Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Alleged 'Unfixable' Exploit in Firefox ~ an alleged Firefox 1.5 exploit hit the Web this weekend...
BetaNews ^ | October 2, 2006, 11:52 AM | Scott M. Fulton, III, BetaNews

Posted on 10/02/2006 2:49:35 PM PDT by Ernest_at_the_Beach

An overflow of stories concerning an alleged Firefox 1.5 exploit hit the Web over the weekend, emerging from an underground users' conference in San Diego. But after the dust has begun settling, evidence of the exploit's severity and even existence has yet to materialize from official sources, including the Mozilla organization responsible for Firefox's development.

A few weeks ago, a series of exploitable bugs involving Firefox's JavaScript interpreter were reported by Secunia in an official advisory, which continues to rate these flaws this morning as "highly critical."

"An error in the handling of JavaScript regular expressions containing a minimal quantifier," reads the Secunia advisory, "can be exploited to cause a heap-based buffer overflow." No more recent Firefox flaws have been added to Secunia's list since then.

The alleged flaw introduced last weekend at the ToorCon convention in San Diego was reported to also involve a buffer overflow triggered through the JavaScript interpreter, although reports have made it appear this is the first such flaw in Firefox's history - which is far from reality. The venue in which the alleged flaw was presented -- a session entitled "LOVIN THE LOLS - LOL IS MY WILL" -- promised attendees a mix of BIOS patches, AIM exploits and sexual innuendo.

There, amid the presumed innuendo, new Mozilla security chief Window Snyder -- a former @stake researcher recently hired away from Microsoft -- reportedly took seriously a video of the exploit shown at the conference, although reports do not go so far as to say whether Mozilla officials consider the exploit to be particularly novel.

In any event, characterizations of the apparently uniquely prepared exploit as "unpatchable" have spread faster than the average zero-day, without the aid of a professional security advisory to push it along.

BetaNews has contacted Mozilla.org officials for comment on the alleged flaw, which may yet be forthcoming.



TOPICS: Computers/Internet
KEYWORDS: firefox
Navigation: use the links below to view more comments.
first previous 1-2021-32 last
To: 21stCenturion

Bump ...


21 posted on 10/02/2006 3:45:55 PM PDT by 21stCenturion ("It's the Judges, Stupid !")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach

Well, it actually did say "Document not found" when I clicked on it in your post. But I eventually did get it to work.

But, yes, I was still just 'joshin'!


22 posted on 10/02/2006 4:40:30 PM PDT by Bigh4u2 (Denial is the first requirement to be a liberal)
[ Post Reply | Private Reply | To 14 | View Replies]

To: Ernest_at_the_Beach

Sounds like the rumor and it's spread is made in Microsoft. I call serious BS on "unfixable" exploits. Everything is fixable given enough time and effort, except perhaps the next version of Microsoft's OS.


23 posted on 10/02/2006 4:42:04 PM PDT by thoughtomator (Islam delenda est)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Ernest_at_the_Beach
I was right. It's total BS. It was a prank.
24 posted on 10/02/2006 7:21:44 PM PDT by Terpfen (And in the second year, Nick Saban said "Let there be a franchise quarterback...")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Terpfen; ShadowAce

Thanks,...but to Mozilla's credit they say they will continue to investigate....


25 posted on 10/02/2006 8:36:28 PM PDT by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 24 | View Replies]

To: rdb3; chance33_98; Calvinist_Dark_Lord; Bush2000; PenguinWry; GodGunsandGuts; CyberCowboy777; ...

26 posted on 10/03/2006 9:20:46 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Terpfen

Just interested... Do you set 'noscript' to allow FR to run JS? I don't because I don't trust troll posted html.


27 posted on 10/03/2006 9:40:39 AM PDT by zeugma (I reject your reality and substitute my own in its place. (http://www.zprc.org/))
[ Post Reply | Private Reply | To 3 | View Replies]

To: Ernest_at_the_Beach
There, amid the presumed innuendo, new Mozilla security chief Window Snyder -- a former @stake researcher recently hired away from Microsoft -- reportedly took seriously a video of the exploit shown at the conference

The dude's first name is Window???? What? Were his parents some sort of Micro-hippies or something?

28 posted on 10/03/2006 10:14:05 AM PDT by Still Thinking (Quis custodiet ipsos custodes?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Still Thinking
Window Snyder -- a former @stake

Interesting. @stake merged with L0pht Heavy Industries, a hacker group. I wonder whether she (yes, she) comes from the @stake or L0pht side.

29 posted on 10/03/2006 10:51:44 AM PDT by antiRepublicrat
[ Post Reply | Private Reply | To 28 | View Replies]

To: zeugma

FR doesn't use Javascript (at least, not that I've ever seen--this is a pretty basic site design) so no, I don't allow FR Javascript.


30 posted on 10/03/2006 12:51:55 PM PDT by Terpfen (And in the second year, Nick Saban said "Let there be a franchise quarterback...")
[ Post Reply | Private Reply | To 27 | View Replies]

To: Ernest_at_the_Beach; All
Update: It would appear that this one is B.S..
31 posted on 10/03/2006 3:02:02 PM PDT by Redcloak (Speak softly and wear a loud shirt.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Redcloak

Thanks for the update....


32 posted on 10/03/2006 10:05:53 PM PDT by Ernest_at_the_Beach (History is soon Forgotten,)
[ Post Reply | Private Reply | To 31 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-32 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson