PDA

View Full Version : Safe tabbed browsing?



wenwilder
10-23-2004, 08:21 PM
Secunia Advisory SA12712 (http://secunia.com/advisories/12712/print/) released on October 20th, 2004 isn't going to make fans of Mozilla, Firefox and Camino happy. The advisory states:


Secunia Research has discovered two vulnerabilities in Mozilla, Mozilla Firefox, and Camino, which can be exploited by malicious web sites to obtain sensitive information and spoof dialog boxes.

1) Inactive tabs can launch dialog boxes so they appear to be displayed by a web site in another tab. This can be exploited by a malicious web site to show a dialog box, which seems to originate from a trusted web site.

Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

A test is available here:
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/

The vulnerability has been confirmed in the following versions:
* Mozilla 1.7.2 and 1.7.3
* Mozilla Firefox 0.10.1
* Camino 0.8

2) Inactive tabs can gain focus from form fields on web sites in another tab. This can potentially be exploited to collect sensitive data entered in form fields on other web sites.

Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

A test is available here:
http://secunia.com/multiple_browsers_form_field_focus_test/

The vulnerability has been confirmed in the following versions:
* Mozilla 1.7.2 and 1.7.3
* Mozilla Firefox 0.10.1

Other versions may also be vulnerable.

Solution:
Don't visit trusted web sites while visiting untrusted web sites or disable JavaScript.

Maximilian
10-24-2004, 11:19 PM
Solution:
Don't visit trusted web sites while visiting untrusted web sites or disable JavaScript.

Hi wenwilder,

Will Mozilla becoming out with a "hot-fix" for Firefox 0.10.1 for these vulnerability alerts like M$ does for Explorer?

Note: Upon your previous recommendation on another forum, I downloaded the full-featured version of Firefox.

Does Mozilla have an automated update for Foxfire - or is it simply something I should look for in the options tabs?

Cheers!
Max

wenwilder
10-24-2004, 11:46 PM
Firefox is saying they should have a fix by the time Firefox 1.0 ships, in a couple of weeks. That was the word on the 20th.

As for updating Firefox, unless you change your settings it checks for updates and installs them. You can check by going into tools> options> advanced and scroll down to Software Updates.

There haven't been anywhere near the security issue's with Mozilla, Firefox or Opera but, with their increased usage... that is quickly changing. :( I still use IE when I check sites for malware and virus downloads. Firefox when I don't feel like playing with bugs.