Go Back   Novahq.net Forum > Off-Topic > General Chat
FAQ Community Calendar Today's Posts Search

General Chat Talk about anything that does not fit into other topics here.

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 09-09-2005, 08:47 AM
General Nuisance is offline General Nuisance
Registered User

Join Date: Oct 2004
Posts: 616

Send a message via ICQ to General Nuisance
eek Firefox unpatched!

found this..

-----

A new, unpatched flaw in that affects all versions of Firefox could let attackers surreptitiously run malicious code on users' PCs, a security researcher has warned.

The problem lies in the way Firefox handles Web links that are overly long and contain dashes, security researcher Tom Ferris said in an interview via instant messaging late Thursday.

He posted an advisory and a proof of concept to the Full Disclosure security mailing list and to his Security Protocols Web site.

The security vulnerability is a buffer overflow flaw that "allows for an attacker to remotely execute arbitrary code" on a vulnerable PC, Ferris said. An attacker could host a Web site containing the malicious code to exploit the flaw, he said. Though his proof of concept only crashes Firefox, Ferris claims he has been able to tweak it to run code.

Buffer overflows are a commonly exploited security problem. They occur when a program allows data to be written beyond the allocated end of a buffer in memory. A computer can be made to execute potentially malicious code by feeding in extra data that is designed to flood the buffer.

Ferris reported the bug to the Mozilla Foundation on Sunday, intending to go through the organization's bug-reporting process, he said. However, in an example of the uneasy alliance between security researchers and software makers, he decided to publicly disclose the flaw after a run-in with Mozilla staff, he said.

Mozilla, which coordinates development of Firefox and distributes the software, could not immediately comment on the flaw disclosure. However, a source close to the organization confirmed that Ferris had filed several bug reports, including this specific one.

Since the debut of Firefox 1.0 in November, usage of the open-source browser has grown. Security has been a main selling point for Firefox over Microsoft's Internet Explorer, which has begun to see its market share dip slightly--for the first time in years.

However, Firefox has had its own security woes. Several serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist

The public bug disclosure comes just as Mozilla released the first beta of Firefox 1.5. The final release of the next Firefox update, which includes security enhancements, is due by year's end, according to the Firefox road map.

Ferris has found bugs in Microsoft software before, including a yet-unpatched flaw in Internet Explorer that Microsoft still has under investigation.

Earlier this month Microsoft credited Ferris with reporting a bug in a Windows feature called Remote Desktop Protocol that could allow an attacker to remotely restart Windows systems.

------------

source: http://news.com.com/Unpatched+Firefo...l?tag=nefd.top
__________________
The Nova-Zone


http://youraite.yourhost.yourusername.com - long urls
-looks bad
-who can remember it?
- Solution?
- Get a short Nova-Zone subdomain! Yoursite.nova-zone.com
- Now thats smart. just ask for one via pm,email or contact page on site.
Reply With Quote
  #2  
Old 09-09-2005, 09:44 AM
atholon is offline atholon
"ath-hole"

Join Date: Jan 2003
Location: Failville.
Posts: 11,357

Send a message via MSN to atholon
You can never be completely safe but it is good that people are trying to make it better.
__________________
Reply With Quote
  #3  
Old 09-09-2005, 01:45 PM
VooDoo- is offline VooDoo-
VooDoo-'s Avatar
Registered User

Join Date: Jan 2004
Location: Florida
Posts: 2,896

well .. it can't be worse then IE ..
__________________
Reply With Quote
  #4  
Old 09-09-2005, 03:21 PM
Lucky is offline Lucky
Registered User

Join Date: Aug 2004
Posts: 4,705

Quote:
Originally posted by VooDoo-
well .. it can't be worse then IE ..
true
__________________
Reply With Quote
  #5  
Old 09-10-2005, 05:57 AM
BADDOG is offline BADDOG
resigned

Join Date: Mar 2002
Posts: 7,050

Quote:
Originally posted by atholon
You can never be completely safe but it is good that people are trying to make it better.
I couldn't agree more Ath!!!!

Warm Regards
Reply With Quote
  #6  
Old 09-10-2005, 08:46 AM
katana*GFR* is offline katana*GFR*

Join Date: May 2002
Location: North Sea
Posts: 2,421

Send a message via ICQ to katana*GFR* Send a message via MSN to katana*GFR*
I agree with ath also, and i think FF is better then IE, just for the fact flaws and errors in the code are fixed quicker then in IE..
__________________
<- Sponsored by Chris



Found on Youtube:
Quote:
And if Newton Faulkner's voice can be described as "R&B" then Kurt Cobain must be a member of Boyz II Men.
Link here
Reply With Quote
  #7  
Old 09-10-2005, 02:03 PM
Hellfighter is offline Hellfighter
Hellfighter's Avatar
Chief ADFP

Join Date: Jun 2002
Location: San Jose Calif 95111
Posts: 21,143

Send a message via ICQ to Hellfighter
if its in your PC a hacker will get their dirty hands into it, you can bit on that one.

Browsers, games, offices software, hackers love to "f" them up big time, they don't care.

you know what i don't care if a child or a full grown adult who is doing it, slam them in Fed/jail house rock for life or at lease 20yrs to max 40yrs. time they get out all computer system be anew stander and they be out dated
=========================================
on the lighter side of life last night i seen at a club two "blind" players? playing a LAN-game it was some thing like street fighter but up to date way cool.

these two player were really going at it. think it was Xbox game they was playing.

man they was going at it. yep they were blind as a bat but they can see each other some how in the death match, they did not have to look for each other and when the other player did something the other player known it was coming. wicket

there was a guy (not blind at all) there said he take on the winner if it was ok, Blind Vs the normal guy, but normal guy lasted 5min game over. OMFG blind guy was the winner
__________________
* altnews sources [getmo & others news] not found main FNN: realrawnews.com
*Discord: Unknown77#7121
Playing now days: EA Games> swtor [star wars old republic]

Last edited by Hellfighter; 09-10-2005 at 02:14 PM.
Reply With Quote
  #8  
Old 09-10-2005, 05:45 PM
SilentTrigger is offline SilentTrigger
-1PARA-

Join Date: Sep 2002
Location: Sweden
Posts: 3,972

Quote:
Originally posted by katana*GFR*
I agree with ath also, and i think FF is better then IE, just for the fact flaws and errors in the code are fixed quicker then in IE..
Yeah because everyone in the world is able to change the source code of it, which in it self can pose a problem if it get official attention with a loop hole in it, like this.
__________________
-1PARA-AlexKall

My photography website



Reply With Quote
  #9  
Old 09-10-2005, 06:26 PM
atholon is offline atholon
"ath-hole"

Join Date: Jan 2003
Location: Failville.
Posts: 11,357

Send a message via MSN to atholon
I think the whole point is that it is UPDATED and security threats are taken more seriously by mozilla then by microsoft.
__________________
Reply With Quote
  #10  
Old 09-10-2005, 11:16 PM
Hellfighter is offline Hellfighter
Hellfighter's Avatar
Chief ADFP

Join Date: Jun 2002
Location: San Jose Calif 95111
Posts: 21,143

Send a message via ICQ to Hellfighter
Quote:
The public bug disclosure comes just as Mozilla released the first beta of Firefox 1.5. The final release of the next Firefox update, which includes security enhancements, is due by year's end, according to the Firefox road map.
next year they will fix this not sooner, sad news if there any bug i like it be fix asap not wait next year some jerk may start to look into this now even more.

by the way Microsoft is releasing the new IE7 or IE10 soon. think it is IE7 can't say off hand. Windows Xp family is getting a new "Service pack 3" soon too.
__________________
* altnews sources [getmo & others news] not found main FNN: realrawnews.com
*Discord: Unknown77#7121
Playing now days: EA Games> swtor [star wars old republic]
Reply With Quote
  #11  
Old 09-11-2005, 01:26 AM
Lakie is offline Lakie

Join Date: Mar 2002
Posts: 5,540

a major security advantage that firefox and the like have over IE is that they are used by a vast minority, the lowlifes out there will 99% of the time try to target IE, simply because its used by 98% of people on the net. Ther life would be more hellish if everyone used firefox....

Also, the people that tend to use firefox and other non IE broswers, tend to be the more technologically savvy people and that because of this anything they release wont cause as much of a problem...
Reply With Quote
  #12  
Old 09-11-2005, 03:28 AM
SilentTrigger is offline SilentTrigger
-1PARA-

Join Date: Sep 2002
Location: Sweden
Posts: 3,972

Quote:
Originally posted by atholon
I think the whole point is that it is UPDATED and security threats are taken more seriously by mozilla then by microsoft.
I doubt that its taken more seriously, secondly why not use Mozilla then? Its a hell of a lot better then FireFox

The issue isnt about caring, its about how fast you can work. FireFox is a very small target while IE is a really big target for hackers

Oh mike allready covered that part hehe
__________________
-1PARA-AlexKall

My photography website



Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
FireFox ShArP Tech Support 11 08-30-2008 08:34 AM
FireFox 2.0 Erik Hardware and Software 4 10-24-2006 08:32 PM
FireFox Stephen Web design and Programming 2 10-13-2006 10:39 PM
FireFox 1.5 is out DevilDog#1 Hardware and Software 15 12-19-2005 05:12 PM
Firefox 1.0 Steve Hardware and Software 4 11-12-2004 11:58 AM


All times are GMT -5. The time now is 09:19 PM.




Powered by vBulletin®