DVD CDR Base Forums  

Go Back   DVD CDR Base Forums > Computer Software > Computer Software News

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 07-01-2005, 21:30
VIPER_1069's Avatar
Administrator
 
Join Date: Dec 2001
Location: Here @ DVDRBase !?
Posts: 12,227
FLAW in FIREFOX leaves it wide open for phishing scams :(

source Secunia Research


FLAW IN FIREFOX open to phishers

Quote:

A security flaw in the increasingly popular Firefox browser is exposing millions of users to phishing scams, security experts have warned.
Jakob Balle, security spe******t at Secunia Research, said that the vulnerability in Firefox and Mozilla allows malicious hackers to execute phishing scams by spoofing the source URL displayed in the browser's Download Dialog box.
"The problem is that long sub-domains and paths are not displayed correctly, which can be exploited to obfuscate what is being displayed in the source field of the Download Dialog box," he said.
A Secunia Research advisory stated that the "less critical" vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. It added that "other versions may also be affected".
"Currently, no solution is available. However, the vendor reports that this vulnerability will be fixed in upcoming versions of the affected products," Secunia stated.
Balle urged users not to follow download links from untrusted sources
__________________

Reply With Quote
  #2 (permalink)  
Old 07-01-2005, 21:47
serjer's Avatar
Gold Member
 
Join Date: Jul 2002
Location: Mauritius
Posts: 1,857
damn ,but thx 4 heads up m8
__________________

In the name of God,impure souls of the living dead shall be banished into eternal damnation.Amen
Reply With Quote
  #3 (permalink)  
Old 07-01-2005, 21:53
VIPER_1069's Avatar
Administrator
 
Join Date: Dec 2001
Location: Here @ DVDRBase !?
Posts: 12,227
no worries serjer mate ...even tho im not a user of it i will still always provide vital information
__________________

Reply With Quote
  #4 (permalink)  
Old 07-01-2005, 22:55
roadworker's Avatar
Administrator
 
Join Date: Nov 2002
Posts: 2,812
Seems that the security experts of Secunia Research neve heard of the spoofstick extension .....
A very convieniant way to check url's.....
__________________
It's nice to be important,but it's more important to be nice.....
Reply With Quote
  #5 (permalink)  
Old 19-01-2005, 08:31
Senior Member
 
Join Date: Jan 2003
Posts: 3,302
Quote:
Originally Posted by roadworker
Seems that the security experts of Secunia Research neve heard of the spoofstick extension .....
A very convieniant way to check url's.....
Even if they did, they are supposed to scrutinize the vanilla browser and not a tweaked one.
__________________
The revolution cannot be a lever, or an essay, or tablaeu, or embroidery. It cannot proceed mellowly, piece-by-piece, gently, devoutly, simply and humbly.
Mao Zedong
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT +1. The time now is 22:26.


Powered by vBulletin® Version 3.6.7 PL1