Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 30th, 2004, 10:11 AM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default 30th july- latest internet browser vulnerability news.

Mozilla / Mozilla Firefox User Interface Spoofing Vulnerability
Secunia Advisory: SA12188http://secunia.com/gfx/printer.jpg Release Date: 2004-07-30
Critical: http://secunia.com/gfx/crit_3.gif
Moderately critical Impact: Spoofing
Where : From remote

Software:Mozilla 0.x
Mozilla 1.0
Mozilla 1.1
Mozilla 1.2
Mozilla 1.3
Mozilla 1.4
Mozilla 1.5
Mozilla 1.6
Mozilla 1.7.x
Mozilla Firefox 0.x


Choose a product and view comprehensive vulnerability statistics and all Secunia advisories affecting it.
Description:
A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface.

The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees.

The Mozilla user interface is built using XUL files.

A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website.

This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected.

NOTE: This issue appears to be the same as Mozilla Bug 244965.

Solution:
Do not follow links from untrusted sites.

Provided and/or discovered by:
Reported in Mozilla Firefox by:
Jérôme ATHIAS (also created a PoC)

Reported in Mozilla by:
James Ross

Changelog:
2004-07-30: Added an additional Mozilla Bug reference.

Original Advisory:
Original Advisory and Proof of Concept:
http://www.nd.edu/~jsmith30/xul/test/spoof.html

Other References:
XUL Documentation:
http://www.xulplanet.com/

Mozilla Bug reference:
http://bugzilla.mozilla.org/show_bug.cgi?id=244965

Mozilla Bug reference:
http://bugzilla.mozilla.org/show_bug.cgi?id=252198


Please note: The information, which this Secunia Advisory is based upon, comes from third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  #2  
Old July 30th, 2004, 10:38 AM
Justhelping
 
Posts: n/a
Default Re: 30th july- latest internet browser vulnerability news.

Ah a fellow Singaporean.

http://forums.mozillazine.org/viewtopic.php?t=102334 is another good discussion on this fairly old issue. Some solutions are presented. You would have to do some "Scary" configuration changes. To wit

user_pref("dom.disable_window_open_feature.close", true);
user_pref("dom.disable_window_open_feature.directories", true);
user_pref("dom.disable_window_open_feature.location", true);
user_pref("dom.disable_window_open_feature.menubar", true);
user_pref("dom.disable_window_open_feature.minimizable", true);
user_pref("dom.disable_window_open_feature.personalbar", true);
user_pref("dom.disable_window_open_feature.resizable", true);
user_pref("dom.disable_window_open_feature.scrollbars", true);
user_pref("dom.disable_window_open_feature.titlebar", true);
user_pref("dom.disable_window_open_feature.toolbar", true);
  #3  
Old July 30th, 2004, 11:59 AM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: 30th july- latest internet browser vulnerability news.

I am just a 13 year old boy from Singapore, Justhelping.
  #4  
Old July 30th, 2004, 12:39 PM
Justhelping
 
Posts: n/a
Default Re: 30th july- latest internet browser vulnerability news.

I know you are 13 years old. (or at least between 13 to 16 from your postings).

It's rare to see someone from Asia much less Singapore. The last time there was such a poll, I recall only 2 people from Asia.
  #5  
Old July 30th, 2004, 12:43 PM
nadirah nadirah is offline
Massive Poster
 
Join Date: Oct 2003
Posts: 3,647
Default Re: 30th july- latest internet browser vulnerability news.

Quote:
Originally Posted by Justhelping
I know you are 13 years old. (or at least between 13 to 16 from your postings).

It's rare to see someone from Asia much less Singapore. The last time there was such a poll, I recall only 2 people from Asia.

Why don't you register and be a member so we can get to know each other? Are u a computer pro?
  #6  
Old July 31st, 2004, 11:24 AM
Justhelping
 
Posts: n/a
Default Re: 30th july- latest internet browser vulnerability news.

I'm already registered.

As for being a "pro", I'm no more a pro than you, I suspect.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:39 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums