• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

New Firefox Vulnerability Exposed

Jimmy 2004

New Member
Joined
Jan 15, 2005
Messages
5,458 (0.75/day)
Location
England
System Name Jimmy 2004's PC
Processor S754 AMD Athlon64 3200+ @ 2640MHz
Motherboard ASUS K8N
Cooling AC Freezer 64 Pro + Zalman VF1000 + 5x120mm Antec TriCool Case Fans
Memory 1GB Kingston PC3200 (2x512MB)
Video Card(s) Saphire 256MB X800 GTO @ 450MHz/560MHz (Core/Memory)
Storage 500GB Western Digital SATA II + 80GB Maxtor DiamondMax SATA
Display(s) Digimate 17" TFT (1280x1024)
Case Antec P182
Audio Device(s) Audigy 4 + Creative Inspire T7900 7.1 Speakers
Power Supply Corsair HX520W
Software Windows XP Home
A serious new flaw in Mozilla's browser, Firefox, has been discovered which could allow malicious sites to exploit a system using the browser with JavaScript enabled. Mozilla's error tracking system classes the vulnerability as critical, and attackers could potentially access your system using a specially crafted HTML file and then run malware remotely. The recommendation from Mozilla is to disable JavaScript in Firefox until a fix is released, but another good idea may be to install the NoScript add-on which will allow you to control which sites can use Java and Flash. This flaw is present on all versions of Firefox, including the new 2.0.0.2 update, and is yet another illustration that Firefox is not immune to security exploits.

View at TechPowerUp Main Site
 

Alec§taar

New Member
Joined
May 15, 2006
Messages
4,677 (0.69/day)
Location
Someone who's going to find NewTekie1 and teach hi
Processor DualCore AMD Athlon 64x2 4800+ (o/c 2801mhz STABLE (Ketxxx, POGE, Tatty One, ME))
Motherboard ASUS A8N-SLI Premium (PCIe x16, x4, x1)
Cooling PhaseChange Coolermaster CM754/939 (fan/heatsink), Thermalright heatspreaders + fan built on (RAM)
Memory 512mb PC-3200 DDR400 (set DDR-33 for o/c) by Corsair (matched pair, 2x256mb) 200.1/200mhz
Video Card(s) BFG GeForce 7900 GTX OC 512mb GDDR3 ram (o/c manually to 686 core/865 memory) - PhaseChange cooled
Storage Dual "Raptor X" 16mb 10krpm/RAID 0 Promise EX8350 x4 PCIe 128mb & Intel IO chip/CENATEK RocketDrive
Display(s) SONY 19" Trinitron MultiScan 400ps 1600x1200 75hz refresh 32-bit color
Case Antec Super-LanBoy (aluminum baby-tower w/ lower front & upper rear cooling exhaust fans)
Audio Device(s) RealTek AC97 onboard mobo stereo sound (Altec Lansing ACS-45 speakers - 10 yrs. still running!)
Power Supply Antec 500w ATX 2.0 "SmartPower" powersupply
Software Windows Server 2003 SP #1 fully patched, & massively tuned/tweaked to-the-max (plus latest drivers)
A serious new flaw in Mozilla’s browser, Firefox, has been discovered which could allow malicious sites to exploit a system using the browser with JavaScript enabled. Mozilla’s error tracking system classes the vulnerability as critical, and attackers could potentially access your system using a specially crafted HTML file and then run malware remotely. The recommendation from Mozilla is to disable JavaScript in Firefox until a fix is released, but another good idea may be to install the NoScript add-on which will allow you to control which sites can use Java and Flash. This flaw is present on all versions of Firefox, including the new 2.0.0.2 update, and is yet another illustration that Firefox is not immune to security exploits.

Source: vunet.com

Another reason to TURN OFF JAVASCRIPT IN YOUR BROWSERS... gotta be the 2nd one this week alone.

(I've been saying this for Java, Javascript, ActiveX, & ActiveScripting since 1997 in various posts & articles etc. I have authored, & it's coming true, moreso now, than ever! I knew the days when this would get 'abused' were coming is why... I used it enough to see things you could do for "the good" could just as easily been used for "the bad" is why...)

APK

P.S.=> For sites that DEMAND it? Turn it on... but, by default, keep it OFF... heck, "the infamous they" can hijack your routers now using it! See here, for those that did NOT see that:

COMPUTER ROUTERS FACE HIJACK RISK:

http://forums.techpowerup.com/showthread.php?t=25734

It's good stuff for INTRANET usage, but on the public internet? Heck, crank it off, & only use it, IF you HAVE to! apk
 

spectre440

New Member
Joined
Jul 18, 2005
Messages
937 (0.13/day)
Location
Israel
Processor Athlon 64 x2 4000+ (65nm Brisbane)
Motherboard Abit AN-M2 (AM2) nForce 630a
Cooling Stock everything (for the time being), 2x120mm fans (intake & exhaust)
Memory 2GB (2x1024) OCZ Platinum PC2-6400 (4-4-4-15, 2T)
Video Card(s) PowerColor ATI HD 2600XT 256mb GDDR4 PCI-e
Storage Hitachi Deskstar 160GB SATA 3.0G/s, External USB2.0 WD 160GB
Display(s) LG 17' LCD (L1753TR)
Case HEC-Compucase 6A, black & grey
Audio Device(s) On-Board 7.1 (realtek)
Power Supply Spire Zeno 650W
Software WinXP Pro SP2 (32-bit, for the time being)
yet another illustration that Firefox is not immune to security exploits.

of course its not immune to security exploits, nothing is...

but fact of the matter remains that firefox is still about a buhjillion (yes, i made that number up) times more secure than IE...

and yeah, turning off javascript and keeping it off unless you absolutly need it... definantly a good idea. regerdless of what you might define "secure" or "unsecure" or what kind of add-ons/plugins/whatever you are using.
 

Scavar

New Member
Joined
Aug 29, 2006
Messages
573 (0.09/day)
Location
Ft Lauderdale, FL
System Name ScarredWolf(Desktop), MBlackWolf(Laptop)
Processor E6600(Desktop), T7300(Laptop)
Motherboard EVGA 680i(Desktop), IFL90(Laptop)
Cooling Akasa EVO 120(Desktop), No idea(Laptop)
Memory G Skill PI 8GB 4x2gb(Desktop), G Skill 3GB 1GB/2GB(Laptop)
Video Card(s) 8800GTS 640mb(Desktop), 8600m GT(Laptop)
Storage 3x250GB 1x500GB(Desktop), 1x320GB(Laptop)
Display(s) Acer AL2216W 22"(Desktop), 15.4"(Laptop)
Case Cosmos 1000(Desktop), PowerPro J 10:15(Laptop)
Audio Device(s) CreativeX-Fi/Z-5500(Desktop), Realtek/No idea(Laptop)
Power Supply PC Power and Cooling Silencer 610w(Desptop), *shrug*(Laptop)
Software Windows Vista Ultimatex64 with tweaks(Both)
Benchmark Scores I'm too lazy to benchmark anything.
I recently turned it off after listening to Alecstar and the Hijack router thing, and I have to say, its amazing just how many sites use it, including even our very own techpowerup.

And I have to say it is mildly annoying to have to set things like this up. I wish humans were less malicious.
 

Alec§taar

New Member
Joined
May 15, 2006
Messages
4,677 (0.69/day)
Location
Someone who's going to find NewTekie1 and teach hi
Processor DualCore AMD Athlon 64x2 4800+ (o/c 2801mhz STABLE (Ketxxx, POGE, Tatty One, ME))
Motherboard ASUS A8N-SLI Premium (PCIe x16, x4, x1)
Cooling PhaseChange Coolermaster CM754/939 (fan/heatsink), Thermalright heatspreaders + fan built on (RAM)
Memory 512mb PC-3200 DDR400 (set DDR-33 for o/c) by Corsair (matched pair, 2x256mb) 200.1/200mhz
Video Card(s) BFG GeForce 7900 GTX OC 512mb GDDR3 ram (o/c manually to 686 core/865 memory) - PhaseChange cooled
Storage Dual "Raptor X" 16mb 10krpm/RAID 0 Promise EX8350 x4 PCIe 128mb & Intel IO chip/CENATEK RocketDrive
Display(s) SONY 19" Trinitron MultiScan 400ps 1600x1200 75hz refresh 32-bit color
Case Antec Super-LanBoy (aluminum baby-tower w/ lower front & upper rear cooling exhaust fans)
Audio Device(s) RealTek AC97 onboard mobo stereo sound (Altec Lansing ACS-45 speakers - 10 yrs. still running!)
Power Supply Antec 500w ATX 2.0 "SmartPower" powersupply
Software Windows Server 2003 SP #1 fully patched, & massively tuned/tweaked to-the-max (plus latest drivers)
I recently turned it off after listening to Alecstar and the Hijack router thing, and I have to say, its amazing just how many sites use it, including even our very own techpowerup.

Yea, it is... but nice part about this forums & site is, that W1zzard doesn't make it MANDATORY to use Javascript...

E.G./I.E.-> Here, I use the site, just fine (maybe better imo) WITHOUT Javascript being set active in my webbrowsers!

And I have to say it is mildly annoying to have to set things like this up.

Ah, it is... but, you go FASTER, if you do it right... & also go online quite a bit more securely (the TRUE bonus).

I wish humans were less malicious.

So do I... but, there is a "bright-spot" too, because many of them WILL say how they created them, & how to work around them.

E.G.->

http://forums.techpowerup.com/showthread.php?t=26141

They're the "white hats", & they're NOT the ones to worry about!

... it's the "black hat" types that pull the tricks & don't tell others HOW they are doing it.

You can "head them off @ the pass" largely, nowadays, by turning off "features" in browsers, that CAN & DO work against you for both speed & security...

(Heck, you can @ the OS level, using things like HOSTS files for instance (& no 3rd party tools needed), for both more speed & stronger security, amongst others tweaks & tunings!)

APK
 

Easy Rhino

Linux Advocate
Staff member
Joined
Nov 13, 2006
Messages
15,597 (2.36/day)
Location
Mid-Atlantic
System Name Desktop
Processor i5 13600KF
Motherboard AsRock B760M Steel Legend Wifi
Cooling Noctua NH-U9S
Memory 4x 16 Gb Gskill S5 DDR5 @6000
Video Card(s) Gigabyte Gaming OC 6750 XT 12GB
Storage WD_BLACK 4TB SN850x
Display(s) Gigabye M32U
Case Corsair Carbide 400C
Audio Device(s) On Board
Power Supply EVGA Supernova 650 P2
Mouse MX Master 3s
Keyboard Logitech G915 Wireless Clicky
Software The Matrix
eeeeeew java script. and flash aint any better!
 

Scavar

New Member
Joined
Aug 29, 2006
Messages
573 (0.09/day)
Location
Ft Lauderdale, FL
System Name ScarredWolf(Desktop), MBlackWolf(Laptop)
Processor E6600(Desktop), T7300(Laptop)
Motherboard EVGA 680i(Desktop), IFL90(Laptop)
Cooling Akasa EVO 120(Desktop), No idea(Laptop)
Memory G Skill PI 8GB 4x2gb(Desktop), G Skill 3GB 1GB/2GB(Laptop)
Video Card(s) 8800GTS 640mb(Desktop), 8600m GT(Laptop)
Storage 3x250GB 1x500GB(Desktop), 1x320GB(Laptop)
Display(s) Acer AL2216W 22"(Desktop), 15.4"(Laptop)
Case Cosmos 1000(Desktop), PowerPro J 10:15(Laptop)
Audio Device(s) CreativeX-Fi/Z-5500(Desktop), Realtek/No idea(Laptop)
Power Supply PC Power and Cooling Silencer 610w(Desptop), *shrug*(Laptop)
Software Windows Vista Ultimatex64 with tweaks(Both)
Benchmark Scores I'm too lazy to benchmark anything.
I wish I knew how to do things, because it would be nice to make it so that like, you can actively scan the java, javascript, flash, like. Uhh the page loads without it, and it can scan the stuff while the page is loaded, and then load it. Or something. Because I mean they are nice features if they were safe.

I know some white hat type of people sort of. I mean by malicious I mean the people who really do it to mess with people, and never release information. If you do it, just to show that you can, and then talk about it. Thats different. Thats more like me building a better catapult system, destroying like one small town, and everyones freaking out, and then im like chill kingdoms near me, for this was just to prove I could do it. Look, this how it works. You can even do good things with it like blah blah blah....


Right so anyways you get my point. Ill just have to get use to being safer. Because well, less headaches with nonsense.
 

Alec§taar

New Member
Joined
May 15, 2006
Messages
4,677 (0.69/day)
Location
Someone who's going to find NewTekie1 and teach hi
Processor DualCore AMD Athlon 64x2 4800+ (o/c 2801mhz STABLE (Ketxxx, POGE, Tatty One, ME))
Motherboard ASUS A8N-SLI Premium (PCIe x16, x4, x1)
Cooling PhaseChange Coolermaster CM754/939 (fan/heatsink), Thermalright heatspreaders + fan built on (RAM)
Memory 512mb PC-3200 DDR400 (set DDR-33 for o/c) by Corsair (matched pair, 2x256mb) 200.1/200mhz
Video Card(s) BFG GeForce 7900 GTX OC 512mb GDDR3 ram (o/c manually to 686 core/865 memory) - PhaseChange cooled
Storage Dual "Raptor X" 16mb 10krpm/RAID 0 Promise EX8350 x4 PCIe 128mb & Intel IO chip/CENATEK RocketDrive
Display(s) SONY 19" Trinitron MultiScan 400ps 1600x1200 75hz refresh 32-bit color
Case Antec Super-LanBoy (aluminum baby-tower w/ lower front & upper rear cooling exhaust fans)
Audio Device(s) RealTek AC97 onboard mobo stereo sound (Altec Lansing ACS-45 speakers - 10 yrs. still running!)
Power Supply Antec 500w ATX 2.0 "SmartPower" powersupply
Software Windows Server 2003 SP #1 fully patched, & massively tuned/tweaked to-the-max (plus latest drivers)
I wish I knew how to do things, because it would be nice to make it so that like, you can actively scan the java, javascript, flash, like. Uhh the page loads without it, and it can scan the stuff while the page is loaded, and then load it. Or something. Because I mean they are nice features if they were safe.

Stick around here, you'll learn a lot... I do, everyday, even if only 'little things' & imo, there IS nothing bigger, because they're the foundations of LARGER things imo!

Hey, I outline a few things thru the forums in regard to this type of thing, & other stuff, & so do others, via the methods THEY use vs. my own.

(Some are better than others, OVERALL, but most all of what I have seen noted by folks vs. methods I use, will work as well).

:)

* 8 ways to China in this stuff... quite often.

APK
 

Jimmy 2004

New Member
Joined
Jan 15, 2005
Messages
5,458 (0.75/day)
Location
England
System Name Jimmy 2004's PC
Processor S754 AMD Athlon64 3200+ @ 2640MHz
Motherboard ASUS K8N
Cooling AC Freezer 64 Pro + Zalman VF1000 + 5x120mm Antec TriCool Case Fans
Memory 1GB Kingston PC3200 (2x512MB)
Video Card(s) Saphire 256MB X800 GTO @ 450MHz/560MHz (Core/Memory)
Storage 500GB Western Digital SATA II + 80GB Maxtor DiamondMax SATA
Display(s) Digimate 17" TFT (1280x1024)
Case Antec P182
Audio Device(s) Audigy 4 + Creative Inspire T7900 7.1 Speakers
Power Supply Corsair HX520W
Software Windows XP Home
Like I've mentioned in the news post, NoScript on Firefox is a great way to control JavaScript - give it a go, I didn't think I'd like it but now I'm very glad I have it. It means I can let sites like TPU (which I trust... assuming W1zz doesn't have some secret plot) use JavaScript and flash, but I block any that I don't know about or don't trust - so I can still do what I want, and it's very easy to use. Obviously the safest thing is to remove Java from your system, but this gives you a good balance between security, features and ease-of-use.
 

WarEagleAU

Bird of Prey
Joined
Jul 9, 2006
Messages
10,812 (1.60/day)
Location
Gurley, AL
System Name Pandemic 2020
Processor AMD Ryzen 5 "Gen 2" 2600X
Motherboard AsRock X470 Killer Promontory
Cooling CoolerMaster 240 RGB Master Cooler (Newegg Eggxpert)
Memory 32 GB Geil EVO Portenza DDR4 3200 MHz
Video Card(s) ASUS Radeon RX 580 DirectX 12 DUAL-RX580-O8G 8GB 256-Bit GDDR5 HDCP Ready CrossFireX Support Video C
Storage WD 250 M.2, Corsair P500 M.2, OCZ Trion 500, WD Black 1TB, Assorted others.
Display(s) ASUS MG24UQ Gaming Monitor - 23.6" 4K UHD (3840x2160) , IPS, Adaptive Sync, DisplayWidget
Case Fractal Define R6 C
Audio Device(s) Realtek 5.1 Onboard
Power Supply Corsair RMX 850 Platinum PSU (Newegg Eggxpert)
Mouse Razer Death Adder
Keyboard Corsair K95 Mechanical & Corsair K65 Wired, Wireless, Bluetooth)
Software Windows 10 Pro x64
Anything can be exploited. But it took them awhile to find out how to do it.
 

Benpi

New Member
Joined
Dec 14, 2006
Messages
415 (0.06/day)
Processor AMD X2 4400+
Memory 2G
Video Card(s) 7950 GX2
Storage 2x 74g 10000rpm Raid:0
Display(s) Dell 1920x1200 widescreen
Software 3dmark06 score: 7650
Anything can be exploited. But it took them awhile to find out how to do it.

That's because 95% use IE. If you were going to hack a browser to better profit your company, why would you try to exploit a browser used by only 5 percent? You wouldn't as it would be a waste of time.

Avant Browser FTW!
 

kakazza

New Member
Joined
Aug 25, 2006
Messages
470 (0.07/day)
"Mozilla Firefox appears to have lost some momentum. In January, 13.7 percent of all internet users browsed using Firefox, down from 14% in December. In contrast, Apple's Safari is gaining market usage. In January, 4.7% of all browser users used Safari, up from 4.2% in December. This is most likely due to more people using Mac OS X, which could be caused by all sorts of things (creative advertising, Core 2 Duo based iMacs, etc). Microsoft's Internet Explorer still accounts for 79.8% of all internet browser use."

http://www.techpowerup.com/?26044



@Jimmy

Yeah, NoScript is nice. Even better is the developer version which has an experimental Blacklist instead of only the whitelist :)
 
Top