Page 1 of 2 12 LastLast
Results 1 to 10 of 13

Thread: Mozilla Downplays Firefox 1.5 Exploit

  1. #1
    Join Date
    Apr 2003
    Posts
    13,270
    Rep Power
    35

    Default Mozilla Downplays Firefox 1.5 Exploit

    A private security outfit has released a proof-of-concept exploit for a security flaw in Firefox 1.5, warning that the code can be modified to launch code execution attacks.

    However, officials at the Mozilla Foundation are downplaying the threat, insisting the bug is more of an "annoyance" than a serious security vulnerability.
    Read more: http://www.eweek.com/article2/0,1895,1898253,00.asp
    Link to Proof of Concept code found here: http://isc.sans.org/diary.php?storyid=920
    "The best software is the one that fits your needs." - A_A

    Virus free since: date unknown
    Anti-virus free since: August 2008

  2. #2
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Well its good that firefox seems to be getting constant attention where security is concerned. This will just help to get rid of these bugs faster.

  3. #3
    Join Date
    Apr 2003
    Posts
    13,270
    Rep Power
    35

    Default Long-title temporary startup unresponsiveness

    Quote Originally Posted by Mozilla.org
    Web pages with extremely long titles (the posted proof of concept used 2.5 million characters) can cause Mozilla Firefox and the Mozilla Suite to appear to "hang" on startup when reading the browsing history data. The browser will eventually continue normally although this can take up to several minutes on a slower computer. The unresponsive starts will continue until the item with the long title is removed from the history file or eventually expires.

    We have investigated this issue and can find no basis for claims that variants of this denial-of-service attack can cause an exploitable crash, and no evidence for this claim has been offered. There does not appear to be any risk to users or their computers beyond the temporary unresponsiveness at startup.

    Should the user encounter this problem the slow starts can be fixed by deleting the item from history.
    Taken from: http://www.mozilla.org/security/history-title.html
    "The best software is the one that fits your needs." - A_A

    Virus free since: date unknown
    Anti-virus free since: August 2008

  4. #4
    Join Date
    Jun 2004
    Posts
    3,547
    Rep Power
    0

    Default

    Quote Originally Posted by mitchie
    Which firefox user gonna test this Proof of concept? Arch??
    lol, i'll pass on that one.

  5. #5
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    I'll try it and let you guys know.

  6. #6
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Well the proof worked.

    Before:



    Firefox trying to start after visiting url:



    I didnt wait until it started to find out how long it would take, Waiting a minute is long enough.
    Last edited by leoandru; Dec 12, 2005 at 10:42 AM.

  7. #7
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    I didnt delete the entire history.dat file is you open it in notepad u'll see the extremly long url. Just delete it using the combination keys to highlight it else lots of scrolling. here is how it looked:


  8. #8
    Join Date
    Apr 2005
    Posts
    1,333
    Rep Power
    0

    Default

    Hah! It doesn't affect Opera.
    The fox was probably right - they could have been sour grapes.

  9. #9
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Where did all of Mitchie's post disappeared to?

  10. #10
    Join Date
    Jan 2003
    Posts
    1,137
    Rep Power
    0

    Default

    Quote Originally Posted by leoandru
    Where did all of Mitchie's post disappeared to?
    Wondering the same thing...
    Vision without Mission is Daydreaming!

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •