Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 5th, 2005, 10:29 AM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas, USA
Posts: 40,325
Default Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

Quote:
A vulnerability has been discovered in Mozilla Firefox, which can be exploited by malicious people to gain knowledge of potentially sensitive informatio


Netscape and Mozilla are also affected. A test is at the link.

Secunia
  #2  
Old April 5th, 2005, 08:14 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas, USA
Posts: 40,325
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

Flaw found in Firefox

Quote:
"Unlike other browser flaws, this one is not subject to phishing or access to the system. But it can expose sensitive information from other Web sites you visited and the information you entered there," said Thomas Kristensen, Secunia chief technology officer


More Info
  #3  
Old April 5th, 2005, 08:47 PM
Kye-U Kye-U is offline
Security Expert
 
Join Date: Jun 2004
Posts: 481
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

If you happen to use Proxomitron, here is a filter that *may* block this vulnerability (I still don't have a clear idea on how this flaw works):

Code:
[Patterns] Name = "Mozilla: Memory Access Remover [Kye-U]" Active = TRUE URL = "($TYPE(htm)|$TYPE(js))" Limit = 30 Match = ".replace\(\w,function\($[#1-9]\)" Replace = ".Shonenscape"
  #4  
Old April 6th, 2005, 02:02 AM
Marja's Avatar
Marja Marja is offline
Honestly, I'm not a bot!!
 
Join Date: Mar 2004
Location: In the Vast Fields of My Mind
Posts: 4,491
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

\\\\\\\\\\







Well, that was fun! It felt like half my computer's brain was just left at Secunia! So, Promoxitron is the only workaround right now?
  #5  
Old April 6th, 2005, 02:04 AM
Marja's Avatar
Marja Marja is offline
Honestly, I'm not a bot!!
 
Join Date: Mar 2004
Location: In the Vast Fields of My Mind
Posts: 4,491
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

So I disabled javascript and now I can only answer in this little quote box, or is that something else?
  #6  
Old April 6th, 2005, 02:49 AM
gottadoit's Avatar
gottadoit gottadoit is offline
Security Expert
 
Join Date: Jul 2004
Location: Australia
Posts: 589
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

You might be able to do the same sort of thing with the greasemonkey extension

If you haven't seen it before this extension allows you to make arbitrary changes to webpages dynamically
  • useful to fix pages that are slightly broken under Moz/FF
  • useful to add in features rather than waiting for the site owners...
  • possibly useful in this case to dynamically ferret out unwanted js behaviour
Greasemonkey can be found at http://greasemonkey.mozdev.org/
  #7  
Old April 6th, 2005, 03:55 PM
Kye-U Kye-U is offline
Security Expert
 
Join Date: Jun 2004
Posts: 481
Default Re: Mozilla Firefox JavaScript Engine Information Disclosure Vulnerability

There's a fix out now:

https://bugzilla.mozilla.org/show_bug.cgi?id=288688
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 06:55 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums