Submit Your Article Forum Rules

Results 1 to 3 of 3

Thread: Safe tabbed browsing?

  1. #1
    WebProWorld MVP wenwilder's Avatar
    Join Date
    Jul 2003
    Posts
    942

    Safe tabbed browsing?

    Secunia Advisory SA12712 released on October 20th, 2004 isn't going to make fans of Mozilla, Firefox and Camino happy. The advisory states:

    Secunia Research has discovered two vulnerabilities in Mozilla, Mozilla Firefox, and Camino, which can be exploited by malicious web sites to obtain sensitive information and spoof dialog boxes.

    1) Inactive tabs can launch dialog boxes so they appear to be displayed by a web site in another tab. This can be exploited by a malicious web site to show a dialog box, which seems to originate from a trusted web site.

    Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

    A test is available here:
    http://secunia.com/multiple_browsers...spoofing_test/

    The vulnerability has been confirmed in the following versions:
    * Mozilla 1.7.2 and 1.7.3
    * Mozilla Firefox 0.10.1
    * Camino 0.8

    2) Inactive tabs can gain focus from form fields on web sites in another tab. This can potentially be exploited to collect sensitive data entered in form fields on other web sites.

    Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

    A test is available here:
    http://secunia.com/multiple_browsers...ld_focus_test/

    The vulnerability has been confirmed in the following versions:
    * Mozilla 1.7.2 and 1.7.3
    * Mozilla Firefox 0.10.1

    Other versions may also be vulnerable.

    Solution:
    Don't visit trusted web sites while visiting untrusted web sites or disable JavaScript.
    Forum Rules
    Thinking Out Loud
    "Cat washing IS a martial art."

  2. #2
    Senior Member Maximilian's Avatar
    Join Date
    Sep 2004
    Posts
    330

    Re: Safe tabbed browsing?

    Quote Originally Posted by wenwilder
    Solution:
    Don't visit trusted web sites while visiting untrusted web sites or disable JavaScript.
    Hi wenwilder,

    Will Mozilla becoming out with a "hot-fix" for Firefox 0.10.1 for these vulnerability alerts like M$ does for Explorer?

    Note: Upon your previous recommendation on another forum, I downloaded the full-featured version of Firefox.

    Does Mozilla have an automated update for Foxfire - or is it simply something I should look for in the options tabs?

    Cheers!
    Max

  3. #3
    WebProWorld MVP wenwilder's Avatar
    Join Date
    Jul 2003
    Posts
    942
    Firefox is saying they should have a fix by the time Firefox 1.0 ships, in a couple of weeks. That was the word on the 20th.

    As for updating Firefox, unless you change your settings it checks for updates and installs them. You can check by going into tools> options> advanced and scroll down to Software Updates.

    There haven't been anywhere near the security issue's with Mozilla, Firefox or Opera but, with their increased usage... that is quickly changing. :( I still use IE when I check sites for malware and virus downloads. Firefox when I don't feel like playing with bugs.
    Forum Rules
    Thinking Out Loud
    "Cat washing IS a martial art."

Similar Threads

  1. Google Safe Browsing.
    By kgun in forum Google Discussion Forum
    Replies: 2
    Last Post: 07-16-2008, 10:46 AM
  2. Quick and Safe Browsing!!!
    By stathom98 in forum Internet Security Discussion Forum
    Replies: 0
    Last Post: 06-26-2008, 11:54 PM
  3. Firefox sues Microsoft over Tabbed Browsing
    By texxs in forum IT Discussion Forum
    Replies: 3
    Last Post: 04-02-2007, 09:22 PM
  4. MSN Follows Firefox Lead with Tabbed Browsing
    By WPW_Feedbot in forum Search Engine Optimization Forum
    Replies: 0
    Last Post: 06-10-2005, 09:00 AM
  5. Microsoft Releases Tabbed Browsing For IE 6
    By jmiller in forum MSN Search Discussion Forum
    Replies: 0
    Last Post: 06-09-2005, 08:56 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •