Potential Firefox Javascript issue ( Archived) (6)

Oct 2, 2006 3:59 PM CST Potential Firefox Javascript issue
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
Got this via mail, figured it'd be good to share.

....

By Joris Evers
CNET Newscom
October 02, 2006

Mozilla is investigating claims that its Firefox browser is vulnerable
to a zero-day attack.

The open source Firefox Web browser is critically flawed in the way it
handles JavaScript, two hackers said on Saturday afternoon.

An attacker could commandeer a computer running the browser simply by
crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference in San Diego. The flaw affects Firefox on Windows, Apple's Mac OS X and Linux, they said.

"Internet Explorer, everybody knows, is not very secure. But Firefox is also fairly insecure," said Spiegelmock, who in everyday life works at blog company SixApart. He detailed the flaw, showing a slide that
displayed key parts of the attack code needed to exploit it.

The flaw is specific to Firefox's implementation of JavaScript, a
10-year-old scripting language widely used on the Web. In particular,
various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a "complete mess," he said. "It is impossible to patch."

The JavaScript issue appears to be a real vulnerability, Window Snyder, Mozilla's security chief, said after watching a video of the
presentation Saturday night. "What they are describing might be a
variation on an old attack," she said. "We're going to do some
investigating."

Snyder said she isn't happy with the disclosure and release of an
apparent exploit during the presentation. "It looks like they had enough information in their slide for an attacker to reproduce it," she said. "I think it is unfortunate because it puts users at risk, but that seems to be their goal."

At the same time, the presentation probably gives Mozilla enough data to fix the apparent flaw, Snyder said. However, because the possible flaw appears to be in the part of the browser that deals with JavaScript, addressing it might be tougher than the average patch, she added. "If it is in the JavaScript virtual machine, it is not going to be a quick fix," Snyder said.

The hackers claim they know of about 30 unpatched Firefox flaws. They
don't plan to disclose them, instead holding on to the bugs.

Jesse Ruderman, a Mozilla security staffer, attended the presentation
and was called up on the stage with the two hackers. He attempted to
persuade the presenters to responsibly disclose flaws via Mozilla's bug
bounty program instead of using them for malicious purposes such as
creating networks of hijacked PCs, called botnets.

"I do hope you guys change your minds and decide to report the holes to us and take away $500 per vulnerability instead of using them for
botnets," Ruderman said.

The two hackers laughed off the comment. "It is a double-edged sword,
but what we're doing is really for the greater good of the Internet,
we're setting up communication networks for black hats," Wbeelsoi said.
------ This thread is Archived ------
Oct 2, 2006 4:04 PM CST Potential Firefox Javascript issue
catwm
catwmcatwmSomewhere in the middle, Florida USA48 Threads 6,683 Posts
Hmmmmmmmmmmmmmm

Always something. It is getting to the point that you do not even want to use a computer. jaw drop
------ This thread is Archived ------
Oct 2, 2006 4:07 PM CST Potential Firefox Javascript issue
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
There is a script add-on for Mozilla that will auto-disable scripts for all sites, and you can perm enable them for those that you would trust, like CS for example. I added it the first day I re-installed firefox, and it works with the latest version:

Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7

If you have questions about it, or wish to get and add it.. drop me a mail and I'll provide information.

Rich
------ This thread is Archived ------
Oct 2, 2006 4:15 PM CST Potential Firefox Javascript issue
nwnstar
nwnstarnwnstarConway, USA38 Threads 5,464 Posts
does it work for firefox 2?
------ This thread is Archived ------
Oct 2, 2006 4:17 PM CST Potential Firefox Javascript issue
TheProfessor
TheProfessorTheProfessorPandoras Box, USA91 Threads 4,746 Posts
That's a good question - I didn't see it mentioned, however the javascript code between latest stable and Firefox 2 RC1 Beta is the same per cvs reports. I would assume so and be cautious until told otherwise.

Rich
------ This thread is Archived ------
Oct 2, 2006 4:30 PM CST Potential Firefox Javascript issue
Mike1162
Mike1162Mike1162Over the Rainbow, Pennsylvania USA70 Threads 1,694 Posts
Thanks for the heads-up. handshake
------ This thread is Archived ------
Post Comment - Post a comment on this Forum Thread

This Thread is Archived

This Thread is archived, so you will no longer be able to post to it. Threads get archived automatically when they are older than 3 months.

« Go back to All Threads
Message #318

Stats for this Thread

413 Views
5 Comments
by TheProfessor (91 Threads)
Created: Oct 2006
Last Viewed: Apr 16
Last Commented: Oct 2006

Share this Thread

We use cookies to ensure that you have the best experience possible on our website. Read Our Privacy Policy Here