jedipi
Sep 22 2005, 12:57 PM
| | Another flaw has been found in Firefox browser. This exploit affects Unix/Linix systems, not Windows. And the latest version 1.07 contains a fix. You guys, who are using older version in Unix/Linix systems, should update your firefox as soone as possible.
It shows that firefox is just not saft enough. It has good track record just simply because it wasn't used enough. Firefox browser is as vulnerable as any other popular browser on the market. |
Comment/Reply (w/o sign-up)
vizskywalker
Sep 22 2005, 02:31 PM
I've been saying that about Linux and Macs too, but no one will believe me! thanks for the warning, as I don't use my Linux box too muxh I probably wouldn't have found out for a while. Is this another full install update or is 1.07 finally a true update? And do you know if they are releasing 1.07 for Windows or if Linux and Windows will be out of sync on version numbers? ~Viz
Comment/Reply (w/o sign-up)
vizskywalker
Sep 22 2005, 03:52 PM
I can actually answer my own questions! Yes there is a 1.0.7, yes it installs over preceeding versions like a true update. On the other hand, so does 1.5 beta, which is insanely fast, so I recommend simply getting 1.5 beta. ~Viz
Comment/Reply (w/o sign-up)
saxsux
Sep 22 2005, 04:20 PM
QUOTE(jedipi @ Sep 22 2005, 01:57 PM) It shows that firefox is just not saft enough. How can you say that? Firefox has hardly a fraction of the security flaws of Internet Explorer. Yes, as it becomes more popular, more people are going to find flaws in it, but I think it is much better than the competition regardless. With Internet Explorer, they find a new security flaw in it nearly everyday.
Comment/Reply (w/o sign-up)
vizskywalker
Sep 22 2005, 05:01 PM
QUOTE With Internet Explorer, they find a new security flaw in it nearly everyday. Not to start a browser war or anything (as a matter of fact, if one starts this topic will be closed) but, do you have any data to back up your claim? Also, popularity has a lot to do with how many flaws are found. It is a simple law of computer science that as soon as you give a user any control over a system, you immediately have at least one security hole. Any fix of that hole invariably creates at least one more. Because windows is so popular and is so hated, many malicious code writers focus their attention on it, causing more security flaws to be found. Because the source to firefox is available to anyone, creating code that takes advantage of blatant security is easier, but blatant security flaws can be tracked down and fixed more easily as well. However, if you refer to CS principle 2 from above, the fixing of the blatant security flaw creates at least one more security flaw. If this one is blatant and gets fixed, new security flaws are created and fixed recursively until a non-bltant security flaw is created that someone can finally make use of. The only difference is that response time in firefox is faster do to the opensource nature, but since its release less than two years (I'm talking about the release of version 1.0) it has required 7 new minor version releases. Internet Explorer, while having many hotfixes an patches (most of which were very particular and really only needed to be installed by select people making use of certain interfaces between IE and other programs) has had maybe one minro version release. Just some food for thought to explain both sides and hopefully prevent a browser war. In conclusion, do not make grand statements without providing evidence. All of my statements can be found at the microsoft website by looking at updates released and at the firefox website by looking at their updates released. Except the CS principles, which, like the Laws of Thermodynamics and Energy, can be found in numeorus trustworthy locations around the net and in several largeCS publications. ~Viz
Comment/Reply (w/o sign-up)
solanky
Sep 22 2005, 05:03 PM
Although Firefox is a great browser but it is too early to say that it has very less flaws in it. The first choice for all the security breaking activities is Internet Explorer. But still it is a good competition to IE and I hope that due to firefox microsoft can think to chaning the source code of IE which is stiill years old.
Comment/Reply (w/o sign-up)
Sarah81
Sep 22 2005, 08:50 PM
QUOTE(jedipi @ Sep 22 2005, 07:57 AM)
It shows that firefox is just not saft enough.
I don't recall Firefox ever claiming that they had created a *perfect* Web browser. Had they been able to make that claim, they'd surely be charging arms, legs and large toes for their program. But I still prefer it over "the big two" because a) it crashes less often (a LOT less often, actually),  I've had to remove significantly LESS spyware/adware from my computer since switching over (we're talking a drastic reduction here - somewhere in the 70-90 percent range would be my guess), and c) I like the convenient features, such as the tabbed browsing. Yes, security flaws will happen. That's true no matter WHAT programs we use on the Internet. Programmers can only cover our butts to a certain extent. After that we have to make sure that we take the appropriate steps and measures to secure our systems.
Comment/Reply (w/o sign-up)
yu-cha
Sep 23 2005, 05:17 PM
the security flaws on all browsers have been know for sometime. it was a matter of making fixes that does not disrupt services that the users want. i like firefox but i hope someday they work on the memory leaks issues.
Comment/Reply (w/o sign-up)
Logan Deathbringer
Sep 24 2005, 05:58 AM
As stated by vizskywalker popularity of a program, or in IE and MS programs in general, the forced use of software will cause the security flaws to be made very public and very easy to use to those that want to use them. The fact that FireFox has fewer security flaws is a testament to the OpenSource nature of the project and the comunity formed around it. Also the fact that MS IE has so many patches and fixes is a testament to the fact that so many people use it, and so many others want to exploit the unknowing/uneducated that use it, only goes to prove that no matter how you look at it eventually anyone that wants to cause mischief, steal, or harm someone else will find a way to do it. Yes the programers/companies that put out software could do a better job of coding (cutting out bloat) and security, but also stated by vizskywalker no matter how "secure" you make something someone will find a flaw and exploit it, not to mention the fact that the minute you put a human infront of a terminal there is your biggest security flaw to start with. There are 2 major security holes in any system: 1 is the computer opperator that has any sort of access, and 2 is if it is connected to any sort of network. Yes the software being run can cause problems but the human part of any equation is the biggest hole in security.
Comment/Reply (w/o sign-up)
Similar Topics
Keywords : update, firefox, flaw, found, firefox
- Foxtorrent: Download Torrents From Within Firefox
(1)
How To Double Firefox Speed
(5) 1. Type about:config in the address bar and then press Enter. 2. In the filter search bar type
network.http.pipelining . Be sure the value field is set true ,if not double-click to set true .
3. Go back to the filter search bar and type network.http.pipelining.maxrequests . Double-click
this option and set its value to 8 . 4. In the filter search bar and type
network.http.proxy.pipelining . Once opened double-click on it and set it to true . 5. In
IPv6-capable DNS servers, an IPv4 address may be returned when an IPv6 address is requested. It is
possible for Mozi....
Winzip 10 Vunerability/update To Winzip 11
(7) Although this is a month old and most likely people have already done this, but for those who who
use winzip their is a somewhat major vulnerability with WINZIP in which they patched it with build
7245. http://www.winzip.com/wz7245.htm QUOTE This vulnerability could allow a remote
attacker to execute arbitrary code on a system with an unpatched installation of WinZip 10.0 if the
user was to visit a malicious web page. While there are no known exploits as of this announcement,
WinZip 10.0 users are strongly urged to update to build 7245, due to the critical nature....
Ld Window Injection Flaw Reappears In Ie 7
Flaw reappeared again (7) I just read an article on eWEEK about a vulnerability that was in 2004 is still present in the
latest Internet Explorer 7.The flaw is rated as moderately critical by Secunia. Here is a short
discription about the problem QUOTE "The problem is that a Web site can inject content into
another site's window if the target name of the window is known," said Secunia, in Copenhagen,
Denmark. Quote From eWeek. Do you think IE is going to be a secure browser?....
New Firefox Update 1.5.0.4
(10) This update fixes several security issues found in firefox such as HTTP smuggling and XSS issues.
It also improves stability with updates to memory and crashin issues. Unfortunately, it does not
fix the javascript issue I have identified. To get or for more info go to the update page . ~Viz....
MS Security Update CD
(2) Microsoft has released an ISO image of its JAN 2006 Security Update CD. The image is available free
to download. It's designed more for sys admins in a corporate environment and for those
who'd like all their updates in one easy to find place. Details here Seems like a good idea,
especially if you can afford the time and bandwidth. Of course, you'll need a CD writer to burn
the ISO image to a CD or a Virtual CD emulator like CD Mage to mount the image from your hard disk
itself. For home users, though I recommend the free AutoPatcher package . It'....
Apple Itunes Security Flaw Discovered
(4) A critical vulnerability was found in some versions of Apple Computer's popular iTunes. This
vulnerability could enable attackers to remotely take over a user's computer This vulnerability
existed on the earlier version of iTunes 6. However, Itwas not fixd by the newest security update.
iTunes 6 Windows version are affected. They are still trying to determine whether Mac OS X version
affected. http://news.com.com/Apple+iTunes+security+...ml?tag=nefd.top ....
Critical Flaw Found In Firefox
(5) I don't want to spam by posting the entire article but this was brougt to my attention by an
email posting at work. Since I have not seen it in this thread here it is. The full atricle can be
found at http://news.yahoo.com/s/pcworld/120756 "Firefox has unpatched "extremely critical"
security holes and exploit code is already circulating on the Net, security researchers have warned.
The two unpatched flaws in the Mozilla browser could allow an attacker to take control of your
system." Security focus also has a note http://www.securityfocus.com/advisories/8430....
Trend Micron Virus-update Creates Massive Problems
(0) An imperfection of update for softwares antivirus of the company of Trend security Micron caused the
slowness or interruption in the operations of some computers around of the world, confirmed the
company in this Monday (25/04). For return of 2h of this monday in Tokyo, the Trend Micron had
received about 311,9 a thousand telephonic calls users in Japan declaring that its PCs had been
afectados for a deficient filing-cabinet with information on virus and plagues. The filing-cabinet
of data was placed online between 7h30 and 9h02 (hourly Japanese) of Saturday (23/04). ....
Firefox Speed Tweaks
How to make Firefox open websites faster (16) Note: The one posted here is not the same thing. This one has been tested and increases the
speed, an update to perform these same steps is avalailable on the mozilline.org forums as well.
Type in the Address Bar - about:config Then scroll over to the following settings and adjust:
network.http.max-connections :40 network.http.max-connections-per-server :20
network.http.max-persistent-connections-per-server :20 network.http.pipelining :True
network.http.pipelining.maxrequests :32 network.http.proxy.pipelining :True Taken from here ....
Another Vulnerability Was Found In Firefox
(8) http://secunia.com/advisories/14820/ It is about JavaScript Engin, This vulnerability is rated as
Moderately critical. System information will be exposured to malicious people. Patch has not
available yet. The vulnerability has been confirmed in versions 1.0.1 and 1.0.2 Does turning off
the java script help in this suitation???? Firefox does has much user as IE, but more and more
vulnerability are found. I remember that some people said firefox is the most securest internet
browser. How about now??....
Microsoft's security program manager...
use firefox ???? (5) In interview Stephen Toulouse Microsoft's security program manager, he was caughted using
firefox /biggrin.gif" style="vertical-align:middle" emoid=":D" border="0" alt="biggrin.gif" />,
maybe ie really sucks, themselves not dare to use it... and beside it have 102012923239231 security
holes... QUOTE Meanwhile, Firefox and Opera look awfully appealing. Security is really an
industry-wide problem. Just this morning I had to install an update to Firefox to block a flaw
that would've allowed an attacker to run a program on my system. http://www.wired....
Looking for update, firefox, flaw, found, firefox
|
See Also,
*SIMILAR VIDEOS*
Searching Video's for update, firefox, flaw, found, firefox
|
advertisement
|
|