Forum index / General Chat / Firefox 2.0 Vunerability

Firefox 2.0 Vunerability

6 posts · page 1 of 1

post #1
01 December 2006, 05:57 UTC#1
Just a note if you are using Firefox 2.0

There is a warning out for all Firefox users to disable the auto password feature. Hackers have discovered a way to get your password.

Security
November 22, 2006
Phishers Lurk For Firefox 2.0 Password Manager
By Sean Michael Kerner

Using Mozilla Firefox's built-in Password Manager to keep track of your browser's passwords? It makes site logins faster but it also could help malicious sites steal your passwords.
The bug, which has been known to Mozilla for at least 10 days, remains unpatched and exploits as well as a proof of concept exist in the wild.
"I was shocked today to find an in-the-wild phish that uses nothing more than cross-site forms, and also extracts information from the Password Manger!" Security Researcher Robert Chapin wrote in a November 12th e-mail posted in the bugzilla bug tracking system.
"The underlying method was so obvious that it should have raised multiple warnings," Chapin continued. "There were none at all."
The flaw allows a maliciously crafted page to auto-fill a form with credentials intended for another site. Apparently, there is no warning in Firefox 2.0 or previous versions that the credentials are being pulled for the wrong site and submitted to a third party.
Details of the flaw first became public this week. Mozilla developers do not yet have a fix. "Since this bug is an in-the-wild attack we're not protecting anyone by hiding the details anyway," Mozilla developer Daniel Veditz wrote in a bugzilla entry. "Up to now, browser makes have focused on user convenience and assumed sites with valuable passwords would be well-written. But they have bugs just like we have bugs so we might have to be more defensive."
post #2
01 December 2006, 06:01 UTC#2
Thanks Gaz, I think the only thing I have it used for is this site and my facebook page...So I don't think they'll get too much information from me. I bet Microsoft found the hack and exploited it.
post #3
01 December 2006, 07:56 UTC#3
thanks man...
post #4
01 December 2006, 10:22 UTC#4
meh I gonna start using safari and opera.
post #5
01 December 2006, 13:50 UTC#5
Thanks for the heads up.

And by auto password feature, you mean this?
Tools>options>security>*untick remember passwords for sites*

Heh, just making sure.
post #6
01 December 2006, 15:55 UTC#6
IE all the way. Read about this a bit ago. People using it to steal Myspace accounts.