Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Mozilla says that flaw could lead to data leak
LinuxWorld ^ | 23 January 2008 | Robert McMillan

Posted on 01/24/2008 8:13:34 AM PST by ShadowAce

Mozilla is working to fix a browser flaw that could give attackers unauthorized access to data on a victim's machine.

The problem is similar to other data leakage flaws found in the open-source browser, according to researcher Gerry Eisenhaur, who first reported the problem on Saturday.

Eisenhaur has posted sample code that reads the contents of a Mozilla Thunderbird preferences file, but he believes that attackers could get access to more information with variations on his attack. "It's possible to load any JavaScript file on a victim's machine," he wrote in his blog posting. "This looks very interesting and may have bigger potential, but for now, it's just another information disclosure [flaw]."

"It could become something more if there was an application that stored sensitive data inside JavaScript files," he said via instant message. "Some plugins have been known to store usernames and passwords."

"Its also just a powerful way to do recon," he added.

Hackers have discovered a number of flaws in recent months that take advantage of the way that browsers pass information between different components within the Windows operating system. Some of these URI (Uniform Resource Identifier) protocol handler flaws have led to serious security problems for both Firefox and Internet Explorer.

This latest flaw affects only certain Firefox add-ons, such as the Download Statusbar or Greasemonkey, which store scripts in a fashion that lets them be discovered on the hard drive, said Window Snyder, Mozilla's security chief in a Wednesday blog posting.

Firefox is investigating the issue and has rated it as a low-severity problem, she said.


TOPICS: Technical
KEYWORDS: mozilla; security
This flaw seems to be OS-independent.
1 posted on 01/24/2008 8:13:36 AM PST by ShadowAce
[ Post Reply | Private Reply | View Replies]

To: rdb3; Calvinist_Dark_Lord; GodGunsandGuts; CyberCowboy777; Salo; Bobsat; JosephW; ...

2 posted on 01/24/2008 8:13:53 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
This flaw seems to be OS-independent.

Imagine that.

3 posted on 01/24/2008 8:14:55 AM PST by r9etb
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

I still like firefox over IE.


4 posted on 01/24/2008 8:16:04 AM PST by Slapshot68
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Great, just great.


5 posted on 01/24/2008 8:19:04 AM PST by GOPJ (McCain's NOT the man for the job.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

“This latest flaw affects only certain Firefox add-ons, such as the Download Statusbar or Greasemonkey,”

i use firefox but not those add-ons, so no big deal, and besides, i am sure the mozilla community will close the hole soon


6 posted on 01/24/2008 8:22:01 AM PST by Wuli
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Time to get rid of my plugins, eh?


7 posted on 01/24/2008 8:22:41 AM PST by ConservatismRedux
[ Post Reply | Private Reply | To 1 | View Replies]

To: Wuli

I use Greasemonkey just to filter out a certain troll here on FR.


8 posted on 01/24/2008 8:23:04 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Wuli

Me neither. I dont use ANY add-ons from FF and I use it over IE everytime.


9 posted on 01/24/2008 8:23:28 AM PST by max americana
[ Post Reply | Private Reply | To 6 | View Replies]

To: Wuli

I hate those search bar add-ons like that as a general rule.


10 posted on 01/24/2008 8:28:27 AM PST by Dead Corpse (What would a free man do?)
[ Post Reply | Private Reply | To 6 | View Replies]

To: max americana
Try ad blocker plus.

It is amazing how fast pages load without the ads.

11 posted on 01/24/2008 8:30:24 AM PST by fireforeffect (A kind word and a 2x4, gets you more than just a kind word.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: fireforeffect

Thnks for the advice. Ill try that.


12 posted on 01/24/2008 8:31:30 AM PST by max americana
[ Post Reply | Private Reply | To 11 | View Replies]

To: Wuli
This latest flaw affects only certain Firefox add-ons...

I run firefox in safe mode: no add-ons and less memory usage.

13 posted on 01/24/2008 9:03:18 AM PST by Rudder
[ Post Reply | Private Reply | To 6 | View Replies]

To: ShadowAce

With the tech economy doing pretty well, the “volunteers” these open source products needs aren’t so available.


14 posted on 01/24/2008 9:09:39 AM PST by fso301
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce
I use Greasemonkey just to filter out a certain troll here on FR.

I'm not  giving up my FRTrollBlocker Greasemonkey script!

Sounds to me like this attack could give up my list of trolls.

I also use the "noscript" extension, though it is sometimes a PITA, so that helps a bit as well.

15 posted on 01/24/2008 9:10:19 AM PST by zeugma (Hillary! - America's Ex-Wife!)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ShadowAce
Eisenhaur has posted sample code that reads the contents of a Mozilla Thunderbird preferences file,

Is Thunderbird the FF mail program? I'm still using Eudora but was going to change to TB when I get my new iMac...

16 posted on 01/24/2008 9:15:43 AM PST by tubebender
[ Post Reply | Private Reply | To 1 | View Replies]

To: tubebender

Thunderbird is a separate mail program, also produced by Mozilla.


17 posted on 01/24/2008 9:16:37 AM PST by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 16 | View Replies]

To: ShadowAce

I think I just had a greasemonkey update yesterday, and a noscript today.

I guess those Chinese slaves used to write open source are busy. ;-)


18 posted on 01/24/2008 9:21:55 AM PST by Salo
[ Post Reply | Private Reply | To 1 | View Replies]

To: ShadowAce

Thanks for the script btw, Its been off for a month but ort seems to be back..


19 posted on 01/24/2008 12:30:57 PM PST by N3WBI3 (Ah, arrogance and stupidity all in the same package. How efficient of you. -- Londo Mollari)
[ Post Reply | Private Reply | To 8 | View Replies]

To: fso301

Mozilla has a paid staff as does RedHat and IBM who work on OSS projects..


20 posted on 01/24/2008 12:31:41 PM PST by N3WBI3 (Ah, arrogance and stupidity all in the same package. How efficient of you. -- Londo Mollari)
[ Post Reply | Private Reply | To 14 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson