| | |
Firefox Hackers Discovered.
![]() |
There is a warning out for all Firefox users to disable the auto password feature. Hackers have discovered a way to get your password. Just a warning.
http://www.internetnews.com/img/hdr_security.gif
November 22, 2006
Phishers Lurk For Firefox 2.0 Password Manager
By Sean Michael Kerner
Using Mozilla Firefox's built-in Password Manager to keep track of your browser's passwords? It makes site logins faster but it also could help malicious sites steal your passwords.
The bug, which has been known to Mozilla for at least 10 days, remains unpatched and exploits as well as a proof of concept exist in the wild.
"I was shocked today to find an in-the-wild phish that uses nothing more than cross-site forms, and also extracts information from the Password Manger!" Security Researcher Robert Chapin wrote in a November 12th e-mail posted in the bugzilla bug tracking system.
"The underlying method was so obvious that it should have raised multiple warnings," Chapin continued. "There were none at all."
The flaw allows a maliciously crafted page to auto-fill a form with credentials intended for another site. Apparently, there is no warning in Firefox 2.0 or previous versions that the credentials are being pulled for the wrong site and submitted to a third party.
Details of the flaw first became public this week. Mozilla developers do not yet have a fix. "Since this bug is an in-the-wild attack we're not protecting anyone by hiding the details anyway," Mozilla developer Daniel Veditz wrote in a bugzilla entry. "Up to now, browser makes have focused on user convenience and assumed sites with valuable passwords would be well-written. But they have bugs just like we have bugs so we might have to be more defensive."
http://www.internetnews.com/img/hdr_security.gif
November 22, 2006
Phishers Lurk For Firefox 2.0 Password Manager
By Sean Michael Kerner
Using Mozilla Firefox's built-in Password Manager to keep track of your browser's passwords? It makes site logins faster but it also could help malicious sites steal your passwords.
The bug, which has been known to Mozilla for at least 10 days, remains unpatched and exploits as well as a proof of concept exist in the wild.
"I was shocked today to find an in-the-wild phish that uses nothing more than cross-site forms, and also extracts information from the Password Manger!" Security Researcher Robert Chapin wrote in a November 12th e-mail posted in the bugzilla bug tracking system.
"The underlying method was so obvious that it should have raised multiple warnings," Chapin continued. "There were none at all."
The flaw allows a maliciously crafted page to auto-fill a form with credentials intended for another site. Apparently, there is no warning in Firefox 2.0 or previous versions that the credentials are being pulled for the wrong site and submitted to a third party.
Details of the flaw first became public this week. Mozilla developers do not yet have a fix. "Since this bug is an in-the-wild attack we're not protecting anyone by hiding the details anyway," Mozilla developer Daniel Veditz wrote in a bugzilla entry. "Up to now, browser makes have focused on user convenience and assumed sites with valuable passwords would be well-written. But they have bugs just like we have bugs so we might have to be more defensive."
This is sensational journalism at it finest.
Firefox is not the only browser vulnerable to this type of exploit. IE7 and Safari are also vulnerable. This is probably the first, in my memory, exploit to affect multiple browsers on multiple platforms.
The exploit in question is a Reverse Cross-Site Request (RCSR), brought to light by last months phishing scam on MySpace.
This vulnerability could affect anyone, using FireFox, IE7, and Safari, visiting a website that allows user-contributed HTML code.
The browser is not directly fooled, by the RCSR exploit. Instead the user is presented with a fake login page that fool’s the browser into providing the UserID and Log-In information. None of these browsers were designed to check the form data before submission.
This type of attack is particularly effective, as the user is presented with a Log-In page very similar to the one they are used to seeing on a website they trust.
Firefox developer discussion at Bugzilla Bug 360493 Cross-Site Forms + Password Manager = Security Failure
Microsoft has acknowledged the vulnerability, but inquires by Chapin Information Services (CIS) have been met with this response from Microsoft.
Firefox is not the only browser vulnerable to this type of exploit. IE7 and Safari are also vulnerable. This is probably the first, in my memory, exploit to affect multiple browsers on multiple platforms.
The exploit in question is a Reverse Cross-Site Request (RCSR), brought to light by last months phishing scam on MySpace.
This vulnerability could affect anyone, using FireFox, IE7, and Safari, visiting a website that allows user-contributed HTML code.
The browser is not directly fooled, by the RCSR exploit. Instead the user is presented with a fake login page that fool’s the browser into providing the UserID and Log-In information. None of these browsers were designed to check the form data before submission.
This type of attack is particularly effective, as the user is presented with a Log-In page very similar to the one they are used to seeing on a website they trust.
Firefox developer discussion at Bugzilla Bug 360493 Cross-Site Forms + Password Manager = Security Failure
Microsoft has acknowledged the vulnerability, but inquires by Chapin Information Services (CIS) have been met with this response from Microsoft.
“We are aware of the issue you reported.” And, “As a matter of policy, we cannot comment on ongoing investigations.”I have located no official documentation from Apple regarding this vulnerability in Safari.
Last edited by ShadowPuterDude; Nov 26th, 2006 at 12:44 am.
"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Well, thanks 'Stein.
I should add to my previous post that Netscape 8 may also be vulnerable. Since Netscape 8 is built from the Firefox 1.x source tree, therefore it stands to reason that Netscape 8 may also be vulnerable to this kind of exploit.
I should add to my previous post that Netscape 8 may also be vulnerable. Since Netscape 8 is built from the Firefox 1.x source tree, therefore it stands to reason that Netscape 8 may also be vulnerable to this kind of exploit.
"Only those who fail greatly can ever achieve greatly" - Robert F. Kennedy
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
Microsoft Most Valuable Professional - Consumer Security (2007-2008)
Member - Alliance of Security Analysis Professionals - Since 2006
![]() |
Similar Threads
- wireless network indicates connection, but ie browser won't connect (Windows NT / 2000 / XP)
- PC problems (Viruses, Spyware and other Nasties)
- Difference between Firefox and IE (JavaScript / DHTML / AJAX)
- Taskbar Address Bar and Firefox (Windows NT / 2000 / XP)
- question on browser compatible with windows (Windows Software)
- decryption error (OS X)
Other Threads in the Web Browsers Forum
- Previous Thread: Can't access certain pages (Hotmail) or DL Firefox
- Next Thread: Another person with Javascript links that will not open..
| Thread Tools | Search this Thread |
andrewlippmann aol apple awesomebar background britain browser browserproblems browsers browsing budget bug bughunt censorship childabuse chrome client code compuserve contest crash defect development dns email error eu europe exploit explorer facebook fennec fileeditmissing firefox flash gecko google government history ie7 ie8 internet internet.broadband internetexplorer internetexplorer8 iphone leak linux malware marshallmcluhan media memory microsoft mitmedialab mosaic mozilla music netscape networking news newspapers newyork olympics onlinecommunities opensource opera opera.software patch plugins porn privacy problem safari save seamonkey security server sex social software survey surveys teenagers television testing thunderbird twitter u.s. uk update usenet users utest web webbrowser webdevelopment webusage worldrecord worldwideweb xp






