Windows Secrets

Subscribers: Sign in

Enter your e-mail address to get a free subscription.
We guarantee your privacy
Skip to content
  • Home
  • Newsletter Archives
    • Current
    • LangaList Plus
    • Patch Watch
    • Wacky Web Week
    • Security Baseline
  • E-Books
  • Lounge
  • About us
    • Refunds
    • Privacy Policy
    • Advertise
  • Contact
  • Your Account
    • Upgrade
    • Preferences
    • Bonus Download
    • Unsubscribe
Home>Windows Secrets>IE 7 allows Firefox exploit to work

IE 7 allows Firefox exploit to work

Tweet

Chris mosby By Chris Mosby

In my July 12 column, I discussed a flaw in IE that was exposed by installing Firefox.

Now the tables have turned and the opposite is true with the latest releases of Firefox and IE 7.


URI flaw has new exploit method

I discussed on July 12 a problem with the way that Firefox registers certain URI handlers with the operating system. If exploited, these handlers could call IE to launch Firefox, using JavaScript-based attacks that can compromise a user’s system.

This flaw was fixed in a new version of Firefox known as 2.0.0.5. The exploit, however, is reportedly still possible with other browsers, such as Safari for Windows, according to security researcher Thor Larholm.

Since then, the Web has seen a constant flow of arguments over who was at fault for this flaw. “Mozilla,” says former Microsoft security strategist Jesper Johansson, “Microsoft,” says Mozilla developer Window Snyder.

The most recent new flaw is very similar to the previous one — except this time, the presence of IE 7 on a system that also has the latest version of Firefox allows Firefox to be exploited. Also, instead of an infected URL being passed from IE to Firefox, this exploit works entirely within Firefox itself.

A Windows flaw makes Firefox vulnerable

The new flaw is caused by an input validation error that’s introduced by the installation of IE 7. It involves the browser’s handling of URI handlers such as "mailto," "news," "nntp,", etc.

This article is part of our paid content. Subscribe.

Already a paid subscriber? Click here to login.

Related posts:

  1. New flaw in Mozilla and Firefox fixed
  2. Firefox v1.5.0.1 released
  3. Critical Firefox vulnerability patched
  4. Firefox updated to v2.0.0.3
  5. Another Firefox security release
= Paid content

All Windows Secrets articles posted on 2007-08-02:

  • Introduction Make sure you get the e-mails you want
  • Top Story How to simulate User Account Control in XP
  • Known Issues Drive encryption not just for hard disks
  • Wacky Web Week Apple takes on iRack
  • PC Tune-Up Does the future of Windows include adware?
  • Windows Secrets IE 7 allows Firefox exploit to work
  • Patch Watch How to clean up after MS’s .NET patches
  •  Show all articles on a single page
E-books

We’ve pored through years of back issues, picking the best tips, to create these ebooks:

E-book series
  • PC Maintenance Guide
  • PC Security Guide
  • Windows 7 Guide Vol 1
  • Windows 7 Guide Vol 2
  • Win XP Survival Guide
See the e-book series
Top-scoring articles in the past 12 months
  • Leaving long cookie trails throughout the Web 5.00
  • Windows-like security for Android devices 5.00
  • Win7′s no-reformat, nondestructive reinstall 4.53
  • The sorry tale of the (un)Secure Sockets Layer 4.42
  • RPV: Win7′s least-known data-protection system 4.33
  • Recovery: the last step in total data security 4.30
  • Time for a .NET update we can’t ignore 4.30
  • Getting the most from Windows Search — Part 1 4.25
  • Revising printing habits saves money and trees 4.25
  • Upgrades end in erratic, partial hangs 4.25
  • Pros and cons of a ‘keyfile’ password 4.21
  • Beating back Duku and a plethora of other threats 4.20
  • Office 2007 gets its final service pack 4.19
  • Putting Registry-/system-cleanup apps to the test 4.19
  • One year and 99 security bulletins later 4.18
  • 1.8TB external drive goes down hard 4.17
  • Don’t pay for software you don’t need — Part 3 4.16
  • Internet Explorer gets another round of patches 4.15
  • Is your free AV tool a ‘resource pig?’ 4.15
  • Vacation’s over; it’s a big round of patches 4.15
  • Remote access leads to remote attacks 4.15
  • Keeping you up to date: say no to .NET — again 4.14
  • Take control of Google’s privacy policy settings 4.14
  • Office File Validation patch leads to problems 4.14
  • The advanced system-recover toolkit 4.13
  • New “419″ scam involves PayPal and Western Union 4.12
  • Readers’ best personal-privacy tips 4.11
  • Getting the most from Windows Search — Part 2 4.11
  • Re-examining Dropbox and its alternatives 4.10
  • Easily edit Windows’ right-click context menus 4.09
Connect with us Follow us on Twitter Connect with us on Facebook View our RSS Feeds
  • Home|
  • Newsletter|
  • About Windows Secrets|
  • Advertise with us|
  • Unsubscribe|
  • Sitemap|
  • Affiliates|
Trademarks: Microsoft and Windows are registered trademarks of Microsoft Corporation. The Windows Secrets series of books is published by Wiley Publishing Inc. The Windows Secrets Newsletter, WindowsSecrets.com, WinFind, Windows Gizmos, Security Baseline, Patch Watch, Perimeter Scan, Wacky Web Week, the Logo Design (W, S or road, and Star), and the slogan Everything Microsoft Forgot to Mention all are trademarks and service marks of iNET Interactive. All other marks are the trademarks or service marks of their respective owners.
iNET Interactive Copyright © 2011 iNET Interactive.
All rights reserved.
Terms of Use  |  Privacy Policy
Internet Services
  • Web Hosting Talk
  • HostingCon
  • Hosting Catalog
  • Host Voice
Web Development
  • Hot Scripts
  • DB Forums
Digital Marketing
  • ABestWeb
  • Search Marketing Standard
  • PayPerClickUniverse
  • SEMCompare
Consumer Tech
  • Windows Secrets
  • Overclockers
  • Mac Forums

Learn more about
advertising opportunities across the iNET Interactive Network.

LiquidWeb