Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old September 9th, 2005, 08:58 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,195
Default Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Quote:
Highly critical
Impact: DoS
System access
Where: From remote
Solution Status:Unpatched

Secunia

More


Netscape

Mozilla

Last edited by ronjor : September 9th, 2005 at 09:52 AM.
  #2  
Old September 9th, 2005, 10:49 AM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,535
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow



Thanks for the heads up Ron.
__________________
This space for rent.
  #3  
Old September 9th, 2005, 10:51 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,195
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

No rest for the wicked.
  #4  
Old September 9th, 2005, 04:10 PM
Kye-U Kye-U is offline
Security Expert
 
Join Date: Jun 2004
Posts: 481
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Yay! Another exploit!

*gets to work*

(Thanks ronjor Been waiting for one.)

EDIT: My Proxomitron config pack (v4.44) now detects and removes this exploit.

http://www.wilderssecurity.com/showp...0&postcount=16

For those who want to use a standalone Proxomitron filter, here you go.

*Had to attach filter in text file due to special character.*
Attached Files
File Type: txt filter.txt (367 Bytes, 10 views)

Last edited by Kye-U : September 9th, 2005 at 05:13 PM.
  #5  
Old September 9th, 2005, 06:22 PM
passing thru
 
Posts: n/a
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

According to FrSIRT a possible solution is:
Disable IDN support by entering "about:config" in the location bar, and then setting "network.enableIDN" to "false"."

http://isc.sans.org/diary.php?storyid=656

No need for complicated filters.
  #6  
Old September 9th, 2005, 07:11 PM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,535
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Thanks for the link passing through. I don't use Prox so this is cool.
__________________
This space for rent.
  #7  
Old September 9th, 2005, 08:18 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,195
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Another fix. http://www.mozilla.org/security/idn.html
  #8  
Old September 9th, 2005, 09:27 PM
Trooper's Avatar
Trooper Trooper is offline
Very Frequent Poster
 
Join Date: Jan 2005
Posts: 2,535
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Quote:
Originally Posted by ronjor

Thanks Ron, all set here.
__________________
This space for rent.
  #9  
Old September 10th, 2005, 08:43 AM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,097
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Thanks Ronjor
Not perfect but still better!!

Regards
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres
  #10  
Old September 10th, 2005, 12:29 PM
ice60
 
Posts: n/a
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

i'm reading this with OB1, becacue i don't want to leave any obvious records i've been using this pc ( family work PC which they know i'll screw around with if they give me the password, but i cracked it anyway , and they're right, so far i have installed afew things i would never on my PC. not that they check the logs, and find out. it will all be cleared up and back to normal when i have finished.

anyway, doesn't this prove that Opera, being closed source, is a more secure browser, just be looking at Secunia shows that. even my OB1 OffByOne is very scure, thanks Ron for showing it to me

sorry, if i'm getting this all wrong, i'm still a little confused with the lay out of the pages in OB1

I am now an opera Evangelist
  #11  
Old September 10th, 2005, 01:06 PM
Beefcarver's Avatar
Beefcarver Beefcarver is offline
Frequent Poster
 
Join Date: Jan 2005
Location: michigan
Posts: 263
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

i downloaded the patch and its now set to false. is that it?
__________________
Cavemen were wise men, They had no computers.
  #12  
Old September 14th, 2005, 09:05 PM
nicM's Avatar
nicM nicM is offline
nico-nico
 
Join Date: Jul 2004
Location: France
Posts: 631
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Thanks for the warn, and for the fix link !
  #13  
Old September 14th, 2005, 11:08 PM
bigbuck's Avatar
bigbuck bigbuck is offline
Massive Poster
 
Join Date: Jul 2004
Location: Qld, Aus
Posts: 4,877
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Quote:
Originally Posted by ice60
i'm reading this with OB1, becacue i don't want to leave any obvious records i've been using this pc ( family work PC which they know i'll screw around with if they give me the password, but i cracked it anyway , and they're right, so far i have installed afew things i would never on my PC. not that they check the logs, and find out. it will all be cleared up and back to normal when i have finished.

anyway, doesn't this prove that Opera, being closed source, is a more secure browser, just be looking at Secunia shows that. even my OB1 OffByOne is very scure, thanks Ron for showing it to me

sorry, if i'm getting this all wrong, i'm still a little confused with the lay out of the pages in OB1

I am now an opera Evangelist
Hey J, Me Too! Just loving it!
BTW, are you running that OB1 (don't know anything about it) off a USB thumb drive? Like Portable Firefox ? I just read the other day that there's a portable thunderbird for thumbdrives too! Good stuff when using someone else's machine....
__________________
Hard work never hurt anyone......but why take the chance!
  #14  
Old September 14th, 2005, 11:38 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,602
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

you can hit help and then about firefox
Attached Images
 
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #15  
Old September 15th, 2005, 05:41 AM
ice60
 
Posts: n/a
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Quote:
Originally Posted by bigbuck
Hey J, Me Too! Just loving it!
BTW, are you running that OB1 (don't know anything about it) off a USB thumb drive? Like Portable Firefox ? I just read the other day that there's a portable thunderbird for thumbdrives too! Good stuff when using someone else's machine....
hi, Brad no i'm not. it's a no install so i can just delete the folder when finished with it.

to tell the truth i don't remember writting my post and am a little shocked to see it. i'm looking after this business ATM and there's an apartment on the property, i was bored so went and bought a couple of really big beers the other night, that must have been when i wrote the post i don't think i was still drunk in the morning, but not sure. i'm sure i'm not drunk now though. Wow, that was strong beer
  #16  
Old September 15th, 2005, 06:12 AM
Brian N's Avatar
Brian N Brian N is offline
Very Frequent Poster
 
Join Date: Jul 2005
Location: Denmark
Posts: 2,150
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Good stuff, thank you Ron
__________________
AntiVir PremiumFD-ISR ProFirefox 3Jetico 2 Firewall
ASAP Member
  #17  
Old September 15th, 2005, 11:06 AM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,195
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

Thanks everyone.

New Firefox, Mozilla releases to fix bugs "shortly"

Quote:
The Mozilla Foundation plans to "shortly" release new versions of its Firefox and Mozilla Web browsers to address a recently disclosed serious security bug as well as several additional flaws, a representative said Wednesday.
Story
  #18  
Old September 17th, 2005, 11:53 AM
pamelajoy's Avatar
pamelajoy pamelajoy is offline
Regular Poster
 
Join Date: Jun 2005
Location: Fairbanks, Alaska
Posts: 127
Default Re: Firefox, Mozilla, Netscape,URL Domain Name Buffer Overflow

I read about it here:
http://www.pcmag.com/article2/0,1895,1857898,00.asp
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:20 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums