Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

IE, Firefox Spoofable, Again
Yahoo News ^ | 21 June 2005 | Unknown

Posted on 06/22/2005 10:44:40 AM PDT by ShadowAce

Internet Explorer and Firefox -- even the newest edition that's getting ready for release -- can be spoofed by hackers intent on stealing passwords or other confidential information, a security firm said Tuesday.

According to Danish vulnerability tracker Secunia, Microsoft's Internet Explorer, Mozilla's Firefox, and virtually every other popular browser could be used by malicious Web site to display bogus Java dialog boxes atop legitimate sites.

"The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open -- a prompt dialog box -- which appears to be from a trusted site," read the alert that Secunia posted.

An exploit requires that the user first visit a malicious site -- perhaps enticed there via e-mail or instant message -- that includes a link to a legit, trusted site, say an online banking portal. By leveraging the JavaScript bug, the attacker could display a fake password dialog, and trick the user into entering her account information.

Secunia has created a vulnerability test that users can quickly run to see if their browser is open to such a spoof.

Not only does the vulnerability exist in up-to-date editions of Internet Explorer, Firefox, Mozilla, Camino, Opera, and Safari, but it also affects the not-yet-released Firefox 1.0.5, which is in the last stages of testing.

"We expect a Firefox 1.0.5 release in the not too distant future," the quality control blog for Firefox read Tuesday. "We'd appreciate any help you all can offer by downloading and testing out these new bits."

It was expected that Firefox 1.0.5 would fix the frame insertion bug that crept back into the open-source browser's code, a gaffe that made news earlier in June.

Would 1.0.5 also fix this news flaw?

"We'll be taking a look at the vulnerability, and deciding whether it makes sense to put [a fix] in 1.0.5," said a Mozilla spokesman. "Firefox security is an ongoing process."

The spokesman wouldn't comment on whether any inclusion of a fix for the new vulnerability -- which Secunia rates as only a "less critical" threat -- would delay the appearance of 1.0.5, but said that the builds now available "were mostly for the development community. The release of 1.0.5 is a ways off."

Firefox 1.0.5 can be downloaded in its not-finished Windows, Mac, and Linux editions from the Mozilla Web site.


TOPICS: Technical
KEYWORDS: browser; firefox; ie; spoof
Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last
To: N3WBI3
Fire fox has very few core developers when compared to ie

How many developers are on Firefox versus IE?
41 posted on 06/24/2005 3:18:30 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 40 | View Replies]

To: Bush2000
Vladmir Vukicevic, Michael Connor, David Hyatt, Brian Ryner, Blake Ross, Ben Matthew Goodger

These are the guys who write firefox, and these guys have jobs outside of FF.

Do you think MS puts less man hours into ie?

So I ask again if this indicates that FireFox and Ie are just as vulnerable is it not safe to an opensource project consisting a a relatively small number (smaller than most IT departments) can make a product just as good as Microsoft's?

42 posted on 06/24/2005 4:23:05 PM PDT by N3WBI3 (I musta taken a wrong turn at 198.182.159.17)
[ Post Reply | Private Reply | To 41 | View Replies]

To: N3WBI3
These are the guys who write firefox, and these guys have jobs outside of FF.

Reference?
43 posted on 06/24/2005 9:15:30 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 42 | View Replies]

To: N3WBI3

And, again, how many developers are working on IE? How about a reference rather than some guess you pulled out of your arse?


44 posted on 06/24/2005 9:28:26 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 42 | View Replies]

To: Bush2000

http://www.mozilla.org/owners.html


45 posted on 06/24/2005 9:59:33 PM PDT by N3WBI3 (I musta taken a wrong turn at 198.182.159.17)
[ Post Reply | Private Reply | To 43 | View Replies]

To: Bush2000
Stop trying to get off of the topic...

Are you saying in post 30 that GPL Firefox is as good as ie and vise-cersa..

46 posted on 06/24/2005 10:01:28 PM PDT by N3WBI3 (I musta taken a wrong turn at 198.182.159.17)
[ Post Reply | Private Reply | To 44 | View Replies]

To: N3WBI3

Nice try. But the "Owners" aren't the only ones working on the code. Again, how many developers are working on IE? You made the comparison, so let's see your reference for the number of devs working on IE.


47 posted on 06/24/2005 11:33:58 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 46 | View Replies]

To: Bush2000

Does your comment in 30 mean the the OSS voulenteer project FireFox is of the same or comparable quality to Microsoft internet explorer...


48 posted on 06/25/2005 8:39:56 AM PDT by N3WBI3 (I musta taken a wrong turn at 198.182.159.17)
[ Post Reply | Private Reply | To 47 | View Replies]

To: N3WBI3
FireFox is subject to the same engineering problems as IE. I would expect the defect rates to be practically the same. If you've studied software engineering, you know this to be true. There's nothing magical about FireFox developers or their methodology. In the end, their defect rate per KLOC will be no better or worse than IE's.

BTW, you do realize that FireFox incorporates the work of numerous other projects (ie. Gecko, etc), right? So, in fact, the number of developers, testers, designers, and other folks working on the code that FireFox needs to execute is actually far greater than you've specified. I'm letting that slide for the moment because you've consistently failed to identify how many developers et al are working on IE. I'm still waiting for a response.
49 posted on 06/25/2005 10:32:06 AM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 48 | View Replies]

To: Bush2000

So you are saying that firefox is of equivelant quality to ie... thank you..


50 posted on 06/25/2005 10:40:05 AM PDT by N3WBI3 (I musta taken a wrong turn at 198.182.159.17)
[ Post Reply | Private Reply | To 49 | View Replies]

To: N3WBI3

So how many IE developers are there? You're the one that claimed that FireFox has fewer developers. I'm just waiting for proof.


51 posted on 06/25/2005 12:52:13 PM PDT by Bush2000 (Linux -- You Get What You Pay For ... (tm)
[ Post Reply | Private Reply | To 50 | View Replies]

To: ShadowAce

pinging my inner geek for later


52 posted on 06/25/2005 12:55:24 PM PDT by Feiny (I put the purrr in freeper, baby)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-52 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson