Monday, February 26th 2007
New Firefox Vulnerability Exposed
A serious new flaw in Mozilla's browser, Firefox, has been discovered which could allow malicious sites to exploit a system using the browser with JavaScript enabled. Mozilla's error tracking system classes the vulnerability as critical, and attackers could potentially access your system using a specially crafted HTML file and then run malware remotely. The recommendation from Mozilla is to disable JavaScript in Firefox until a fix is released, but another good idea may be to install the NoScript add-on which will allow you to control which sites can use Java and Flash. This flaw is present on all versions of Firefox, including the new 2.0.0.2 update, and is yet another illustration that Firefox is not immune to security exploits.
Source:
vunet.com
11 Comments on New Firefox Vulnerability Exposed
(I've been saying this for Java, Javascript, ActiveX, & ActiveScripting since 1997 in various posts & articles etc. I have authored, & it's coming true, moreso now, than ever! I knew the days when this would get 'abused' were coming is why... I used it enough to see things you could do for "the good" could just as easily been used for "the bad" is why...)
APK
P.S.=> For sites that DEMAND it? Turn it on... but, by default, keep it OFF... heck, "the infamous they" can hijack your routers now using it! See here, for those that did NOT see that:
COMPUTER ROUTERS FACE HIJACK RISK:
forums.techpowerup.com/showthread.php?t=25734
It's good stuff for INTRANET usage, but on the public internet? Heck, crank it off, & only use it, IF you HAVE to! apk
but fact of the matter remains that firefox is still about a buhjillion (yes, i made that number up) times more secure than IE...
and yeah, turning off javascript and keeping it off unless you absolutly need it... definantly a good idea. regerdless of what you might define "secure" or "unsecure" or what kind of add-ons/plugins/whatever you are using.
And I have to say it is mildly annoying to have to set things like this up. I wish humans were less malicious.
E.G./I.E.-> Here, I use the site, just fine (maybe better imo) WITHOUT Javascript being set active in my webbrowsers! Ah, it is... but, you go FASTER, if you do it right... & also go online quite a bit more securely (the TRUE bonus). So do I... but, there is a "bright-spot" too, because many of them WILL say how they created them, & how to work around them.
E.G.->
forums.techpowerup.com/showthread.php?t=26141
They're the "white hats", & they're NOT the ones to worry about!
... it's the "black hat" types that pull the tricks & don't tell others HOW they are doing it.
You can "head them off @ the pass" largely, nowadays, by turning off "features" in browsers, that CAN & DO work against you for both speed & security...
(Heck, you can @ the OS level, using things like HOSTS files for instance (& no 3rd party tools needed), for both more speed & stronger security, amongst others tweaks & tunings!)
APK
I know some white hat type of people sort of. I mean by malicious I mean the people who really do it to mess with people, and never release information. If you do it, just to show that you can, and then talk about it. Thats different. Thats more like me building a better catapult system, destroying like one small town, and everyones freaking out, and then im like chill kingdoms near me, for this was just to prove I could do it. Look, this how it works. You can even do good things with it like blah blah blah....
Right so anyways you get my point. Ill just have to get use to being safer. Because well, less headaches with nonsense.
Hey, I outline a few things thru the forums in regard to this type of thing, & other stuff, & so do others, via the methods THEY use vs. my own.
(Some are better than others, OVERALL, but most all of what I have seen noted by folks vs. methods I use, will work as well).
:)
* 8 ways to China in this stuff... quite often.
APK
Avant Browser FTW!
www.techpowerup.com/?26044
@Jimmy
Yeah, NoScript is nice. Even better is the developer version which has an experimental Blacklist instead of only the whitelist :)