Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Most Browsers Buggy, Even IE In XP SP2 (A new - Test your browser here)
TechWeb ^ | December 8, 2004 | TechWeb News

Posted on 12/08/2004 8:34:03 PM PST by Eagle9

A European security vendor warned Wednesday that most browsers sport a bug that hackers can exploit to spoof a Web site and trick users into trusting bogus pop-up windows.

The vulnerability, which Danish security firm Secunia rated as "moderately critical" is similar to previous bugs in browsers that was disclosed in July and September of 2004. Attackers could use it to add content into a trusted Web site's window by, for instance, inserting a fake form in a pop-up window seemingly opened by that site.

Affected browsers, said Secunia, include the popular Internet Explorer and the up-and-coming Firefox, as well as third-tier alternatives like Mozilla, Opera, Apple's Safari, and the open-source Konqueror.

IE 5.01, 5.5, and 6.x are vulnerable, claimed Secunia, and the "vulnerability has been confirmed on a fully patched system with Microsoft Windows XP SP1/SP2."

While flaws in Windows XP Service Pack 2 (SP2) are rare, some have been reported since the Microsoft released the security update in October.

Secunia has posted a test that users can run on their browser to determine if it's plagued by the bug.


TOPICS: Business/Economy; Extended News; News/Current Events; Technical
KEYWORDS: browser; computersecurity; exploit; getamac; internetexploiter; lowqualitycrap; patch; securityflaw; spoof; technical; test; windoze
Navigation: use the links below to view more comments.
first 1-5051-100101-102 next last
I tested IE 6.0 and Firefox 1.0 - both failed.

The "test" link is in the last sentence of the article, and also posted here - http://secunia.com/multiple_browsers_window_injection_vulnerability_test/

1 posted on 12/08/2004 8:34:03 PM PST by Eagle9
[ Post Reply | Private Reply | View Replies]

To: Eagle9

Ran it with Firefox 1.0... and passed.


2 posted on 12/08/2004 8:37:12 PM PST by kezekiel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

I use FireFox, and the popup was blocked. I still had the option to view it if I chose to though.


3 posted on 12/08/2004 8:37:51 PM PST by KoRn
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

I have IE6 with XP-Pro with ALL updates and I PASSED! but the noise (ie sound fx) from the huge barrage of attempted pop-ups was irritating.


4 posted on 12/08/2004 8:38:55 PM PST by steplock (http://www.outoftimeradio.org)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kezekiel

I ran it with Firefox 1.0 and it failed. Wonder what the difference is.


5 posted on 12/08/2004 8:40:42 PM PST by Arkinsaw
[ Post Reply | Private Reply | To 2 | View Replies]

To: Arkinsaw

My Firefox 1.0 fails.


6 posted on 12/08/2004 8:41:27 PM PST by steve86
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9
On all Internet browsers, the Pop-up windows should be disabled, and third party cookies disabled, and even JavaScript disabled, except for a particular website at which you are certain of its security.

The Mozilla browsers and Internet Explorer, provide a settings window where you can list such websites, that will permit Pop-up windows.

In other words, you fly an Internet browser, adjusting the trim and fuel settings as you go, if you mean to get there and back.

7 posted on 12/08/2004 8:41:46 PM PST by First_Salute (May God save our democratic-republican government, from a government by judiciary.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Arkinsaw

That's interesting I use Firefox 1.0 and I passed.


8 posted on 12/08/2004 8:41:54 PM PST by KoRn
[ Post Reply | Private Reply | To 5 | View Replies]

To: Eagle9

Firefox 1.0....passed


9 posted on 12/08/2004 8:43:37 PM PST by Jasper ("Power flows from the barrel of a 10mm pistol.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

No problems here. I'm using Safari 1.2.4 (v125.12)


10 posted on 12/08/2004 8:44:34 PM PST by d0le
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9
Mine passed both with and without the pop-up blocker IE 6 with all the latest patches to WinXP Home and IE 6.0
11 posted on 12/08/2004 8:44:57 PM PST by airedale ( XZ)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kezekiel

My mozilla 1.7.3 passed


12 posted on 12/08/2004 8:45:13 PM PST by Knitting A Conundrum (Act Justly, Love Mercy, and Walk Humbly With God Micah 6:8)
[ Post Reply | Private Reply | To 2 | View Replies]

To: airedale

FF runs all the sites I need to access now. I wouldn't use IE for anything.


13 posted on 12/08/2004 8:46:01 PM PST by 1L
[ Post Reply | Private Reply | To 11 | View Replies]

To: Eagle9
Firefox 1.0 failed on my machine.

Solution: Do not browse untrusted sites while browsing trusted sites.

14 posted on 12/08/2004 8:47:12 PM PST by LibWhacker
[ Post Reply | Private Reply | To 1 | View Replies]

To: BearWash

Same here, failure.


15 posted on 12/08/2004 8:50:17 PM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 6 | View Replies]

To: steplock
I just ran the test with FireFox 1.0 (with pop-up blocker enabled and running AVG Anti-Virus 7.0 "Free" and ZoneAlarm 5.5.062.004 active) and I didn't see any new pop-up windows from Secunia show up. I'm confused.

I think Secunia's test should be done after a run of a spyware removal program such as Ad-Aware SE, SpyBot or the new spyware remover from Yahoo! Toolbar 1.9 for Internet Explorer. Embedded spywre might be the reason the windows are opening in the way Secunia describes it.

16 posted on 12/08/2004 8:50:49 PM PST by RayChuang88
[ Post Reply | Private Reply | To 4 | View Replies]

To: Knitting A Conundrum

Mozilla 1.5 also passed.


17 posted on 12/08/2004 8:51:43 PM PST by kylaka
[ Post Reply | Private Reply | To 12 | View Replies]

To: kezekiel
Ran it with Firefox 1.0... and passed.

My version 0.8 Firefox passed as well. You wanna knnow why folks?

Firefox has an extension available called PrefButtons 0.2.
This allows you to place a small check box on you tool bar that you can easily turn of Java scripting with. Uncheck the box and run the test and Secunia can't do bupkis!

Firefox still beats the crap out of everything else.

18 posted on 12/08/2004 8:52:10 PM PST by Bloody Sam Roberts (All I ask from livin' is to have no chains on me. All I ask from dyin' is to go naturally.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Arkinsaw; Eagle9

My Firefox blocks the popups from the Drudge site....

So these guys have a new technique?


19 posted on 12/08/2004 8:52:36 PM PST by Ernest_at_the_Beach (A Proud member of Free Republic ~~The New Face of the Fourth Estate since 1996.)
[ Post Reply | Private Reply | To 5 | View Replies]

To: kezekiel

bs open source means NO ONE patches it...


20 posted on 12/08/2004 8:53:26 PM PST by kinoxi
[ Post Reply | Private Reply | To 2 | View Replies]

To: Bloody Sam Roberts

Tried it with Avant too. Works great!


21 posted on 12/08/2004 8:54:17 PM PST by Never2baCrat (I used to be modest, now I'm perfect!)
[ Post Reply | Private Reply | To 18 | View Replies]

To: Never2baCrat

Firefox 1.0 works too!


22 posted on 12/08/2004 8:56:20 PM PST by Never2baCrat (I used to be modest, now I'm perfect!)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Bloody Sam Roberts
This is more subtle than that.

The lack of consistency among different Firefox users caused me to go to the Slashdot thread for more discussion.

Apparently the function of the vulnerability has to do with the exact sequence of types of windows that are opened, i.e. existing, tabbed, background, etc.

After failing the test a few minutes ago my Firefox now passes, without changing any settings.

So some people who think their bowser is invulnerable may be in for a shock when the vulnerability pops up someday.
23 posted on 12/08/2004 8:56:26 PM PST by steve86
[ Post Reply | Private Reply | To 18 | View Replies]

To: Eagle9

Bump


24 posted on 12/08/2004 8:57:00 PM PST by ApesForEvolution (You will NEVER convince me that Muhammadanism isn't a death cult that must end. Save your time...)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BearWash
bowser is invulnerable

You have to be real careful with those.

25 posted on 12/08/2004 8:58:53 PM PST by steve86
[ Post Reply | Private Reply | To 23 | View Replies]

To: BearWash

My Fire fox passes. I know at one time I had installed this update...I thought it was to correct this problem. I would think it would already be included in Firefox 1.0

http://ftp.mozilla.org/pub/mozilla.org/mozilla/releases/mozilla1.7.1/shellblock.xpi


26 posted on 12/08/2004 8:59:22 PM PST by Revel
[ Post Reply | Private Reply | To 23 | View Replies]

To: Never2baCrat
Tried it with Avant too. Works great!

I was going to try Avant at one time but was put off by what I read on their webpage:

"Since it's based on Internet Explorer, Avant Browser is as secure as Internet Explorer."

I don't want a browser that is AS secure as IE. I want one MORE secure than IE.

Maybe I'll try it on my desktop PC at work. Our company intranet sites don't like Firefox.

27 posted on 12/08/2004 9:02:03 PM PST by Bloody Sam Roberts (All I ask from livin' is to have no chains on me. All I ask from dyin' is to go naturally.)
[ Post Reply | Private Reply | To 21 | View Replies]

To: BearWash

Good to know. Thanks for the research.


28 posted on 12/08/2004 9:03:03 PM PST by Bloody Sam Roberts (All I ask from livin' is to have no chains on me. All I ask from dyin' is to go naturally.)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Revel
My Fire fox passes

I think all you can say is that your browser passed on that particular occasion.

29 posted on 12/08/2004 9:03:47 PM PST by steve86
[ Post Reply | Private Reply | To 26 | View Replies]

Shiira for OSX passed.


30 posted on 12/08/2004 9:04:07 PM PST by oolatec
[ Post Reply | Private Reply | To 27 | View Replies]

To: Revel

most recent problems in mozilla can be accessed through " about:config" , in your search bar. No browser will ever be "safe" and most bugs only infect your operating system anyway... which usually is microsoft...


31 posted on 12/08/2004 9:05:36 PM PST by kinoxi
[ Post Reply | Private Reply | To 26 | View Replies]

To: Eagle9

Lynx PASSED!


32 posted on 12/08/2004 9:06:06 PM PST by xrp (Executing assigned posting duties flawlessly -- ZERO mistakes)
[ Post Reply | Private Reply | To 1 | View Replies]

To: BearWash; Ernest_at_the_Beach
Apparently the function of the vulnerability has to do with the exact sequence of types of windows that are opened, i.e. existing, tabbed, background, etc

Exactly. I had my Tabbed Browsing set to load links in New Tab. It failed the test. I changed the setting to load links in Current Tab. It passed the test.

33 posted on 12/08/2004 9:06:44 PM PST by Eagle9
[ Post Reply | Private Reply | To 23 | View Replies]

To: Knitting A Conundrum

Ditto - Mozilla 1.7.3 was good, though the pop-up notifications lasted quite a while (I guess it was doing what it was supposed to do!).


34 posted on 12/08/2004 9:06:46 PM PST by alancarp (When does it cease to be "Freedom of the Press" and become outright SEDITION?)
[ Post Reply | Private Reply | To 12 | View Replies]

To: Bloody Sam Roberts

So this is a Java script buggy thing that will allow a new web page to attempt to gain control of my computer if I have another tab (or browser) that is open on a secure site?


35 posted on 12/08/2004 9:07:41 PM PST by Delta 21 (MKC USCG -ret)
[ Post Reply | Private Reply | To 18 | View Replies]

Konqueror passed...


36 posted on 12/08/2004 9:09:33 PM PST by Michael Barnes
[ Post Reply | Private Reply | To 9 | View Replies]

To: Eagle9

Passed on both IE 6.0 and Firefox 1.0. Whatever the bug is, certain configurations are protected against it.


37 posted on 12/08/2004 9:09:33 PM PST by beckett
[ Post Reply | Private Reply | To 1 | View Replies]

To: Delta 21

Mmmm...could be. Check out reply #23.


38 posted on 12/08/2004 9:09:40 PM PST by Bloody Sam Roberts (All I ask from livin' is to have no chains on me. All I ask from dyin' is to go naturally.)
[ Post Reply | Private Reply | To 35 | View Replies]

To: xrp
re #32

HAHA!!! Excellent!

39 posted on 12/08/2004 9:10:21 PM PST by Michael Barnes
[ Post Reply | Private Reply | To 32 | View Replies]

To: Eagle9

Well that sucked, I tried it with both IE and Fire fox and both failed.


40 posted on 12/08/2004 9:12:35 PM PST by edchambers ("Pajamahadin Neocon footsoldier of the Haliburton Death squad Digital brown shirts")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Nice, clear test.


41 posted on 12/08/2004 9:12:48 PM PST by steve86
[ Post Reply | Private Reply | To 33 | View Replies]

To: ntnychik; Smartass

Ping a ling!!


42 posted on 12/08/2004 9:23:42 PM PST by potlatch (Always remember you're unique. Just like everyone else.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

scary post lulling people into false sense of security, the "test" proves nothing... this is a 4 month old exploit that can be changed by typing "about:config" and changing
various settings...(just one). Would like to recommend cert.org to any who cares. Bugs are usually meant to take over your operating system anyway, you can always reinstall your browser...


43 posted on 12/08/2004 9:28:15 PM PST by kinoxi
[ Post Reply | Private Reply | To 1 | View Replies]

To: BearWash
After failing the test a few minutes ago my Firefox now passes, without changing any settings.

Same with my Netscape 7.1

44 posted on 12/08/2004 9:45:01 PM PST by Graybeard58 (Remember and pray for Spec.4 Matt Maupin - MIA/POW- Iraq since 04/09/04)
[ Post Reply | Private Reply | To 23 | View Replies]

To: Eagle9
Safari on my Mac passed.
45 posted on 12/08/2004 10:01:40 PM PST by Question_Assumptions
[ Post Reply | Private Reply | To 1 | View Replies]

To: Question_Assumptions

Same here. Safari is safe.


46 posted on 12/08/2004 10:09:16 PM PST by CurlyDave
[ Post Reply | Private Reply | To 45 | View Replies]

To: Question_Assumptions

mac's are far less safe than open source, or microsoft. They would find millions of converts if they were... (your Mac probably won't tell you you're compromised)


47 posted on 12/08/2004 10:10:24 PM PST by kinoxi
[ Post Reply | Private Reply | To 45 | View Replies]

To: Eagle9

Bump


48 posted on 12/08/2004 10:19:05 PM PST by nw_arizona_granny (Today, please pray for God's miracle, we are not going to make it without him.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Eagle9

Ran it with SlimBrowser ... passed


49 posted on 12/08/2004 10:21:19 PM PST by Centurion2000 (Truth, Justice and the Texan Way)
[ Post Reply | Private Reply | To 1 | View Replies]

To: kinoxi

don't mean to offend mac users, this is SERIOUS when someone can steal your financial info. The first virus generally recognised was a mac auto run cd virus... i typed this on mozilla and would never recommend anyone ever use a mac, they don't patch... the fact that AL GORE is on they're board might tell any one who cares... something about mac


50 posted on 12/08/2004 10:22:58 PM PST by kinoxi
[ Post Reply | Private Reply | To 47 | View Replies]


Navigation: use the links below to view more comments.
first 1-5051-100101-102 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson