FireFox Vulnerability

Having problems installing that new stick of memory? Found some great software or having issues with something? Or maybe want to chat about your PlayStation, X-Box, Nintendo, Sega, even your old Spectrum 48k....! Or maybe something you want to sell or acquire (computing related of course!). Let us know here...
Post Reply
UBT - Halifax-lad
Posts: 3790
Joined: Mon Mar 13, 2006 12:00 am

FireFox Vulnerability

Post by UBT - Halifax-lad »

UBT - Mikee
Marvin the Dalek
Posts: 4396
Joined: Wed Mar 15, 2006 12:00 am
Location: North Wales

Post by UBT - Mikee »

That's a bit scary.

Apparantly, the easy fix is NOT to go to any Java pages, but as that's a bit impracticle install a 'noScript' extension. Will only allow Java if you say so. Not perfect as a page you allow may have malicious code in it anyway unless it's a site you know of.

This has got some good feedback if anyone wants to try it!
Follow us on Twitter... http://twitter.com/UKBOINCTeam

Image Image

Image
UBT - Halifax-lad
Posts: 3790
Joined: Mon Mar 13, 2006 12:00 am

Post by UBT - Halifax-lad »

Update: Possible Vulnerability Reported at Toorcon
We got a chance to talk to Mischa Spiegelmock, the Toorcon speaker that reported the potential javascript security issue referenced earlier.  He gave us more code to work with and also made this statement and agreed to let me post it here:

The main purpose of our talk was to be humorous.

As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has.

I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code.

I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.

I apologize to everyone involved, and I hope I have made everything as clear as possible.

Sincerely,

Mischa Spiegelmock

Even though Mischa hasn’t been able to achieve code execution, we still take this issue seriously.  We will continue to investigate.

-Window Snyder
Post Reply