Critical Firefox Vulnerability | xltronic messageboard
 
You are not logged in!

F.A.Q
Log in

Register
  
 
  
 
(nobody)
...and 601 guests

Last 5 registered
Oplandisks
nothingstar
N_loop
yipe
foxtrotromeo

Browse members...
  
 
Members 8025
Messages 2614128
Today 0
Topics 127542
  
 
Messageboard index
Critical Firefox Vulnerability
 

offline fleetmouse from Horny for Truth on 2005-05-08 09:52 [#01591608]
Points: 18042 Status: Lurker



LAZY_TITLE

* Solution *

- Disable JavaScript, or disable the "Allow web sites to
install software" option [Tools - Options - Web
Features].


I like Javascript (it's necessary for xltronic and some
other sites) so I disabled the install software option.



 

offline r40f from qrters tea party on 2005-05-08 09:55 [#01591611]
Points: 14210 Status: Regular



thanks for the tip, comrade!


 

offline Skink from A cesspool in eden on 2005-05-08 09:58 [#01591612]
Points: 7483 Status: Lurker



: )


 

offline redrum from the allman brothers band (Ireland) on 2005-05-08 09:59 [#01591613]
Points: 12878 Status: Addict



yeah thanks for this - however, firefox pops up a box saying
"This website is trying to install software, click here for
options" when a site does try to do it, so i'm gonna leave
my options the way they are...

i think (correct me if i'm wrong here) that you'd have to
have given the dubious website explicit permission, upon
firefox asking, to let it install software.


 

offline earthleakage from tell the world you're winning on 2005-05-08 10:06 [#01591616]
Points: 27795 Status: Regular



java can go to hell!


 

offline ecnadniarb on 2005-05-08 10:12 [#01591620]
Points: 24805 Status: Lurker | Followup to earthleakage: #01591616 | Show recordbag



Well it's a javascript problem not java.


 

offline earthleakage from tell the world you're winning on 2005-05-08 10:25 [#01591629]
Points: 27795 Status: Regular



i know that! i just wanted to exploit this misdemenour by
trying to trick other people into hating java as much as i
do by slyly linking my own personal hatred of java with that
caused by an input validation error when processing
specially crafted JavaScript code in the "src" parameter of
an "IFRAME" tag or in the "iconURL" parameter of the
"InstallTrigger.install()" function (called when installing
a firefox extension add-on or theme file), which may be
exploited via a malicious web page or email to bypass the
security restrictions and inject arbitrary JavaScript code,
which could lead to a system compromise!


 

offline ecnadniarb on 2005-05-08 10:28 [#01591632]
Points: 24805 Status: Lurker | Followup to earthleakage: #01591629 | Show recordbag



Very cunning.


 

offline Raz0rBlade_uk on 2005-05-08 11:05 [#01591642]
Points: 12540 Status: Addict | Show recordbag



thankyaw


 

offline x0hx from Lysdexia (United States) on 2005-05-08 21:27 [#01592261]
Points: 1318 Status: Regular



Wait'll 1.1 comes out next month...
Faster back n foward browsing
More standards support
Better software update feature
Better page rendering (/. fixed)
Faster retrieval from cache
"Stealth" mode... kinda like a non-caching feature for those
times you need to browse those... naughty sites



 

offline epohs from )C: on 2005-05-12 10:07 [#01596193]
Points: 17620 Status: Lurker



1.0.4 fixes these problems

Of course, current firefox users can upgrade through the
auto updates feature. If you're not seeing the red arrow
icon in the upper right-hand corner of firefox you can force
ff to check:

Tools > Options > Advanced > Software Updates: Check
Now


And, for what it's worth, they're working on improving the
auto update feature soon.

----------------------
In this light, improving the Software Update System has
become a primary objective for Firefox 1.1.
...

I have developed some initial UI mocks which you can find on
the Mozilla Wiki in the Software Update section, along with some growing but
rough design documentation for the client side piece. Darin
has figured out how to get binary patching working, and is
working on a system for incremental background update
download.

----------------------
LAZY_TITLE

... which is really good news imhotep.


 

offline epohs from )C: on 2005-05-12 10:10 [#01596201]
Points: 17620 Status: Lurker | Followup to epohs: #01596193



shit, i linked to the wrong article.

LAZY_TITLE2


 

offline big from lsg on 2005-05-12 10:11 [#01596205]
Points: 23730 Status: Lurker | Show recordbag



i still get spyware in some java jar folder i delete every
day


 

offline epohs from )C: on 2005-05-12 10:17 [#01596223]
Points: 17620 Status: Lurker



i know what you mean big.

i kinda hate java.


 

offline earthleakage from tell the world you're winning on 2005-05-12 10:51 [#01596316]
Points: 27795 Status: Regular | Followup to big: #01596205



java.byte.verify? PORN virus!


 


Messageboard index