Security Software Critcial FireFox flaw exposed

Status
Not open for further replies.

octave

Discoverer
Tgdaily
According to media reports, a pair of hackers said on Saturday that the Firefox Web browser, commonly perceived as the safer and more customizable alternative to market leader Internet Explorer, is critically flawed. A presentation on the flaw was shown during the ToorCon hacker conference in San Diego.

The hackers claim that anyone running Firefox could be a victim of the flaw, which is related to the browser's handling of the Internet language JavaScript. Reportedly, someone could create a Web page with malicious JavaScript code that would specifically affect computers running Firefox browsers. The hackers, Mischa Spiegelmock and Andrew Wbeelsoi, claim that this could lead to remote control of any affected computer, including Windows, Apple, and Linux systems.

Spiegelmock reportedly said that the JavaScript implementation is a "complete mess" and that it is "impossible to patch." Upon watching a video of the presentation, Window Synder, Mozilla's security chief, said that this issue appears to be a "real vulnerability".

Reportedly, Snyder is also understandably upset about the public flow of this information, claiming that the details presented during the conference almost completely show how one could exploit the flaw. "I think it is unfortunate because it puts users at risk, but that seems to be their goal," she said.

Jesse Ruderman, another member on the Mozilla security staff, persuaded hackers to disclose any potential security holes via their "bug bounty" program, instead of maliciously exploiting them for hijacking vulnerable computers. Mozilla's bug-reporting system gives $500 to anyone who reports a vulnerability to the Firefox staff.

Firefox was originally introduced as an alternative to Internet Explorer, the browser that has long been known for easy exploiting and distribution of worms and viruses. Because Microsoft's browser contains such an enormous userbase, it has always remained the main target for hackers. However, Firefox's audience has been growing and it is becoming a viable target for hackers.
 
KingKrool said:
Already posted before.

sorry did not look at the applications section. i thought any security flaw/threat needs to be posted here(i may be wrong though).

Tgdaily's follow up:The Firefox exploit that wasn't - Hackers backpedal

The much reported Firefox vulnerabilities and exploits from the Toorcon computer security conference appear to be greatly exaggerated. A pair of hackers claimed to have found 30 undisclosed vulnerabilities on the popular browser and even boasted that they could execute malicious code. Now, one of the hackers, Mischa Spiegelmock, has apologized for the talk, saying that its main purpose was "to be humorous"

Despite the exaggerations, Mozilla is leaving nothing to chance and Window Snyder, Mozilla's chief of security says, "We still take this issue seriously. We will continue to investigate".

Since the guys @ mozilla are still taking it seriously and investigating i dont see a need to close the thread or even delete the thread.
 
Status
Not open for further replies.