Results 1 to 7 of 7
  1. #1
    Platinum Lounger
    Join Date
    Feb 2001
    Location
    Yilgarn region of Toronto, Ontario
    Posts
    5,453
    Thanks
    0
    Thanked 0 Times in 0 Posts

    browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 and Ca


  2. #2
    Super Moderator jscher2000's Avatar
    Join Date
    Feb 2001
    Location
    Silicon Valley, USA
    Posts
    23,112
    Thanks
    5
    Thanked 93 Times in 89 Posts

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    I think this is likely to be targeted toward "well known" sites, such as big banks, because I believe it requires prior knowledge of the names of the frames in a frameset in order to push a new page into one of them. Attempts to ascertain the names using JavaScript should be blocked by the scripting security model (I know my efforts to poke around in other sites' pages using JavaScript are blocked). So while "obscurity" is never a substitute for true security, hopefully not too many people will be affected by this. <img src=/S/smile.gif border=0 alt=smile width=15 height=15>

  3. #3
    Platinum Lounger
    Join Date
    Jan 2001
    Posts
    3,788
    Thanks
    0
    Thanked 1 Time in 1 Post

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    For a discussion on this on the Mozillazine forums see Firefox security advisory issued by Secunia 06/06/05

  4. #4
    Platinum Lounger
    Join Date
    Feb 2001
    Location
    Yilgarn region of Toronto, Ontario
    Posts
    5,453
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    Thanks Jefferson. I note from Tony's post that the gurus have had some trouble in triggering it. Since tend not to visit secure sites, my risk is reduced.

  5. #5
    Platinum Lounger
    Join Date
    Feb 2001
    Location
    Yilgarn region of Toronto, Ontario
    Posts
    5,453
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    Thanks Tony. Good discussion. I've bookmarked the forums home page as a starting point for browing when I feel like a coffee-and-read break!

  6. #6
    Platinum Lounger
    Join Date
    Jan 2001
    Posts
    3,788
    Thanks
    0
    Thanked 1 Time in 1 Post

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    An update re this flaw. I have not seen any official announcement yet about a security release, but over the last day or so there has been quite a bit of activity on the Firefox aviary branch (the code base that Firefox 1.0.x releases are based on). This includes a few bug fixes and at least one security update. It looks like Firefox 1.0.5 will be released in the near future.

  7. #7
    Platinum Lounger
    Join Date
    Feb 2001
    Location
    Yilgarn region of Toronto, Ontario
    Posts
    5,453
    Thanks
    0
    Thanked 0 Times in 0 Posts

    Re: browser flaw? (Firefox 1.0.4, Mozilla 1.7.8 an

    > It looks like Firefox 1.0.5 will be released in the near future

    Thanks Tony. Me 'n Jupiter are waiting with baited breath, on my part at any rate.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •