Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

Firefox phishing vulnerability discovered
ZDNet UK ^ | 05 January 2005 | Ingrid Marson

Posted on 01/05/2005 10:21:20 AM PST by ShadowAce

A newly discovered flaw in Firefox could allow cybercriminals to take advantage of Web surfers

A vulnerability in Firefox could make users of the open source browser more likely to fall for phishing scams.

The flaw in Mozilla Firefox 1.0, details of which were published by Secunia on Tuesday, allows malicious hackers to spoof the URL in the download dialog box which pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hyppönen, director of antivirus research at F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," said Hyppönen.

To fall victim to such a scam, a Firefox user would have to click on a link in an email that pointed to a spoofed Web site and then download malware from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said it is unlikely that phishers will take advantage of this exploit in Firefox because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," said Emm. "After all, Firefox has a much, much smaller install base than IE and it's likely that hackers will continue to pay more attention to [IE] instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based browsers, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, but Mozilla developers plan to fix this bug in an upcoming version of the product.

The Secunia advisory and Mozilla bug report are available online.


TOPICS: Computers/Internet
KEYWORDS: computersecurity; firefox; firefoxphishing; lowqualitycrap
Navigation: use the links below to view more comments.
first 1-2021-4041-60 next last
I've always considered phishing to be more of a social engineering bug than technical, but it still pays to watch your browser.
1 posted on 01/05/2005 10:21:24 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

Firefox tech ping!


2 posted on 01/05/2005 10:21:54 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

It's a sure sign of Firefox's popularity, now it is a target for hackers. We'll see just how secure it is.


3 posted on 01/05/2005 10:22:48 AM PST by dfwgator (It's sad that the news media treats Michael Jackson better than our military.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

Bad news to hear, but being open source it will be fixed right away I'm sure.


4 posted on 01/05/2005 10:23:04 AM PST by KoRn
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

Woops.

I don't get it; I have never had any issues with IE or MS "holes" or the like in the 10 years I have used MS products.


5 posted on 01/05/2005 10:23:34 AM PST by RedBloodedAmerican
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce

The more popular you are, the bigger of a target is painted on your back.

If FireFox was THE browser of the web, the same freaks who live and die to hate Microsoft right now would be slamming Firefox.

Its just the natural order of things.


6 posted on 01/05/2005 10:24:30 AM PST by smith288 (I have posted over 10,000 times. The more I post, the more intelligent you become!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
Thx for the update and post.
7 posted on 01/05/2005 10:24:32 AM PST by Ginifer ("All great spirits have encountered opposition from mediocre minds" - A. Einstein)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

As Firefox becomes increasingly popular, we'll probably see more of these vulnerabilities found and exploited.


8 posted on 01/05/2005 10:25:25 AM PST by Recovering Hermit
[ Post Reply | Private Reply | To 1 | View Replies]

To: dfwgator
It's a sure sign of Firefox's popularity, now it is a target for hackers.

Of course the Microsoft haters claim that a software's popularity has nothing to do with it being a target for hackers.

9 posted on 01/05/2005 10:26:43 AM PST by COEXERJ145
[ Post Reply | Private Reply | To 3 | View Replies]

To: Recovering Hermit
...we'll probably see more of these vulnerabilities found and exploited.

Found, perhaps. "Exploited" is still much less likely.

10 posted on 01/05/2005 10:27:35 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ShadowAce

Good post - thanks for the update, ShadowAce


11 posted on 01/05/2005 10:28:23 AM PST by stainlessbanner
[ Post Reply | Private Reply | To 2 | View Replies]

To: ShadowAce
So you're telling me I gotta go back to browsing with IE?
12 posted on 01/05/2005 10:29:12 AM PST by b4its2late (Liberals are good examples of why some animals eat their young.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: b4its2late

< grin >. Nah. Firefox is still better than IE.


13 posted on 01/05/2005 10:31:02 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 12 | View Replies]

To: ShadowAce

I agree...


14 posted on 01/05/2005 10:31:23 AM PST by demlosers
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Wonder if these hackers received any compensation from MS?


15 posted on 01/05/2005 10:31:32 AM PST by TruthWillWin
[ Post Reply | Private Reply | To 1 | View Replies]

To: smith288; Bush2000

I agree.

I love Microsoft and God Bless Bill Gates.

:)


16 posted on 01/05/2005 10:31:37 AM PST by Mr. K (Merry Christmas and Happy New Year. god Bless America, Our Troops, W, and Ann Coulter!)
[ Post Reply | Private Reply | To 6 | View Replies]

To: b4its2late

No, but the lesson is nobody is completely 100% on the interenet, regardless of your browswer/OS of choice.


17 posted on 01/05/2005 10:34:08 AM PST by rogers21774 (The guilty taketh the truth to be hard, for it cutteth them to the very center.)
[ Post Reply | Private Reply | To 12 | View Replies]

To: ShadowAce
I'll be interested in seeing how long it takes to fix this. I run Mozilla Nightlies, so I'll be testing it out when it is released.
18 posted on 01/05/2005 10:38:28 AM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: All; ShadowAce
I just checked out Bugzilla's note about this. It would appear that it's a presentation "bug" in that if your dialog window is not big enough, the entire URL may not be shown. See bold text below. Workaround, is to expand (or maximize) the dialog box so that you can see the entire URL of the download.

To go along with the download box spoof reported in bug SA12712 Jakob Balle submits a demonstration to make the download dialog more convincing by obscuring the software source. The demo takes advantage of the default length truncation (similar to truncation of the filename in bug 258601). While the dialog /can/ be resized to see the whole url, most people won't think to do that or even know it's possible.


19 posted on 01/05/2005 10:44:09 AM PST by zeugma (Come to the Dark Side...... We have cookies!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
I figured. I just wanted to give you laugh, and you got a grin, so I was close... LOL!
20 posted on 01/05/2005 10:47:00 AM PST by b4its2late (Liberals are good examples of why some animals eat their young.)
[ Post Reply | Private Reply | To 13 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-60 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson