Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Most Browsers Buggy, Even IE In XP SP2 (A new - Test your browser here)
TechWeb ^ | December 8, 2004 | TechWeb News

Posted on 12/08/2004 8:34:03 PM PST by Eagle9

A European security vendor warned Wednesday that most browsers sport a bug that hackers can exploit to spoof a Web site and trick users into trusting bogus pop-up windows.

The vulnerability, which Danish security firm Secunia rated as "moderately critical" is similar to previous bugs in browsers that was disclosed in July and September of 2004. Attackers could use it to add content into a trusted Web site's window by, for instance, inserting a fake form in a pop-up window seemingly opened by that site.

Affected browsers, said Secunia, include the popular Internet Explorer and the up-and-coming Firefox, as well as third-tier alternatives like Mozilla, Opera, Apple's Safari, and the open-source Konqueror.

IE 5.01, 5.5, and 6.x are vulnerable, claimed Secunia, and the "vulnerability has been confirmed on a fully patched system with Microsoft Windows XP SP1/SP2."

While flaws in Windows XP Service Pack 2 (SP2) are rare, some have been reported since the Microsoft released the security update in October.

Secunia has posted a test that users can run on their browser to determine if it's plagued by the bug.


TOPICS: Business/Economy; Extended News; News/Current Events; Technical
KEYWORDS: browser; computersecurity; exploit; getamac; internetexploiter; lowqualitycrap; patch; securityflaw; spoof; technical; test; windoze
Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-102 next last
I tested IE 6.0 and Firefox 1.0 - both failed.

The "test" link is in the last sentence of the article, and also posted here - http://secunia.com/multiple_browsers_window_injection_vulnerability_test/

1 posted on 12/08/2004 8:34:03 PM PST by Eagle9
[ Post Reply | Private Reply | View Replies]

To: Eagle9

Ran it with Firefox 1.0... and passed.


2 posted on 12/08/2004 8:37:12 PM PST by kezekiel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

I use FireFox, and the popup was blocked. I still had the option to view it if I chose to though.


3 posted on 12/08/2004 8:37:51 PM PST by KoRn
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

I have IE6 with XP-Pro with ALL updates and I PASSED! but the noise (ie sound fx) from the huge barrage of attempted pop-ups was irritating.


4 posted on 12/08/2004 8:38:55 PM PST by steplock (http://www.outoftimeradio.org)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kezekiel

I ran it with Firefox 1.0 and it failed. Wonder what the difference is.


5 posted on 12/08/2004 8:40:42 PM PST by Arkinsaw
[ Post Reply | Private Reply | To 2 | View Replies]

To: Arkinsaw

My Firefox 1.0 fails.


6 posted on 12/08/2004 8:41:27 PM PST by steve86
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9
On all Internet browsers, the Pop-up windows should be disabled, and third party cookies disabled, and even JavaScript disabled, except for a particular website at which you are certain of its security.

The Mozilla browsers and Internet Explorer, provide a settings window where you can list such websites, that will permit Pop-up windows.

In other words, you fly an Internet browser, adjusting the trim and fuel settings as you go, if you mean to get there and back.

7 posted on 12/08/2004 8:41:46 PM PST by First_Salute (May God save our democratic-republican government, from a government by judiciary.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Arkinsaw

That's interesting I use Firefox 1.0 and I passed.


8 posted on 12/08/2004 8:41:54 PM PST by KoRn
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9

Firefox 1.0....passed


9 posted on 12/08/2004 8:43:37 PM PST by Jasper ("Power flows from the barrel of a 10mm pistol.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

No problems here. I'm using Safari 1.2.4 (v125.12)


10 posted on 12/08/2004 8:44:34 PM PST by d0le
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
Mine passed both with and without the pop-up blocker IE 6 with all the latest patches to WinXP Home and IE 6.0
11 posted on 12/08/2004 8:44:57 PM PST by airedale ( XZ)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kezekiel

My mozilla 1.7.3 passed


12 posted on 12/08/2004 8:45:13 PM PST by Knitting A Conundrum (Act Justly, Love Mercy, and Walk Humbly With God Micah 6:8)
[ Post Reply | Private Reply | To 2 | View Replies]

To: airedale

FF runs all the sites I need to access now. I wouldn't use IE for anything.


13 posted on 12/08/2004 8:46:01 PM PST by 1L
[ Post Reply | Private Reply | To 11 | View Replies]

To: Eagle9
Firefox 1.0 failed on my machine.

Solution: Do not browse untrusted sites while browsing trusted sites.

14 posted on 12/08/2004 8:47:12 PM PST by LibWhacker
[ Post Reply | Private Reply | To 1 | View Replies]

To: BearWash

Same here, failure.


15 posted on 12/08/2004 8:50:17 PM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: steplock
I just ran the test with FireFox 1.0 (with pop-up blocker enabled and running AVG Anti-Virus 7.0 "Free" and ZoneAlarm 5.5.062.004 active) and I didn't see any new pop-up windows from Secunia show up. I'm confused.

I think Secunia's test should be done after a run of a spyware removal program such as Ad-Aware SE, SpyBot or the new spyware remover from Yahoo! Toolbar 1.9 for Internet Explorer. Embedded spywre might be the reason the windows are opening in the way Secunia describes it.

16 posted on 12/08/2004 8:50:49 PM PST by RayChuang88
[ Post Reply | Private Reply | To 4 | View Replies]

To: Knitting A Conundrum

Mozilla 1.5 also passed.


17 posted on 12/08/2004 8:51:43 PM PST by kylaka
[ Post Reply | Private Reply | To 12 | View Replies]

To: kezekiel
Ran it with Firefox 1.0... and passed.

My version 0.8 Firefox passed as well. You wanna knnow why folks?

Firefox has an extension available called PrefButtons 0.2.
This allows you to place a small check box on you tool bar that you can easily turn of Java scripting with. Uncheck the box and run the test and Secunia can't do bupkis!

Firefox still beats the crap out of everything else.

18 posted on 12/08/2004 8:52:10 PM PST by Bloody Sam Roberts (All I ask from livin' is to have no chains on me. All I ask from dyin' is to go naturally.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Arkinsaw; Eagle9

My Firefox blocks the popups from the Drudge site....

So these guys have a new technique?


19 posted on 12/08/2004 8:52:36 PM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: kezekiel

bs open source means NO ONE patches it...


20 posted on 12/08/2004 8:53:26 PM PST by kinoxi
[ Post Reply | Private Reply | To 2 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-4041-6061-80 ... 101-102 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson