Welcome Guest ( Log In | Register )



3 Pages V   1 2 3 >  
Reply to this topicStart new topic
> Vulnerability Was Found In All Major Browsers, Spoofing Flaw affect IE, Firefox, Safari
jedipi
post Jun 22 2005, 02:10 AM
Post #1


Premium Member
Group Icon

Group: Members
Posts: 352
Joined: 2-March 05
From: Australia
Member No.: 2,859



According eWeek.com, a new vulnerability was found in all the major Web browsers ( IE, Firefox, Safari).
This Spoofing Flaw can be exploited by malicious hackers to trick surfers into disclosing confidential information.
QUOTE
"The problem is that JavaScript dialog boxes do not display or include their origin, which allows a new window to open a prompt dialog box, which appears to be from a trusted site,"


Here is the place for you to test your broswer whether vulnerable or not.
http://secunia.com/multiple_browsers_dialo...erability_test/

source:
http://www.eweek.com/article2/0,1759,1830025,00.asp
Go to the top of the page
 
+Quote Post
chiiyo
post Jun 22 2005, 02:53 AM
Post #2


Premium Member
Group Icon

Group: Members
Posts: 218
Joined: 14-March 05
From: Singapore
Member No.: 3,041
myCENTs:92.74



Oh dear, this sounds pretty serious. All my browsers are vulnerable... O-o. Wonder whether there'd be any patch soon?
Go to the top of the page
 
+Quote Post
jcguy
post Jun 22 2005, 04:36 AM
Post #3


Premium Member
Group Icon

Group: Members
Posts: 382
Joined: 5-September 04
Member No.: 255



Hmmn... I'm wondering, if these security flaws were not made public, would potential hackers have found out about and sicovered the flaw? Do they go about engineering and looking at the source code to disocver new flaws?
Go to the top of the page
 
+Quote Post
saxsux
post Jun 22 2005, 11:47 AM
Post #4


Bursting with vegany goodness!
Group Icon

Group: Members
Posts: 342
Joined: 8-April 05
From: Norwich, UK
Member No.: 3,753
myCENTs:10.76



I honestly don't see how that is a security problem. Surely even a completely inexperienced computer user would notice the new window opening when they clicked the link. Even if they didn't, who would be stupid enough to enter bank account details into a completely unsecure javascript dialogue?

To be honest, I doubt scammers will be adopting this method quite soon smile.gif
Go to the top of the page
 
+Quote Post
chiiyo
post Jun 22 2005, 01:32 PM
Post #5


Premium Member
Group Icon

Group: Members
Posts: 218
Joined: 14-March 05
From: Singapore
Member No.: 3,041
myCENTs:92.74



Hmm, I don't know, for me the very fact that they can open a unnamed javascript window on top of a verified site is still rather disturbing. Yes, even a new computer user would notice the new window opening, but it's not the noticing the new window, it's more of if the hacker decides to exploit the vulnerability, makes his pop-up dialog box really authentic-looking, and thus gets information from not-so-experienced computer users, and then use that information. I mean, I think people like my dad or my brother, though they are not total-computer-idiots, might fall for a dialog box that seems to come from Google.com or Amazon.com asking for passwords or stuff like that.
Go to the top of the page
 
+Quote Post
jedipi
post Jun 25 2005, 08:09 AM
Post #6


Premium Member
Group Icon

Group: Members
Posts: 352
Joined: 2-March 05
From: Australia
Member No.: 2,859



I just saw this new in C|Net News.com.
[quota]
Microsoft does not plan to update Internet Explorer to prevent a spoofing attack that could trick users into giving out personal information to hackers.
[/quota]

Is it just because thuse they don't deem them a high risk??
Do you believe this article??
I am quite surprise, microsoft won't issue an update for IE.

it makes IE is the worst browser right now.

source:
http://news.com.com/IE+pop-up+spoof+wont+g...ml?tag=nefd.top
Go to the top of the page
 
+Quote Post
HanginNerd
post Jun 26 2005, 12:48 AM
Post #7


Newbie [ Level 1 ]
Group Icon

Group: Members
Posts: 3
Joined: 26-June 05
Member No.: 6,590



Firefox's Javascrips Is Kinda Messed Upp Dont Ya Think ???? XX
Go to the top of the page
 
+Quote Post
geancanach
post Jun 28 2005, 09:19 PM
Post #8


Newbie [ Level 2 ]
Group Icon

Group: Members
Posts: 12
Joined: 31-May 05
Member No.: 5,632



and this is just one more reason why i have javascript disables in all my browsers. i didnt get the prompt so i assume i dont have that particul insecurity to worry about
Go to the top of the page
 
+Quote Post
MajesticTreeFrog
post Jun 29 2005, 04:09 AM
Post #9


Super Member
Group Icon

Group: Members
Posts: 692
Joined: 25-November 04
Member No.: 1,523



As more such problems are discovered, programmers will learn to be more and more security savvy. Open source has the best chances though. The people who are open source tend to care about security, and having their programs work. So, it will probably get fixed in FF in the not too distant future. IE may have to wait till version 7, whenever the hell that comes out.
Go to the top of the page
 
+Quote Post
runefantasy
post Jun 29 2005, 04:24 AM
Post #10


Member - Active Contributor
Group Icon

Group: Members
Posts: 90
Joined: 29-June 05
Member No.: 6,693



Oof. Thanks for the example you provided. Now I know what it looks like. Good thing banks don't use JS prompts, or hackers could steal credit card information. Hope Microsoft fixes it soon smile.gif (maybe 2006 when IE7 and Longhorn comes out)
Go to the top of the page
 
+Quote Post

3 Pages V   1 2 3 >
Fast ReplyReply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Microsoft's security program manager...(5)
  2. Firefox Speed Tweaks(15)
  3. Critical Flaw Found In Firefox(5)
  4. Update Your Firefox!(8)
  5. Ms Sec. Advisory: Flash Player 7 Vulnerability(1)
  6. Apple Itunes Security Flaw Discovered(4)
  7. Microsoft Confirms Wmf Vulnerability(7)
  8. IE6 & IE7 Beta 2 Address Bar Spoofing Exploit(4)
  9. Password Reset Vulnerability(3)
  10. New Firefox Update 1.5.0.4(10)
  11. Ld Window Injection Flaw Reappears In Ie 7(7)
  12. Microsoft Xmlhttp Activex Control Code Execution Vulnerability(0)
  13. MS Windows CSRSS Vulnerability(4)
  14. phpBB avatar_path PHP Code Execution Vulnerability(3)
  15. Winzip ActiveX Control Remote Code Execution Vulnerability(2)
  1. How To Double Firefox Speed(5)
  2. Foxtorrent: Download Torrents From Within Firefox(1)


 



- Lo-Fi Version Time is now: 5th December 2008 - 03:24 PM