Welcome to p2pnet.net - The original daily p2p and digital news site. Always First!
REGISTER | LOGIN
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
Reviews
Open Source
Mobiles
Advertising
Products
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Scroogle Search: 
Search
 
Web p2pnet   
Search: 
Search
Torrent Site Tracker
    Sponsored by
Frostwire
 
p2pnet
 


mp3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code

Firefox password flaw

p2pnet.net News:- “Are you one of those people who lets Firefox save your passwords so you don’t have to type them in again?” – asked p2pnet on Tuesday.

If you are, it mightn’t be such a good idea, we said, basing the statement on new research from Chapin Information Services’ Robert Chapin, who’d found a new Firefox security hole.

He calling it a Reverse Cross-Site Request (RCSR) and says it could allow a hacker to grab passwords stored by the Firefox Password Manager.

How serious is it? – we asked him.

“On a scale of 1 to 10, with respect to surfing issues, I’d put the Password Manager issue at an 8,” he states. “On other scales, like at Secunia this would be a 2 out of 5, because it doesn’t result in a crash or infection.”

We wondered how clever a hacker have to be to exploit the flaw.

“An attacker would need a complete understanding of CSS, HTML, and HTTP, plus some working knowledge of server-side scripting to collect results” he told p2pnet.

And in realistic terms, what kind of a threat did it present?

“The fact that this has already been done as a MySpace phish means it is quite viable,” he says.

Mozilla has labelled the exploit bug number 360493 and is working on a fix for Firefox 2.0.0.1 or 2.0.0.2.”

A proof-of-concept demonstration is available here.

Also See:
new researchFirefox password security hole, November 21, 2006


p2pnet newsfeeds for your site.
rss feed: http://p2pnet.net/p2p.rss
Mobile – http://p2pnet.net/index-wml.php

HOME

One Response to “Firefox password flaw”

  1. Reader's Write Says:

    A couple of notes about this, this is only possible for sites in the same domain as a stored password.

    Secondly, according to theregister.co.uk this bug also effects fully patched versions of IE7

    All teh best

Leave a Reply

ONLY items referencing the post at hand, please. No links to personal sites, no personal attacks, trolling, freebie advertising, or off-topic posts. Thanks. And Cheers!

    Sponsored by
tek savvy