Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5

Mozilla Firefox issue
#1

http://www.eweek.com/article2/0,1759,1621463,00.asp

Mozilla Flaw Lets Links Run Arbitrary Programs
By Larry Seltzer
July 8, 2004

Updated: The Mozilla Foundation has confirmed findings that its Mozilla and Firefox browsers are vulnerable to attacks using the "shell:" scheme, which execute arbitrary code under Windows without the user having to click a link.




Security researchers are reporting another security issue in Web browsing under Windows, but this time Internet Explorer is not the culprit. The Mozilla Foundation's Mozilla and Firefox are reported as vulnerable.

The Mozilla Foundation has confirmed the problem and issued a fix, which is available here.

The reports indicate that links in a Web page using the "shell:" scheme can execute arbitrary programs on the user's system. The attacker would have to know the location in the file system of the program, but there are known programs in Windows with buffer overflows.

This means the attacker could create a link in a Web page that could execute arbitrary code under Windows. Through the use of an appropriate META tag, the attack could load without the user having to click a link explicitly.

In the definition of a URI (Uniform Resource Identifier), the technical name for a Web address, "shell:" is not a protocol like http but a scheme. Some schemes map directly to protocol handlers in the browser itself or externally, such as those that handle audio and video media.

Current versions of Mozilla and Firefox pass unknown protocol handlers to the operating system shell to handle. In this case, the location passed to the shell is a program name that the shell executes.

Other researchers reported that certain links in Mozilla could cause a denial of service in the system by causing Mozilla to open large numbers of windows and consume 100 percent of CPU capacity.

An old discussion in the Mozilla bug report database considers the possibility of addressing this problem, but the developers decided against it since the program has a facility for letting the user disallow specific external protocols and schemes, including shell:. It is not disabled by default, though.

The developers considered changing from scheme blacklisting to whitelisting, in which case all schemes and protocols would be disallowed unless explicitly allowed. Mozilla Foundation spokesmen said a future version of the browsers will change to whitelisting, but the interim fix just disables the shell protocol. Several other schemes, such as vbscript, are already disabled by default.

Internet Explorer is reported as being less vulnerable. When the user clicks on the link, it opens an "open/save" dialog box in which the user is allowed either to run the program, save it to disk or cancel. Mozilla and Firefox simply run the program without any further user action.

For insights on security coverage around the Web, check out eWEEK.com Security Center Editor Larry Seltzer's Weblog.

The shell: syntax works only on Windows XP systems. According to one report, similar functionality is available on Windows 2000 but with different syntax.

eWEEK.com tested the reported vulnerability on Mozilla Firefox and confirmed the reported behavior. We also confirmed the appearance of the open/save dialog on Windows XP SP1. In our tests on Windows XP SP2, links with the shell: protocol failed to operate at all.
Reply
#2

I just installed Firefox Confused
Reply
#3

OK, here's my beef with Firefox (and Netscape or Opera or any other browser for that matter).

Yes, other browsers can be safer than IE.

Yes, other browsers can have different features than IE (like Tabbed Browsing, genius)

Yes, IE is integrated into the OS when it shouldn't be.

BUT.. IE is INTEGRATED INTO THE OS. There is *NO* way to remove it if you run Windows. Having 2 browsers on a system, to me, is just redundant. If IE works, and works well, which it does, then why bother having another one? The *ONLY* reason I would use Firefox is for tabbed browsing, and I don't open 15 IE windows at once. Know why? I can't read 15 windows at once. Read one, close it or navigate to somewhere new. It's not very difficult.

Most people's argument for using a separate browser, especially Firefox, boils down to "Microsoft is evil! Down with huge corporations! Bill Gates is gay!" or something equally as retarded. To those people, I say slag off and get a real argument.

Redundancy is bad. Why have 2 programs that function, for all intents and purposes, the same, when you have one that is BUILT INTO THE OS that does it just fine? It's already part of the OS, you can bitch about it if you want, but that's not going to change. Use it.
Reply
#4

Probably a story generated by Gates. Fuck Microsoft. I'm a MAC man! However, I have to use Microsoft Office for system X. Word crashes like clockwork. I think the fuckers plan it that way.

We all had Mozilla installed on the computers at the office because of the worm in Explorer. I think we ought to hunt down THESE terrorists who make these bugs and make them kiss girls as punnishment. Pansy assholes.

<img src='http://img.photobucket.com/albums/v92/bonkyboy/bonky/Wshing.jpg' border='0' alt='user posted image' />
Reply
#5

Aren't there many more features than just tabbed browsing (which i happen to like)?

Ty, I see that you're be against using firefox, but is that just do to your personal preference or because of the potential security problems you just mentioned?

[Image: boston.jpg]
Reply
#6

Quote:Originally posted by TyrionXavier@Jul 9 2004, 09:25 AM
Redundancy is bad.&nbsp; Why have 2 programs that function, for all intents and purposes, the same, when you have one that is BUILT INTO THE OS that does it just fine?&nbsp; It's already part of the OS, you can bitch about it if you want, but that's not going to change.&nbsp; Use it.
Redundancy in terms of software is only bad is the software is intensive. Have you removed Notepad and Wordpad from your system because you have MSWord? Fireforx, or Opera, or Netscape, aren't intensive enough to worry about redundancy.

For me, probably the most important reason for installing Firefox was history. When I need a coworker to sit at my computer and help me out, or look at something work related we use IE. I don't have to worry about anything embarassing from the history bar showing up cause all of that is done in Firefox.

Tabbed Browsing. This is brilliant. And are you seriously telling me you only ever have ONE browser window open? I currently have five IE windows open, and Mozilla. Now, I am not reading all six windows simultaneously, but when I get a second and want to finish that article on Wired News its sitting there waiting.

Not bitching about IE being part of the OS and rolling over and accepting it does what? Well it encouages MS and could potentially stop other people from putting out browsers for windows. What happens then? We're stuck with whatever crap MS decides to put out? And crap is what they will put out when there isn't competition, whether or not they intend to. People choosing not to use IE just because it is in the OS, but rather installing the software they want (be it for security reasons, or featuresets) is going to keep these browsers guys working and innovating.

Come to think of it, I don't get the whole "browser war" thing. I have NEVER paid for a web browser, so why the big deal about market share? It's not like having people use Firefox instead of IE is going to hurt MS or help Mozilla. Confused
Reply
#7

Where there's a will......No browser is safe. IE is the most prominent, and is therefore the most exposed. If the other browsers and OS' were as prominent, they would be attacked as often.

The other browsers are equally susceptible, I guarantee it.

All systems are flawed, including MAC. Why? Because they're created by humans.

There is this industry called Computer Software. In this industry software is developed and sold. Until the software is sold, the companies developing the software are incurring endless costs. They have a budgeted timeframe that they must start seeing return on their investment. They therefore release the software before it is completely bug free. Meanwhile, some of the known bugs are being addressed and the development team is busy creating the first service pack or hotfix. The cycle is endless. Why? Because when you are talking about developing a piece of software using teams and teams of individual programmers, you will NEVER create a bug-free application.

Just sayin'.
Reply
#8

i'm still happy with my browser. at least mozilla doesn't have built in spyware.
Reply
#9

Quote:Originally posted by bdic@Jul 9 2004, 10:10 AM
Where there's a will......No browser is safe.&nbsp; IE is the most prominent, and is therefore the most exposed.&nbsp; If the other browsers and OS' were as prominent, they would be attacked as often.

The other browsers are equally susceptible, I guarantee it.

All systems are flawed, including MAC.&nbsp; Why?&nbsp; Because they're created by humans.

There is this industry called Computer Software.&nbsp; In this industry software is developed and sold.&nbsp; Until the software is sold, the companies developing the software are incurring endless costs.&nbsp; They have a budgeted timeframe that they must start seeing return on their investment.&nbsp; They therefore release the software before it is completely bug free.&nbsp; Meanwhile, some of the known bugs are being addressed and the development team is busy creating the first service pack or hotfix.&nbsp; The cycle is endless.&nbsp; Why?&nbsp; Because when you are talking about developing a piece of software using teams and teams of individual programmers, you will NEVER create a bug-free application.

Just sayin'.
I couldn't agree more. We're about to ship a product to our (internal) customer's with a whole list of "known issues"; bugs we'll fix next time around. If they wanted to wait until we got it perfect they might never get a product
Reply
#10

Quote:Originally posted by leucetios@Jul 9 2004, 03:25 PM
I couldn't agree more. We're about to ship a product to our (internal) customer's with a whole list of "known issues"; bugs we'll fix next time around.&nbsp; If they wanted to wait until we got it perfect they [b]would never get a product [/b]
FTFY
Reply
#11

Quote:Originally posted by Suicide Jim@Jul 9 2004, 03:17 PM
i'm still happy with my browser. at least mozilla doesn't have built in spyware.
I always considered you to be one of the least naive at these boards. Hmmm.
Reply
#12

Preach on Brother bdic
Reply
#13

then explain to me why with explorer when i got to a site with no pop ups, not even a sponser, i got pop up windows. now, with out making any alterations to my pc aside from adding mozilla, i don't get the pop ups any more. don't belive me? go to maddox.xmission.com with explorer. and enjoy your pop ups.
Reply
#14

Quote:Originally posted by Suicide Jim@Jul 9 2004, 04:10 PM
then explain to me why with explorer when i got to a site with no pop ups, not even a sponser, i got pop up windows. now, with out making any alterations to my pc aside from adding mozilla, i don't get the pop ups any more. don't belive me? go to maddox.xmission.com with explorer. and enjoy your pop ups.
No popups for me either. And my popup blocker didn't go off.

But whether or not one browser may or may not block certain pop-ups, does not discredit my original statement, nor does it qualify your original statement.
Reply
#15

fuck it. i'm to sleepy right now to give a shit either way.
Reply


Possibly Related Threads…
Thread / Author Replies Views Last Post
Last Post by JCW
06-07-2010, 04:12 PM
Last Post by ntype
10-03-2006, 11:07 AM
Last Post by ntype
02-22-2006, 06:18 PM
Last Post by greg
02-12-2005, 02:04 AM

Forum Jump:


Users browsing this thread: 1 Guest(s)