Homeppstream | pplive | emule | MP3 | Firefox |
The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 2, we’ve added powerful new features that make your online experience even better.
You position :Firefox >> Details Please remember website domain names www.firefox-uk.cn
Mozilla Admits Firefox Exploit Caused by Firefox Bug, Not IE Small print : [big]
Mozilla Admits Firefox Exploit Caused by Firefox Bug, Not IE

The problem was first discovered by security engineer Thor Larholm, who gained recognition last month for having discovered a security hole in Apple's Safari for Windows pre-release two hours after having first obtained it. This time, Larholm reported his discovery as an "Internet Explorer 0day Exploit," by virtue of the fact that IE was the attack vector he originally discovered.


Specifically, the problem concerns the fact that Firefox registers the firefoxurl:// resource identifier, whose handler is capable of running JavaScript code intentionally embedded in a URI that uses that identifier. On the day Secunia publicly reported Larholm's discovery, Mozilla took steps to allay users' fears, posting on its security blog, "It is important to note that if you are using Firefox to browse the web you *are not* vulnerable to this attack."

Later that day, information security expert Jesper Johansson wrote that although he could not get Larholm's exploit to behave exactly as he described, he could eliminate any possibility of the exploit altogether simply by unregistering Mozilla's own handlers from the command line. The direct implication there was that Firefox was not vulnerable because Firefox was responsible.

Meanwhile, Mozilla's security blog repeated a Microsoft spokesperson's comment that it would not be issuing a patch for the exploit.

On July 18, Mozilla released Firefox 2.0.0.5, ostensibly to manage the problem of Firefox receiving maliciously crafted URIs from IE. On her security blog that day, Mozilla's Snyder commented, "This patch for Firefox prevents Firefox from accepting bad data from Internet Explorer. It does not fix the critical vulnerability in Internet Explorer. Microsoft needs to patch Internet Explorer, but at last check, they were not planning to."

That comment prompted Johannson - a former security program manager at Microsoft - to issue this retort two days later: "Well Window, those who sit in a glass house should not be throwing stones." He then demonstrated that Firefox might not be susceptible to this problem at all if it followed the standard for URIs, which mandates that quotation marks - a critical character in JavaScript code, especially to demarcate filenames - must be filtered out.

"Following Mozilla's, and Thor Larholm's logic," Johansson wrote, "Firefox is subject to the exact same flaw that they blame on IE! Firefox also does not escape quotes in URLs before it passes them on to protocol handlers. I won't speculate here on why they failed to fix that 'flaw' in the new version of Firefox that was just released."

This morning, Snyder was forced to concede the point. "We thought this was just a problem with IE," she wrote. "It turns out, it is a problem with Firefox as well. We should have caught this scenario when we fixed the related problem in 2.0.0.5. We believe that defense in depth is the best way to protect people, so we're investigating it now."

 

firefox录入:renwen@renwen.net    责任编辑:renwen@renwen.net 
  • 上一pianfirefox:

  • 下一pianfirefox:
  • [Comment] [collections] told friends joined clock article note
    The latest hot The latest recommendation Relatedfirefox
     Download Firefox® for free
     Firefox Open Source Articles
     Firefox Stats
     Extend Firefox 3 Contest
     Firefox to plug vulnerability …
     Firefox Update Plugs 8 Securit…
     New Firefox Add-On Makes Inter…
     Firefox Isn' Bloated, DRM …
     Firefox: An anti-Israeli consp…
     A Campaign to Block Firefox Us…
     Download Firefox® for free
     Mozilla shares scanning tool, …
     Firefox 3.0 beta coming soon
     Google Browser Sync extension …
     Firefox 3.0 Makes Leap Forward
     The award-winning Web browserM…
     Firefox web browser download1.…
    Firefox Stats
    Extend Firefox 3 Contest
    Firefox to plug vulnerabil…
    Firefox Update Plugs 8 Sec…
    New Firefox Add-On Makes I…
    Firefox Isn' Bloated, …
    Firefox: An anti-Israeli c…
    A Campaign to Block Firefo…
    Mozilla shares scanning to…
    Firefox 3 alpha 7 released
      Netizen : (only shows the latest 10. Comment on the contents represent users view, and has nothing to judge! )