internet.com
You are in the: Small Business Computing Channelarrow
Small Business Technology
» ECommerce-Guide | Small Business Computing | Webopedia | WinPlanet |Refer-It

WinPlanet Software Downloads and Reviews for Small Businesses
Search
Power Search | Tips
-
Navigate WinPlanet
WinPlanet Home Page

Software
Download Index
In-Depth Reviews
Tips & Tutorials
Updates
News

Software Categories
Browsers
Chat / Conferencing
Desktop Utilities
Development
Internet Apps
Multimedia
OS Service Packs
Productivity Tools

Software Glossary

WinPlanet Newsletter

internet.commerce
Partners & Affiliates













Small Business Computing
Small Business Computing
Ecommerce Guide
Webopedia
WinPlanet

WinPlanet / News

Download of the day
Internet Explorer 8

Most Popular Software Downloads
Mozilla Firefox 3.0
QuickTime for Windows
Adobe Flash Player
Winamp
Spybot Search and Destroy
Internet Explorer 7
Paint Shop Pro
AVG Anti-Virus Free
iTunes
Windows XP Service Pack 3

Most Popular Software Articles
Windows Vista Tips & Tricks, Part 1
Windows Vista: Worthy of the Hype?
Windows Wireless Zero Configuration: Five Steps to Sanity


Software Reviews

Warning on Spoofed Login Windows in Firefox
Password Dialog in Firefox 2.0.0.11 Can Be Spoofed
Sean Michael Kerner

A common feature on many Web sites is a pop-up dialog box where users enter their username and password. Before you enter your information in Firefox next time, you might want to think twice. Security researcher Aviv Raff is alleging that in the latest Firefox 2.0.0.11 release the pop-up dialog box for password entry can be spoofed in a phishing attack.

"Mozilla Firefox allows spoofing the information presented in the basic authentication dialog box, Raff wrote in an advisory. "This can allow an attacker to conduct phishing attacks, by tricking the user to believe that the authentication dialog box is from a trusted Web site."

Raff explained that the vulnerability exists because Firefox doesn't 'sanitize' all the characters in the authentication box for the realm value that defines where the authentication is from. As such it is possible for an attacker to maliciously craft a Realm value that looks as though the password dialog box comes from a trusted site such as a financial institution.

"When the victim clicks on the link, the trusted Web page will be opened in a new window, and a script will be executed to redirect the new opened window to the attacker's Web server, which will then return the specially crafted basic authentication response," Raff wrote. In addition to the advisory Raff has posted a video on YouTube showing how the vulnerability can be exploited.

Mozilla Chief Security Officer Window Snyder in an e-mail sent to InternetNews.com said that Mozilla is investigating the issue. Snyder also noted that Raff did not first properly inform Mozilla of the security issue.

"Aviv Raff first posted this information in a public forum," Snyder commented. "At Mozilla, we prefer that security researchers notify us of potential issues by either filing a security sensitive bug in https://bugzilla.mozilla.org or e-mailing security@mozilla.com. It helps us keep users safe when security researches notify us before making details publicly available, but we appreciate all contributions."

Raff was not immediately available for comment.

As a workaround Raff noted in his advisory to avoid providing usernames and passwords to Web sites that use the basic pop-up dialog box authentication method.

Mozilla has had its share of issues with password related phishing and cross site scripting vulnerabilities. The Firefox Password Manager was first revealed to have security issues in November of 2006. Mozilla has since fixed some of the issues with Password Manager though it is still a cause for concern with some security researchers. In fact, a key part of the upcoming Firefox 3 release is a rewritten Password Manager.

"Firefox 3 has improved security UI to minimize the opportunities an attacker has to lure a user into entering information where they shouldn't," Snyder said.

The Firefox 3 final release is expected later this year. As Mozilla is currently investigating Raff's allegations, it is not yet clear when a security update may be available for Firefox 2.0.0.11.

News courtesy of internetnews.com

January 4, 2008

Download Mozilla Firefox 2!Download

Download Mozilla Firefox 3!Download

View All Web Browsers

Contents:
1. Password Dialog in Firefox 2.0.0.11 Can Be Spoofed


Additional Articles:

  • Mozilla's Newest FireFox Takes Flight
  • Browser Wars v.2004: Part 1
  • Browser Wars v.2004: Part 2
  • Mozilla Firefox's Volunteer Launch Brigade
  • Rise of the Underdog Browser
  • Firefox Makes It Official
  • Add-ons Extend Firefox Growth
  • Getting the Most Out of Firefox
  • Firefox Thankful for Strong November
  • Firefox, Others at Phishing Risk
  • Browser Wars: Who's Winning, Who's Losing
  • Firefox Torches Competition for Enterprise Linux Award
  • Mozilla Updates Firefox
  • New Firefox Vulnerability Pushes Latest Update
  • Firefox Update Patches Three in Time
  • JavaScript Flaw Hits Mozilla Users
  • Firefox Popularity Spurs Mozilla Traffic Surge
  • Beware the Browser Backlash
  • Another Flaw Found in Mozilla
  • Google Extends Firefox
  • New Firefox Fixes Holes
  • Firefox Advocate Site Hit by Hackers
  • Mozilla Goes for More Green
  • IBM Donates Code to Firefox
  • Firefox Losing Its Grip?
  • Mozilla Under Fire
  • Mozilla FireFox DoS Exploit Code Released
  • Firefox: Nearly a Year Old And Now 100M Strong
  • Happy Birthday, Firefox 1.0
  • Firefox Upgrade Near
  • Firefox at Critical Mass?
  • New Firefox Kills Bugs
  • A Word-Wise Firefox Extension
  • Mozilla Plugs Firefox Bugs
  • FireFox Fixes by the Dozen
  • Goooaaal! Google, Mozilla Kick In Soccer Fix
  • Firefox 2.0: Mozilla's Tabs Overfloweth
  • Firefox 1.5.0.5 Fixes JavaScript Flaws
  • Firefox Is Doing So Well It's Now a Malware Target
  • Firefox 2.0 Beta Tweaking Its Look
  • The Firefox, IE Race to The Finish
  • Firefox Hits Seventh Heaven
  • Firefox 2.0 Release Candidate Goes Live Today
  • Double Deuce as Firefox 2.0 Nears Completion
  • Mozilla Fine-Tunes for Final Release of Firefox 2
  • Firefox 2.0 Released: 'Bon Echo' Lives!
  • Firefox 3.0 Already?
  • Path to Firefox 2.0 Is Cleared
  • Our Phishing Filter Is Better Than Yours!
  • Phishers Lurk for Firefox 2.0 Password Manager
  • Mozilla Fixes Firefox Flaws, Misses One
  • Mozilla Rakes In $53M
  • Mozilla Patches Some Firefox Holes
  • Mozilla Security: More Than Meets the 'Aye'
  • One Flaw and a First for Latest Firefox Update
  • Firefox 1.5 Gets Its Last Update
  • Firefox at Risk Because of Internet Explorer?
  • Firefox Fixes IE Flaws
  • Mozilla Firefox Still at Risk
  • Will Mozilla's Fuzzer Break the Web?
  • Mozilla Updates Firefox Ahead of Black Hat
  • Flaw Still Shadows Firefox
  • Firefox Gets BitTorrent
  • Firefox Gets QuickTime Fix
  • Mozilla Separating Browser from the App
  • Firefox Fixes Cross-Site Flaws
  • Firefox Breaks Web Canvas
  • Mozilla Update Quashes Slew of Firefox Flaws
  • Firefox Update Tackles Pair of Critical Bugs




  • JupiterOnlineMedia

    internet.comearthweb.comDevx.commediabistro.comGraphics.com

    Search:

    Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

    Jupitermedia Corporate Info


    Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

    Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers