|
| HOMEPAGE | INDICE FORUM | REGOLAMENTO | ::. | NEI PREFERITI | .:: | RSS Forum | RSS News | NEWS web | NEWS software | |
| PUBBLICITA' | | | ARTICOLI | WIN XP | VISTA | WIN 7 | REGISTRI | SOFTWARE | MANUALI | RECENSIONI | LINUX | HUMOR | HARDWARE | DOWNLOAD | | | CERCA nel FORUM » | |
30-07-2004, 16.45.02 | #1 |
Gold Member
Top Poster
Registrato: 26-08-2000
Loc.: tokyo city
Messaggi: 8.374
|
Mozilla / Mozilla Firefox User Interface Spoofing Vulnerability
The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees. The Mozilla user interface is built using XUL files. A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website. This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected. NOTE: This issue appears to be the same as Mozilla Bug 244965... Leggi: http://secunia.com/advisories/12188/ |
Utenti attualmente attivi che stanno leggendo questa discussione: 1 (0 utenti e 1 ospiti) | |
Strumenti discussione | |
|
|
Discussioni simili | ||||
Discussione | Autore discussione | Forum | Risposte | Ultimo messaggio |
Mozilla Firefox Frame Injection Vulnerability | Giorgius | Sicurezza&Privacy | 5 | 09-06-2005 20.08.02 |
"Speciale Firefox 1.0" | Gigi75 | Segnalazioni Web | 8 | 10-11-2004 13.36.17 |
Mozilla Firefox 1.0 RC1 | Gervy | Archivio News Software | 10 | 28-10-2004 20.02.04 |
Mozilla Firefox 1.0RC PR | Gervy | Archivio News Software | 19 | 20-09-2004 15.10.26 |
Mozilla / Mozilla Firefox "onunload" SSL Certificate Spoofing | Giorgius | Sicurezza&Privacy | 1 | 28-07-2004 12.03.57 |