Firefox
Firefox bug could be exploited to create spoofed log-in pages
R E L A T E D   C O N T E N T
ADVERTISEMENT

Forgotten flaw floors Firefox

Seven year-old bug emerges in popular browser

Iain Thomson, vnunet.com 08 Jun 2005
ADVERTISEMENT

A seven year-old flaw has been found in the most recent builds of the Mozilla and Firefox web browsers.

Danish security firm Secunia has issued an advisory rating the flaw as "moderately critical", but no patches are available as yet.

The vulnerability could allow third parties to write information on other people's websites, and could be exploited to create spoofed log-in pages. 

"A seven year-old vulnerability has been reintroduced into Mozilla and Firefox which can be exploited by malicious people to spoof the contents of websites," Secunia warned.

"The vulnerability has been confirmed in Firefox 1.0.4 and Mozilla 1.7.8. Other versions may also be affected."

The flaw makes it technically possible for phishers to harvest details from a banking or e-commerce website, but the user would require both the legitimate and hacked websites open simultaneously for it to work.

Secunia has designed an online test to determine whether a browser is vulnerable to the flaw. 

See also:

Latest browser code offered to developers and testersFoundation releases new browser code for testing  01 Jun 2005
Firefox toolbar provides information on a website's hosting locationSoftware cuts down on scams by spotting fraudulent URLs  26 May 2005
Users urged to upgrade to new versionFoundation responds quickly to security bug  13 May 2005

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
C++ Research Developer Global Pharmaceutical Company London C++ Research Developer Biotechology Global Medical Company London Global Biotechnology Company specialising in the research and development of cutting edge health care products is looking for an innovative, ... more >
| Aston Carter
Your role will be working on direct market access and exchange connectivity part of the application built in C++ on a Unix platform. The team is currently just 9 people including architect and team lead, ... more >
| Aston Carter
This is a fantastic opportunity working for a leading global software house, which is part of a larger multi media company. The role is working in the core development team in central London developing a ... more >
| Aston Carter
C++, Developer, OO, Unix/NT, API, London, City, Graduate A senior core C++/ Unix developer wanting to work in the heart of the city for one of London's most successful companies is required. The successful candidate ... more >
More job opportunities