The Earthtimes online News
Home


Security flaw detected on Firefox and IE7

A security flaw has been discovered in Mozilla Foundation's Firefox 2 and Microsoft's Internet Explorer 7 web browsers. Hackers can use this flaw to capture the username and password of users.
Posted : Thu, 23 Nov 2006 13:12:00 GMT
Author : Brian Holmes
Category : Internet
News Alerts by Email ( click here )
Create your own RSS
Internet News | Home
A security flaw has been discovered in Mozilla Foundation's Firefox 2 and Microsoft's Internet Explorer 7 web browsers. Hackers can use this flaw to capture the username and password of users.

Firefox's Password Manager Software seems to be the source of the flaw. This software automatically fills the username and password into another login page. A hacker can make use of this flaw by creating a fake login page and the browser would be tricked into providing the username and password.

This can be done on sites that allow user created pages such as blogs and forums. This method was used on the social networking site MySpace reported late October. The hacker registered a username with MySpace and used it to host a fake login page. Users who accessed MySpace using Firefox thereafter had their information compromised.

This flaw has been named Reverse Cross Site Request vulnerability (RCSR) by Robert Chapin, who detected this flaw. RCSR poses a greater threat than Cross-site scripting (XCS) as the page is more convincing and shows no sign of external content or open redirects. The reason why RCSR succeeds in Firefox and IE is that both the browsers do not check the destination server, where the password is being sent. Besides since such a reversal happens at a trusted site the browser brings up no alerts.

Robert Chapin has provided a detailed description of the type of attack that can happen and a presentation of how it works on his site. The site also warns that firewalled local network servers and HTTP addresses that are not generally accessible are most vulnerable to these attacks as the hacker does not require direct access.

Though Firefox has been proven to be completely vulnerable to this attack IE seems to have a better defense. IE will not automatically fill the username and password till it accurately checks the source of the login form. Hence it will be tricked only if the RCSR page appears on the same page as a legitimate login page.

A bug report regarding this flaw has been filed with Mozilla but no fix has yet been found. Security experts have recommended that Firefox's Password Manager be disabled and the Master Password Timeout extension be installed.

This extension locks the master security device after a specific period of inactivity. Users have also been advised to disable the “Remember password for sites” option in Firefox.

Copyright, respective author or news agency



Article : Security flaw detected on Firefox and IE7
Print this article
Email this article


Share on

Have your Say
Name
Email
Subject
Your Comment

Enter Verification code
 
  

 

 
Your Comments

1.5
By: nosheen , Tue, 28 Nov 2006 09:47:35 GMT

is firefox 1.5 safe?


no
By: Ripal , Fri, 24 Nov 2006 10:45:18 GMT

no


Firefox Password Security Flaw
By: Jimmy Crackcorn , Fri, 24 Nov 2006 10:38:10 GMT

Does anyone know if the recent security flaw found with Firefox and it's save password feature effects all versions of FF or just Firefox 2?


Internet explorer 7
By: Debbie Olson , Fri, 24 Nov 2006 02:12:56 GMT

I have big fix but i cant get in to find out about, i would like to go back to explorer 6 but dont know if i can



More Internet News click here

Choose Theme
Green Earth Blue Earth Orange Earth Purple Earth

Search
 
You can
Print this articleemail this articleComment on this article

Current News

News Category
Business
Entertainment
Environment
General
Health
Sports
Technology
World
Press Release
Related Links
- Firefox 2
- Internet Explorer 7: Home
- The Cross Site Scripting (XSS) FAQ

About us | News Archives | Browse old Archive | Feedback | Disclaimer | Mobile/PDA | News Alerts

The views expressed in the articles are not necessarily those of earthtimes.org and we accept no responsibility for the views or opinions
expressed in the articles either direct or indirect.

© 2008 www.earthtimes.org, The Earth Times, All Rights Reserved | Privacy Policy