Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

Skip to comments.

Firefox phishing vulnerability discovered
ZDNet UK ^ | 05 January 2005 | Ingrid Marson

Posted on 01/05/2005 10:21:20 AM PST by ShadowAce

A newly discovered flaw in Firefox could allow cybercriminals to take advantage of Web surfers

A vulnerability in Firefox could make users of the open source browser more likely to fall for phishing scams.

The flaw in Mozilla Firefox 1.0, details of which were published by Secunia on Tuesday, allows malicious hackers to spoof the URL in the download dialog box which pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hyppönen, director of antivirus research at F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," said Hyppönen.

To fall victim to such a scam, a Firefox user would have to click on a link in an email that pointed to a spoofed Web site and then download malware from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said it is unlikely that phishers will take advantage of this exploit in Firefox because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," said Emm. "After all, Firefox has a much, much smaller install base than IE and it's likely that hackers will continue to pay more attention to [IE] instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based browsers, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, but Mozilla developers plan to fix this bug in an upcoming version of the product.

The Secunia advisory and Mozilla bug report are available online.


TOPICS: Computers/Internet
KEYWORDS: computersecurity; firefox; firefoxphishing; lowqualitycrap
Navigation: use the links below to view more comments.
first previous 1-2021-4041-60 last
To: N3WBI3

Search is your friend.


41 posted on 01/05/2005 1:59:23 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 40 | View Replies]

To: BigSkyFreeper

And aparently unbacked exaggeration is yours..


42 posted on 01/05/2005 2:06:14 PM PST by N3WBI3
[ Post Reply | Private Reply | To 41 | View Replies]

To: N3WBI3
Just read through the threads with the keyword Firefox
43 posted on 01/05/2005 2:14:22 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 42 | View Replies]

To: BigSkyFreeper
None of these are post to you from someone saying that FireFox has no vulnerabilities..... Safer does not mean impervious..
44 posted on 01/05/2005 2:18:13 PM PST by N3WBI3
[ Post Reply | Private Reply | To 43 | View Replies]

To: N3WBI3
Safer does not mean impervious..

That's basically been my mantra for the past 25 years as a computer user.

45 posted on 01/05/2005 2:23:21 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 44 | View Replies]

To: ShadowAce

Would you please add me to your Firefox ping list?


46 posted on 01/05/2005 2:25:18 PM PST by Jen (Don't be a FReeploader! Support FR by automatic monthly donation. It's so easy!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: BigSkyFreeper

And that is what 99.9999% of the OSS folks on this board will say but constantly I see people saying that OSS folks claim their software is unbreakable when I have *never* seen that said..


47 posted on 01/05/2005 2:34:27 PM PST by N3WBI3
[ Post Reply | Private Reply | To 45 | View Replies]

To: BigSkyFreeper
I'm just saying that with anything popular, there will always be some possible exploitation found, because of the popularity of the product.

The favorite mantra of the Microsoft Apologist.

This is one relatively minor problem with FF, versus how many serious issues with IE? Granted, IE has been around longer, so it has a head start, and is fundamentally flawed to begin with. But popularity has nothing to do with it.

There is no comparison.

48 posted on 01/05/2005 4:39:23 PM PST by TechJunkYard (my "other PC" is a 4381)
[ Post Reply | Private Reply | To 31 | View Replies]

To: TechJunkYard
The favorite mantra of the Microsoft Apologist.

Actually I'm not a Microsoft Apologist. Popularity does play a part in this vulnerability in FF.

49 posted on 01/05/2005 4:43:24 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 48 | View Replies]

To: RedBloodedAmerican

You ever run critter checks?


50 posted on 01/05/2005 4:52:46 PM PST by ChefKeith (If a pig loses its voice, is it disgruntled?)
[ Post Reply | Private Reply | To 5 | View Replies]

To: BigSkyFreeper
Popularity does play a part in this vulnerability in FF.

I'm sure you can post some proof which backs up your theory then.

51 posted on 01/05/2005 5:06:10 PM PST by TechJunkYard (my "other PC" is a 4381)
[ Post Reply | Private Reply | To 49 | View Replies]

To: TechJunkYard
I'm sure you can post some proof which backs up your theory then.

If you're that clueless, then I won't bother.

52 posted on 01/05/2005 5:07:07 PM PST by BigSkyFreeper (PEST/Suicide Hotline 1-800-BUSH-WON)
[ Post Reply | Private Reply | To 51 | View Replies]

To: BigSkyFreeper
.. I won't bother.

I'm never surprised when a MS kneepadder backs away from a challenge.

C'mon, seriously. I want to know why you think the patrons of the most popular restaurant in town are more likely to come down with ptomaine poisoning... just because the restaurant is popular.

53 posted on 01/05/2005 5:22:42 PM PST by TechJunkYard (my "other PC" is a 4381)
[ Post Reply | Private Reply | To 52 | View Replies]

To: Jen

Sure, if you don't mind being pinged to other technical items as well.


54 posted on 01/05/2005 6:18:31 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 46 | View Replies]

To: ShadowAce

OK, thanks.


55 posted on 01/05/2005 6:39:56 PM PST by Jen (Don't be a FReeploader! Support FR by automatic monthly donation. It's so easy!)
[ Post Reply | Private Reply | To 54 | View Replies]

To: ShadowAce
Found, perhaps. "Exploited" is still much less likely.

IIRC, Firefox has an extension that takes care of this problem. At least i seem to run across it when downloading ad-ons.

56 posted on 01/05/2005 7:15:58 PM PST by Calvinist_Dark_Lord (I have come here to kick @$$ and chew bubblegum...and I'm all outta bubblegum! ~Roddy Piper)
[ Post Reply | Private Reply | To 10 | View Replies]

To: ShadowAce

Second that. Do you know if the actual URL will show with the spoofstick extension?

Mel


57 posted on 01/05/2005 7:46:44 PM PST by grwcfl537 (Linux Registered User 224182)
[ Post Reply | Private Reply | To 35 | View Replies]

To: grwcfl537
Here ya go
58 posted on 01/05/2005 7:58:21 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 57 | View Replies]

To: Calvinist_Dark_Lord

Ping to #58


59 posted on 01/05/2005 7:59:09 PM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 56 | View Replies]

To: ShadowAce

Have it already. i believe i might have been thinking of the multi line url addon that also exists.


60 posted on 01/06/2005 6:38:42 AM PST by Calvinist_Dark_Lord (I have come here to kick @$$ and chew bubblegum...and I'm all outta bubblegum! ~Roddy Piper)
[ Post Reply | Private Reply | To 59 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-60 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
Bloggers & Personal
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson