Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Mozilla/Firefox bug Allows Remote Code Execution (Windows only)
Slapdash & eWeek | today | Self

Posted on 07/08/2004 3:51:44 PM PDT by general_re

So I'm reduced to summarizing the article, because the tools at eWeek apparently don't want their material posted here. Long story short: Mozilla and Firefox users on Windows XP (and possibly Windows 2000) have a hole that potentially allows remote code execution, due to the way Mozilla/Firefox passes certain protocols to the operating system. This apparently only affects Windows versions - users can get the full story here, and then download the ShellBlock extension here, which closes the hole.


TOPICS: Business/Economy; Culture/Society; Miscellaneous; News/Current Events; Technical
KEYWORDS: firefox; getamac; lowqualitycrap; microsoft; mozilla; patch; security; securityflaw; trojan; virus; windows; windoze
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-71 next last

1 posted on 07/08/2004 3:51:45 PM PDT by general_re
[ Post Reply | Private Reply | View Replies]

To: general_re

In English, please....(seriously...We just added Firefox to our Windows XP-run computer, and ironically, we did it because we were told Firefox was less prone to placing ad-ware and spy-ware bugs on our computer.)


2 posted on 07/08/2004 3:57:14 PM PDT by My2Cents ("Well.....there you go again.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re

thanx.


3 posted on 07/08/2004 3:59:47 PM PDT by demlosers
[ Post Reply | Private Reply | To 1 | View Replies]

To: My2Cents
I'm not sure there's a simple way to explain this. Essentially, if Mozilla/Firefox encounters a protocol it doesn't understand, it hands it off to the operating system to figure out what to do with it. Most of the time, that's not a problem, but there are certain cases where that passing-the-buck could allow a webpage to execute malicious code on your machine. The fix is to download the ShellBlock extension linked above.

As for you switching, I still think you did the right thing - no software is bug-free, but I'm not planning on switching away from FF. ;)

4 posted on 07/08/2004 4:01:54 PM PDT by general_re (Drive offensively - the life you save may be your own.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: My2Cents

I've done the same. The problem is, hackers who want the big payoff have avoided attacking seldom used browsers. Compared to IE, Mozilla is seldom used. But with browser hijackings becoming more and more of a problem, downloads of Mozilla and Firefox have more than doubled in the past few weeks. So is Mo the target of attacks now? Probably not, but I'd download the fix anyway. Any way you look at it Mo's infinitely more safe than IE.


5 posted on 07/08/2004 4:03:43 PM PDT by South40 (Amnesty for ILLEGALS is a slap in the face to the USBP!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: general_re
I couldn't get Firefox to work...I am unable to think in Russian.


6 posted on 07/08/2004 4:06:55 PM PDT by Poohbah ("Mister Gorbachev, TEAR DOWN THIS WALL!" -- President Ronald Reagan, Berlin, 1987)
[ Post Reply | Private Reply | To 4 | View Replies]

To: South40
The problem is, hackers who want the big payoff have avoided attacking seldom used browsers.

Unless the 'hacker' happens to be (large company name redacted) trying to deflect criticism of their crappy browser.

7 posted on 07/08/2004 4:09:09 PM PDT by JOAT
[ Post Reply | Private Reply | To 5 | View Replies]

To: JOAT
Unless the 'hacker' happens to be (large company name redacted) trying to deflect criticism of their crappy browser.

There's no one in Redmond, WA who would do such a thing.

Oh...wait...you weren't talking about MS were you?

Snicker...

8 posted on 07/08/2004 4:11:30 PM PDT by South40 (Amnesty for ILLEGALS is a slap in the face to the USBP!)
[ Post Reply | Private Reply | To 7 | View Replies]

To: general_re

It appears that it is only a problem for XP users. Win 95/98 users appear safe.


9 posted on 07/08/2004 4:11:40 PM PDT by PAR35
[ Post Reply | Private Reply | To 1 | View Replies]

To: My2Cents
Dealing with Spyware and Adware
10 posted on 07/08/2004 4:12:25 PM PDT by happydogdesign
[ Post Reply | Private Reply | To 2 | View Replies]

To: general_re; All

If you or anyone has a general Mozilla type ping list, add me to it, please.


11 posted on 07/08/2004 4:15:41 PM PDT by JoJo Gunn (Intellectuals exist only if you believe they do. ©)
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re

Hey, thanks for the explanation. It actually makes sense. :-) And thanks for the link to ShellBlock. Sheesh, I just added "Ad-aware 6.0" to my computer, now I need to add "ShellBlock." These pop-up and spyware battles are all-out war, aren't they.


12 posted on 07/08/2004 4:17:26 PM PDT by My2Cents ("Well.....there you go again.")
[ Post Reply | Private Reply | To 4 | View Replies]

To: Poohbah

Wise guy!....LOL


13 posted on 07/08/2004 4:18:24 PM PDT by My2Cents ("Well.....there you go again.")
[ Post Reply | Private Reply | To 6 | View Replies]

To: general_re

bump


14 posted on 07/08/2004 4:23:03 PM PDT by Victor
[ Post Reply | Private Reply | To 1 | View Replies]

To: My2Cents
In English, please

From what I gather the problem is that the "http" part of the URL can be replaced with "shell" and if the person knows the exact location of an executable on your system they might be able to run it.

Knowing the exact path to a program isn't difficult as its pretty standard. However the program itself might have to be buggy for the person to do any real damage. Although I suppose they could run the "del" program.

What's nasty about this is that a user doesn't have t click on a link for the exploit to work as the browser could try and "load" that page directly if the link was placed in an object.

The Fix appears to just remove the "shell://" scheme from being recognized.

This exploit came out pretty quickly, I saw something on BugTraq about it a day or two ago but ignored it.
15 posted on 07/08/2004 4:23:44 PM PDT by lelio
[ Post Reply | Private Reply | To 2 | View Replies]

To: lelio

Looking more into this it appears this is really a Windows problem as Mozilla hands of schemes that it doesn't know about to the OS. However there shouldn't really be a shell:// scheme so FireFox / Mozilla is pre-emptively blocking it. And I believe XP SP2 blocks this scheme altogether.


16 posted on 07/08/2004 4:30:01 PM PDT by lelio
[ Post Reply | Private Reply | To 15 | View Replies]

To: general_re; All

 
 
There are new, nastier browser hijackers flooding the web- the best help is here, but be warned, you have to do most yourself and learn to use some new tools. The old anti-virus software does not work on this new series of bugs:
http://forums.spywareinfo.com/index.php?s=d3c1a671159df31c9420ae4d671f1cd2&showforum=18
 
Microsoft Plugs IE; Warns All Browsers At Risk (Test Your Browser Here)
 
Freepers how do I get rid of this spyware crap that is on my computer?
Worm and Virus Wars- the August Edition
 http://www.mozilla.org/products/firefox/
 

17 posted on 07/08/2004 4:33:38 PM PDT by backhoe
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re

Thanks for the info. Just to be certain that this was really from Mozilla, I went to their website, rather than using your link. (Nothing personal, it's just that I'm a bit paranoid.) The patch is definitely available from them. It's locatable from their home page by scanning down the left margin to "Latest News" and clicking on "security update." Only takes a second.


18 posted on 07/08/2004 4:56:08 PM PDT by PatrickHenry (Hic amor, haec patria est.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Bush2000

Ping!


19 posted on 07/08/2004 5:00:00 PM PDT by Cultural Jihad
[ Post Reply | Private Reply | To 1 | View Replies]

To: general_re

Many thanks from all of us Mozilla users!


20 posted on 07/08/2004 5:01:35 PM PDT by B.Bumbleberry
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-71 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson