Millions at risk from browser flaw
Millions at risk from browser flaw
R E L A T E D   C O N T E N T
ADVERTISEMENT

Phishers catch out Firefox

Browser open to URL spoofing

Robert Jaques, vnunet.com 07 Jan 2005
ADVERTISEMENT

A security flaw in the increasingly popular Firefox browser is exposing millions of users to phishing scams, security experts have warned.

Jakob Balle, security specialist at Secunia Research, said that the vulnerability in Firefox and Mozilla allows malicious hackers to execute phishing scams by spoofing the source URL displayed in the browser's Download Dialog box.

"The problem is that long sub-domains and paths are not displayed correctly, which can be exploited to obfuscate what is being displayed in the source field of the Download Dialog box," he said.

A Secunia Research advisory stated that the "less critical" vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. It added that "other versions may also be affected".

"Currently, no solution is available. However, the vendor reports that this vulnerability will be fixed in upcoming versions of the affected products," Secunia stated.

Balle urged users not to follow download links from untrusted sources.

See also:

Firefox users urged to download security updateSecurity update fixes spoofing and arbitrary code execution, says Mozilla  25 Feb 2005
25 million downloads since NovemberOpen source browser making its way into the mainstream  22 Feb 2005
Browser flaw puts users at risk of phishing scamsSecurity firm warns of phishing risk with Firefox, Opera and others  09 Feb 2005
Revised schedule for version 1.1Developer denies delay linked to move to Google  31 Jan 2005
Ben Goodger defects to GoogleMove fuels speculation about search giant developing its own browser  25 Jan 2005
Increase of 10 per cent during DecemberAnti-Phishing Working Group warns of 'relentless increase'  24 Jan 2005
Hackers using rogue access points to fool hotspot usersWireless phishing attacks threaten corporate data  21 Jan 2005
Firefox 1.0 web browserWorldwide launch of open source browser takes aim at Explorer  09 Nov 2004

All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities