, tools, options, security, show passwords. You can remove them from the window.

Thank you very much. I know this is not this topic but could you tell me please, how to do it in Internet Explorer too?
  #14  
Old December 14th, 2006, 01:56 PM
Mem Mem is offline
Frequent Poster
 
Join Date: Mar 2005
Posts: 292
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

For IE7 Tools->Internet Options-> General-> Browsing History Delete-> Delete All or Delete Passwords
  #15  
Old December 14th, 2006, 02:31 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,365
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

For IE6, tools, Internet options, content, click auto complete, click clear passwords.
  #16  
Old December 16th, 2006, 04:12 AM
AWorriedPerson AWorriedPerson is offline
Infrequent Poster
 
Join Date: Dec 2006
Posts: 30
Default Re: Firefox 2.0 Password Manager Bug Exposes Passwords

Thank you all very much for your help.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:34 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums