Welcome Guest ( Log In | Register )



3 Pages V  < 1 2 3 >  
Reply to this topicStart new topic
> Firefox 2/IE7: Beware Of Using Password Manager
Niru
post Nov 25 2006, 04:28 AM
Post #11


Advanced Member
Group Icon

Group: Members
Posts: 190
Joined: 18-August 06
From: Fun.NiranVv.Com
Member No.: 15,325
myCENTs:41.60



thanks for the info friend!
I never use those bult in password managers in IE and Firefox!

I used to go with AI Roboform http://www.roboform.com/
Its a rocking software, and its compatible with all those major browsers like:
IE, Firefox, Mozilla, Netscape 7, Netscape 8, SeaMonkey, Flock

QUOTE
Complete List of Supported and Not Supported Browsers

If browser is listed and the line does not say that it is not supported, then browser is supported.
If you do not see your favorite browser in this list, let us know.

4cvision
550access
Abolimba
Accutrade
Ace Explorer
Adorama Print Wizard
Advanced Browser
AM Browser
AOL browser
AOL client
AOL Explorer
Avant -- with RoboForm toolbar
Auction Sentry
Auction Tamer
Bay Office
BigOven
Bingooo
BroadPage
BT + Yahoo browser
Bubbles (IE mode)
Cayman Browser
Chaos !ntellect
Compuserve ver 6 or less -- supported
Compuserve ver 7 -- NOT supported
Copernic
Crazy Browser
DeepNet
Donut (JP)
DonutP
DonutQ
DX Browser
E2 by VNcom
EarthLink Browser
Enfish OneSpace
Enigma Browser
Explorer 2002
Expensable
Fast Browser
FastStone
Firefox -- Adapter required
Flock -- Adapter required
Front Page
Fun Browser
GoSurf
Grani
Green Browser
GuruNet FactFinder
Ideal Browser
IE Opera
Internet Explorer -- with RoboForm toolbar
Internet Surfer
iPostage
iRider
iTreeSurf
jBrowser
Juno
KIKI (JP)
KK Man
Kontiki
K-Meleon -- NOT supported
LunaScape (JP)
m9P Surfer
MaxThon -- with RoboForm toolbar
Medical Browser
Money (MS)
Moon Browser (JP)
Motive Browser
Mozilla -- Adapter required
MSN ver 6 to 9
MSN TV -- NOT supported
MusicMatch Jukebox
MyIE2 -- with RoboForm toolbar
MyWeb4Net
Napster
NeoPlanet
NetCaptor (with RoboForm toolbar)
Netscape ver 4 -- NOT suported
Netscape ver 7 -- Adapter required
NetSurf
Oligo
Opera -- NOT supported
Optimal Desktop
Outlook (MS)
Public Web Browser
Quicken (Pro)
QuickBooks
People PC
RealOne Player
Research Desk by Winferno
Paid Help
Paragon Last Minute
PC Health
PhaseOut
PSP 8 Register
SAP logon
Safari -- NOT supported
SBC + Yahoo browser
Secure IE
Sleipnir (IE mode)
Slim Browser -- with RoboForm toolbar
Smart Explorer
SnipeRight
SR Browser
SurfBoard by HP
Sweepstakes Online
Tablane
Tabrowser
TG Games
TenCent Browser
TextBrowser (JP)
Tiscali Browser
T-Online Browser
TurboSweeps
Ultra Browser
UltraRecall
unDonut (JP)
WalMart Connect
Wanadoo Browser
WebMA (KR)
WebMoney
WebSite Watcher
WebSpeedReader
Wichio
Windows Media Player
WinFerno
Wysigot
Yahoo Browser
Yahoo Music Engine
ZapTastic



But one sad news is, RoboForm does not work with the Opera browser. sad.gif

It can, fill personal informatn into online forms, can Generate Secure Random Passwords, Encrypt passwords and personal data using powerful encryptn algorithms like, AES, Blowfish, RC6, 3-DES or 1-DES..
Using that you can Backup & Restore, Print your passwords! Using that you can autoSave passwords in browser, AutoFill passwords to login form!
And you don't need to enter any one character in the address bar to login to any of the website!
Just click the desired Roboform login account! That will open the desired address, and autofill the login forms, and will submit the forms!
Go to the top of the page
 
+Quote Post
Alegis
post Nov 25 2006, 11:14 AM
Post #12


Premium Member
Group Icon

Group: Members
Posts: 300
Joined: 25-May 06
Member No.: 13,654



I do use the password manager, but stopped using addons such as gmail notifier for firefox (got the desktop one from google instead) as other addons would have been able to access my gmail login info then.

Well. I'm not using virus scanner and the likes either as I know what I'm doing, which sites I visit - so I'm not panicking. They'll fix this soon enough. Eitherway I love the password manager.
Go to the top of the page
 
+Quote Post
black shadow
post Nov 25 2006, 05:12 PM
Post #13


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 19
Joined: 25-November 06
Member No.: 17,565



I don't think thats true, a lot of ppl use the FF password manager and nothing happened i ain't so sure about IE since it sucks you may lose your password tongue.gif but it's highly unlikely, maybe if you visit porn and warez type of sites that have all sorts of trojans and stuff.
Go to the top of the page
 
+Quote Post
saint-michael
post Nov 26 2006, 07:39 AM
Post #14


SM- the Man -The Myth - The Legend Himself
Group Icon

Group: Members
Posts: 457
Joined: 4-September 05
From: Drinking da rootbeers
Member No.: 8,313
myCENTs:72.48



Interesting little post, Lucky for me I can tell a fake from a legit site and I only save my passwords to very specific sites and what not.
Go to the top of the page
 
+Quote Post
kgd2006
post Nov 26 2006, 10:07 AM
Post #15


Premium Member
Group Icon

Group: [HOSTED]
Posts: 318
Joined: 1-March 06
Member No.: 11,638



Thanks for the tip micro, Im a firefox and IE7 user and I sometimes use the password manager now I am considering not to use it completely because of this post. Dont want to run the risk of having people making my life harder than it already is. thanks again for the helpful hint...
Go to the top of the page
 
+Quote Post
seec77
post Nov 26 2006, 11:38 AM
Post #16


Advanced Member
Group Icon

Group: Members
Posts: 157
Joined: 16-May 06
Member No.: 13,476



I might be missing something big here, but from the way I see it, miCRoSCoPiC^eaRthLinG is spreading lots of FUD!
Phishing is a long known phenomenon that involves crafting a fake website to look like a legitimate website and thus lure (or "fish") naive users into logging in with sensitive information, such as credentials or billing information, to the hacker's server, thus basically giving him away your bank account or whatever else.

Let me expand on this concept with an example. Imagine you have an account over at Neopets. For those who don't know, NP is a virtual pet site, where you can raise your pet and collect money and items. Say you have been slaving over this account for ages, accumulating vast amounts of "neopoints" (the site's fictional currency) and other valuable items, and training your "neopet" in various activities. Now, say some immature kid is trying to deceive you into letting him access your account. He will create a page that looks exactly like the Neopets login page, and give you the link to it, but when you log in it actually sends your password over to his computer, which he can then use to steal your account.

There are many ways to "phish" users to a fake page. Many include tricks and psychological games that will only work on computer users who are not very tech-savvy. Obviously, browsers can not defend against this phenomenon in 100%, because how can a browser know if a page is legitimate or fake? Maybe Cross-site scripting can be found by a piece of software, but that's just one of many methods of phishing. This is not a "bug" in Fx or IE, because it is the user's naivity that leads to ingenuousness that leads to the vulnerability that these types of attacks cause.

Apart from the fact that you really can't blame the browsers for these problems, Firefox 2 and Internet Explorer 7 both feature phishing protection in the form of validating websites against a list of known harmful pages (Fx actually gets its list from the all-mighty Google). So don't go denouncing any browser for their "vulnerability" to phishing! Oh, and by the way, for all you Opera zealots: Opera will only feature fraud protection in version 9.1 which hasn't been released yet, and it will be turned off by default.

Maybe I wrote this whole post just because I didn't understand something in this topic, but from what I can see a lot of critical information has been missing here!! Sorry. tongue.gif
Go to the top of the page
 
+Quote Post
Arbitrary
post Nov 29 2006, 05:53 AM
Post #17


Premium Member
Group Icon

Group: [HOSTED]
Posts: 381
Joined: 17-June 06
From: Adblock life
Member No.: 13,992



@seec77, I think miCRoSCoPiC^eaRthLinG's point was that because of the way Firefox/IE7 was designed, when you do visit one of those phishing sites that try to steal your password, they can directly access your password manager the minute they ask you to fill out a form.

So basically it's like you go to that fake Neopet's site, attempt to login with your username and password, and then your Neopet's username and password along with all usernames and passwords stored in your password manager are sent to the phisher.

Browsers in this case can be blamed since it's their password managers that the vulnerable ones. If they somehow changed the architecture of their password manager, then maybe people would feel safer using them.

Anyways, I guess I'm now kind of scared, so maybe I'll start deleting my passwords from my password manager now. smile.gif And I'm seriously beginning to doubt the Gmail Manager. I mean, sure, it looks great and all, but maybe it'd be smarter just to download the prestigious Google's manager.
Go to the top of the page
 
+Quote Post
miCRoSCoPiC^eaRt...
post Nov 29 2006, 07:46 AM
Post #18


PsYcheDeLiC dR3aMeR
Group Icon

Group: Admin
Posts: 2,242
Joined: 29-January 05
From: Nakorn Chaisri, Thailand
Member No.: 2,411
myCENTs:84.36



QUOTE(seec77 @ Nov 26 2006, 06:38 PM) *

Let me expand on this concept with an example. Imagine you have an account over at Neopets. For those who don't know, NP is a virtual pet site, where you can raise your pet and collect money and items. Say you have been slaving over this account for ages, accumulating vast amounts of "neopoints" (the site's fictional currency) and other valuable items, and training your "neopet" in various activities. Now, say some immature kid is trying to deceive you into letting him access your account. He will create a page that looks exactly like the Neopets login page, and give you the link to it, but when you log in it actually sends your password over to his computer, which he can then use to steal your account.


Now let me explain a little bit on how this Password Manager vulnerability compares to common phishing attacks. What you've stated is the most common mode of phishing - that someone creates a popular site lookalike BUT usually at a different similar sounding URL and then tricks the users into following that url, thus revealing their login credentials.

However, this exploit can happen over VALID URLs and hence even careful users might fall into the trap. Here's an example --> A lot of the popular Social Networking sites have started offering you human-readable links to the member profiles, rather than the cryptic php variable based dynamic URLs. Currently MySpace, Hi5 etc. all offer you such links.

Example:
MySpace: http://www.myspace.com/microscopic-earthling
Hi5: http://microscopic-earthling.hi5.com

Comapred to this earlier on the links took the form: http://www.social_network.com/index.php?profileid=xxxx

While the new URLs are clearly legible and easy to remember, they've opened up a new avenue of exploit.

As I said, earlier on a phisher would have to trick an user into following to the phishing URL - but since the domain name would be different, Password Managers wouldn't pop-up on their own and/or offer to fill the forms.

The browser pass managers essentially rely on the Domain Name + Form Elements combo to fill the pages. You might have noticed that if the name of a certain form element (say login/password inputboxes) change on a page - the password managers won't be able to fill them up properly.

Anyway, supposing the login page for MySpace is:
http://www.myspace.com/login_form.html

With the new Profile URL scheme, I can easily create a profile that looks like:
http://www.myspace.com/login_form_html
... and install an exact copy of the myspace login form there instead of my profile and then make it redirect to my own database for storing the username/passes.

Since the DOMAIN is the same and so are the FORM ELEMENTS, the Password Managers are fooled into believing that they've reached the valid login page and this fills up the form without thinking twice. Come to think of it - this approach can even fool careful users, who might not notice that the "." before html was replaced by a "_".

The whole point of this panic is that the pass managers don't validate the URLs properly before form fill-up - for some reason the coding for form-fillup is extremely loose & sloppy. It's really funny - why none of the coders ever thought of this before !! It's quite an evident validation issue. Hopefully it'll be rectified soon smile.gif

And hope that explains why this isn't a baseless issue of FUD tongue.gif and why people should think twice before using the existing pass managers - till the fixes are released.

Cheers,
m^e
Go to the top of the page
 
+Quote Post
Quatrux
post Nov 29 2006, 04:06 PM
Post #19


the Q
Group Icon

Group: [HOSTED]
Posts: 1,133
Joined: 13-July 05
From: Lithuania, Vilnius
Member No.: 7,059
myCENTs:5.70



But as I know, say on Opera I can choose to use the password and login for entire domain or just for that file/url/address accessed, so that means domain.net/login.html and login.domains.net will be different, even if the address changed to domain.net/login_x.html But if you choose to use the same login information for entire domain, when it will only check for the form input names and stuff.. But I usually browse services I trust and never did get this kind of password, but whats the difference if the login will be made automatically with password manager or manually with hand, you will still send the password if you didn't see that the login page is actually not login.html but login_x.html ... As I know the password manager only works on Opera when you click CTRL+Enter and on Firefox only when you push submit button with chosen automatic logins, it is just easier for you and you don't need to waste time entering the same username and password again.. :F
Go to the top of the page
 
+Quote Post
seec77
post Dec 2 2006, 10:56 AM
Post #20


Advanced Member
Group Icon

Group: Members
Posts: 157
Joined: 16-May 06
Member No.: 13,476



Alright, so I figured out in my earlier post that I probably had something misunderstood about the topic, and now I understand it was true, so sorry about my long rant!

@m^e: You forgot to mention XSS, which I think can also trick your password manager into giving out your credentials to fishing sites! But I can definitely see the problem now with password managers. I still think that's it a bit of FUD, though, that you made users on these sites untrustful of IE and Fx.

I think that Opera's method, as Quatrux said, of having to press Ctrl+Enter for the password manager to do its thing is smart. Besides from that, it is missing a phising protector, unlike Fx and IE.
Go to the top of the page
 
+Quote Post

3 Pages V  < 1 2 3 >
Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Modem Missing In Device Manager(7)
  2. Assign Keyword To Firefox Bookmarks(3)
  3. How To Disable Password Expiration (xp)(8)
  4. Why You Should Use Firefox...(6)
  5. Make Firefox Look Like Internet Explorer(12)
  6. Ie Tips: To Delete Lost Supervisor Password(1)
  7. What Is Firefox ?(2)
  8. Firefox Update(7)
  9. Firefox Or IE (New Version): Which One Is Better?(71)
  10. Make Sure, Your Name Will Be There On Firefox 2 Wall(7)
  11. Firefox Updated To FX Ver 2.0.0.1(6)
  12. Load Firefox Faster(1)
  13. E-mail - Firefox(6)


 



- Lo-Fi Version Time is now: 5th December 2008 - 05:20 PM