CyberNet News
Please login or register.

Login with username, password and session length
Pages: [1]   Go Down

Author Topic: Password vulnerability in Firefox 2.0.0.5  (Read 1255 times)

0 Members and 1 Guest are viewing this topic.

xpgeek

  • Sr. Member
  • ****
  • Reputation: 19
  • Posts: 526
    • View Profile
    • WWW
Password vulnerability in Firefox 2.0.0.5
« on: July 23, 2007, 02:12:52 PM »
From TechSpot :

Quote
A very short time after Mozilla released an update for Firefox to combat security issues brought about by IE, it seems they are already combating yet another flaw. The newly-discovered but not likely new flaw could potentially result in having a password stolen:

”...the latest version of Firefox, 2.0.0.5, contains a password management vulnerability that can allow malicious Web sites to steal user passwords. If you have JavaScript enabled and allow Firefox to remember your passwords, you are at risk from this flaw.”
On top of Firefox, it seems that Safari is vulnerable in the same way. Being compromised in such a fashion requires certain things to be true, such as the site in question enabling JavaScript (and the site trying to steal your password to begin with). With JavaScript disabled, the flaw can't be exploited.

There is a demo of the flaw available in which you can check to see if you are vulnerable. It seems that some are questioning whether the “flaw” really is such, and whether it should be fixed at all, since certain pages could steal passwords with or without the built-in password manager's help.

Go to the 'demo of the flaw link' there and can test it. Yep, it works.

I then installed the extension Secure Login and tested again, nope doesn't work now. So definitly keeping that extension installed.
Logged

Ryan Wagner

  • Administrator
  • Hero Member
  • *****
  • Reputation: 51
  • Posts: 3404
    • View Profile
    • WWW
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #1 on: July 23, 2007, 04:01:18 PM »
Thanks for the tip on the extension. Firefox should really offer an option as to whether users want to actually have the form automatically filled in.
Logged

Chris Rossini

  • Full Member
  • ***
  • Reputation: 9
  • Posts: 413
    • View Profile
    • WWW
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #2 on: July 23, 2007, 05:28:31 PM »
I never use this feature for any browser...You just never know.
Pages: [1]   Go Up
« previous next »