Spoofing flaw resurfaces in Mozilla browsers
A 7-year-old flaw that could let an attacker place malicious content on trusted Web sites has resurfaced
Friday, June 10, 2005 by Tarkus | Discussion: WinCustomize News
The flaw, which also affects some other Mozilla Foundation programs, lies in the way the software handles frames, which are a way of showing Web content in separate parts of the browser window. The applications don't check whether the frames displayed in a single window all originate from the same Web site, Secunia said in an advisory on Monday. Firefox 1.x, Mozilla 1.7.x and Camino 0.x versions are vulnerable to the flaw, the security monitoring company said.
Reply #22 Saturday, June 11, 2005 6:22 PM
| Got some news for you Vasgo, Internet Explorer can have tabs now with a toolbar from MSN. Also, you can have mouse gestures for your whole computer with a program called StrokeIt. You can have simple mouse gestures for your computer and can actually control Internet Explorer with it (although not exactly 100%). They may be third-party programs, but they still do the job. |
Yeah im pretty sure that plenty of people out there have third party apps and the like. And im pretty sure IE7 will have some a minimal amount of the features firefox have (and still be called revolutionary and uber).
But security is one of the biggest reasons I switched. And as long as IE has ActiveX, im not touching it.
Reply #23 Saturday, June 11, 2005 6:37 PM
I'm sure if you examined my system you would find very little or nothing at all. I don't rely on all those programs by them themselves. I search my hard drive just as you do. By the way what's so bad about those programs? Nothing. Even the hard core PC gurus here at WC use them.
I have updated my BIOS. SP2 still has problems. To my knowledge I am not using any outdated software on my system. Everything besides SP2 is up to date.
The whole reason I "popped up" about Firefox not being secure is because I'm sick of the Firefox fanboys and zealots saying how secure it is when in fact Firefox has security problems as well.
And YES I assure you I know what computer security is and how to protect myself and keep the system clean.
I guess I should remember a old saying - "Never argue with a idiot. A passing bystander might not know who the idiot is."
Reply #24 Saturday, June 11, 2005 11:25 PM
| I will not install SP2 due to the fact that SP2 has a weird affect on my system. It slows down boot time to 4 minutes. It slows down the whole system to the point that it takes 2 minutes to launch any application. I have an Nvidia Nforce chipset and I have read there is problems between SP2 and Nforce chipsets. |
I have an Nforce chipset and SP2 and no such problems.
Reply #25 Saturday, June 11, 2005 11:34 PM
| The whole reason I "popped up" about Firefox not being secure is because I'm sick of the Firefox fanboys and zealots saying how secure it is when in fact Firefox has security problems as well. |
Do you think its not secure? The zealous say its secure for a reason. In fact, there are many people saying its secure that are not secure. I hope you dont think that the US government are firefox zealots cause they think its more secure.I mean secunia (the company that found both of the recent security flaws) works with mozilla to find these flaws.
And you are greatly exaggerating the security problems in firefox. mozilla in conjunction with secunia have found 2 flaws in their browser, one label as critical and the other label as mildly critical. The critical one was fixed before it was even exploited and right now we are talking about the second one which will most likely be fixed before its exploited.
But to answer your questions. Yeah I used to use adaware. I really did just install the thing today. I dont do an actual manual search through the hard drive...thats way to inefficient. To do my real cleans I use linux. I mount my nfts partition and use a modified version of a program called slocate. Which tallies everything in the system. I applied it to the mounted nfts partition right after. not to go into the logistics of the code. Basically any time a new file is added it is recorded into a list. There are some other fuctions which organize where the files are but i try to limit that. Anytime a new file is added it gets checked though. I purposely keep my nfts partition small (20 gigs out of the 350 gigs i got) so any new media files goes into a seperate fat32 partition (which can be used by both linux and windows). The checks on that partition is minimal. And yeah I did do the modifications myself.
I never said that the programs are bad....Im just saying they do not detect everything...even when u use all of them. There are a lot more xxware on the internet then you think, and that these people can actually register. It isnt necessarily illegal. There are plenty data miners/spyware/adware/malware/ etc. that are not detectable by all the programs put together. The places these things hide is amazing sometime.
I personaly think its foolish to dismiss the fact that firefox prevents bad things from going on your computer. I find 10-15 critical items unnacceptable. I should be getting none.
And you are greatly exaggerating the security problems in firefox. mozilla in conjunction with secunia have found 2 flaws in their browser, one label as critical and the other label as mildly critical. The critical one was fixed before it was even exploited and right now we are talking about the second one which will most likely be fixed before its exploited.
Oh and if your bios is updated then it most likely isnt your nforce chipset. And it really shouldnt be the nforce chipset. Your windows installation/hard drive/ partition may be very unstable. If you have one partition dedicated to windows and thats it. I suggest u back up and wipe it. If that dont work, then a virus may have altered your bios so u may need to take to technician. I have an nforce 2 and it works just fine. And its nice to know windows is a little bit safer.
I guess I should remember a old saying - "Never argue with a idiot. A passing bystander might not know who the idiot is." |
whatever man 
Reply #26 Saturday, June 11, 2005 11:38 PM
| I have an Nforce chipset and SP2 and no such problems. |
I tried googling up on the issue and I cant find anything. Can you tell me where you read that.
Reply #27 Sunday, June 12, 2005 2:11 PM
| Oh and if your bios is updated then it most likely isnt your nforce chipset. And it really shouldnt be the nforce chipset. Your windows installation/hard drive/ partition may be very unstable. If you have one partition dedicated to windows and thats it. I suggest u back up and wipe it. If that dont work, then a virus may have altered your bios so u may need to take to technician. I have an nforce 2 and it works just fine. And its nice to know windows is a little bit safer. |
I doubt my Windows insallation is instable. I just reinstalled XP a few months ago. After installing XP I installed a handful of other programs but thats about all I've done.
I doubt I have a virus in my BIOS file or anywhere else. I have scanned and rescanned my system using AVG, Antivir, Panda, and Trend Micro. I don't see how I could get a virus because I'm so careful online. I only visit about 10 to 20 sites a day - the same 10 - 20 every day. All of these sites are well known to not have viruses or spyware. And YES i don't open emails from anyone containing attachments.
I have XP setup on the main drive and have devoted the entire srive to XP.
Reply #28 Sunday, June 12, 2005 4:54 PM
I know my nforce chipset works perfect with SP2 and yours dont though. So you have a problem and it needs to be fixed.
Mabey using firefox will do it 
Reply #29 Sunday, June 12, 2005 5:12 PM
I'm very careful in my attempt to steer clear of viruses. I'm sure nothing got in there. Recommend me a virus scanner that you trust and I'll perform a scan and post the results just to show you I'm clean.
I downloaded the new BIOS file from the manufactuers website and burned it straight away to disk - rebooted and updated.
I will NOT use Firefox. Why should I use a product that I feel is inferior on my system? Nice try but I prefer IE.
Reply #30 Sunday, June 12, 2005 8:57 PM
| Do you think its not secure? The zealous say its secure for a reason. In fact, there are many people saying its secure that are not secure. I hope you dont think that the US government are firefox zealots cause they think its more secure.I mean secunia (the company that found both of the recent security flaws) works with mozilla to find these flaws. And you are greatly exaggerating the security problems in firefox. mozilla in conjunction with secunia have found 2 flaws in their browser, one label as critical and the other label as mildly critical. The critical one was fixed before it was even exploited and right now we are talking about the second one which will most likely be fixed before its exploited. |
Uh... Citizen Ka806, don't wanna pick and stuff, but the Firefox advisories that come to public attention are just a portion of the vuns that really exist out there. I've known this for some time now. Here's just a few of the more recent probs with FFX:
Exploits:
2005-5-21 - Mozilla Firefox "view-source:" Protocol Cross Domain Scripting Exploit
2005-5-21 - Mozilla Firefox "view-source:javascript" url Code Execution Exploit
2005-5-21 - Mozilla Suite and Firefox Script objects Command Execution Exploit
Advisories:
2005-5-8 - Mozilla Firefox "Extensions" Remote Code Execution Vulnerability
Source: Hackers Center
These are just the more known ones.

Reply #31 Sunday, June 12, 2005 9:56 PM
| I believe Antivir and Trend Micro scan the MBR - it's fine. I never said SP2 dosen't work on my system - it just slows it down. Even if I'm using a new Hard Drive with a fresh install of XP pro +drivers and nothing else installed. And yes I have plenty of memory - 512 - to play with. I'm very careful in my attempt to steer clear of viruses. I'm sure nothing got in there. Recommend me a virus scanner that you trust and I'll perform a scan and post the results just to show you I'm clean. I downloaded the new BIOS file from the manufactuers website and burned it straight away to disk - rebooted and updated. I will NOT use Firefox. Why should I use a product that I feel is inferior on my system? Nice try but I prefer IE. |
If its just a tad slower and thats it then there is nothing wrong with your system. If SP2 has a weird affect your my system and slows down boot time to 4 minutes and slows down the whole system to the point that it takes 2 minutes to launch any application, then something IS wrong with your system. The first step in fixing the problem is admitting it
| Exploits: 2005-5-21 - Mozilla Firefox "view-source:" Protocol Cross Domain Scripting Exploit 2005-5-21 - Mozilla Firefox "view-source:javascript" url Code Execution Exploit 2005-5-21 - Mozilla Suite and Firefox Script objects Command Execution Exploit |
Ummm cyber villian, all of those exploits refer to the one big bug that secunia released to the public and was swiftly fixed with firefox 1.04 before it was even exploited. Why do you think they have the same dates =P. Nice try though. The extension advisory was dealt with in firefox 1.04 also. That advisory deals with the extensions and not the browser itself. None of those problems are in firefox 1.04.
| These are just the more known ones. |
That quote makes no sense to me because firefox is open source, so they dont hide their secrets. What you see is what exsist so far. Granted more will likely surface, but that only because mozilla is researching extensively to find them, but when they find the problems, they tell the public. Open source methodology suggest that your code is not perfect, so you show everybody everything you have, in hopes to make that code perfect.

Reply #32 Sunday, June 12, 2005 10:40 PM
| If its just a tad slower and thats it then there is nothing wrong with your system. If SP2 has a weird affect your my system and slows down boot time to 4 minutes and slows down the whole system to the point that it takes 2 minutes to launch any application, then something IS wrong with your system. The first step in fixing the problem is admitting it |
Let me spell this out to you since you can't buy a clue.
Without SP2 my system boots up in about a minute. With SP2 it boots up in about a minute and a half to 2 minutes.
Without SP2 my application launch as they should - about 20 seconds after I choose them from the start menu - under heavy load on the memory. With SP2 they take about 10 to 15 seconds more.
I exaggerated on my first post about SP2 - so sue me. I know for a fact I ain't got no virus or spyware on here.
Reply #33 Sunday, June 12, 2005 11:25 PM
| Let me spell this out to you since you can't buy a clue. Without SP2 my system boots up in about a minute. With SP2 it boots up in about a minute and a half to 2 minutes. Without SP2 my application launch as they should - about 20 seconds after I choose them from the start menu - under heavy load on the memory. With SP2 they take about 10 to 15 seconds more. I exaggerated on my first post about SP2 - so sue me. I know for a fact I ain't got no virus or spyware on here. |
Wow im sorry. You never mentioned it was an exaggeration. And its not like im snapping at you about it, so there is no reason you should going around saying I cant buy a clue or calling me an idiot. Im sorry but your acting like a real asshole. If you tell me that SP2 does those things then I will tell you that your system is messed up. This is totally unrelated to firefox or anything like that.
damn 20 secs for application launch..whats the specs on your system? Oh unless your exaggerating that also

Reply #34 Sunday, June 12, 2005 11:28 PM
Reply #36 Monday, June 13, 2005 8:15 AM
| note that this very same flaw exists in IE6 with XP SP2 (fully patched). try the secunia test. i don't know why this isn't being reported by everyone who reports that the flaw exists in firefox. |
Cause vulnerabilities is nothing new for Internet Explorer. If they reported this flaw for IE, IT professionals will be like "what else is new". With firefox its pretty big as the open source community want this software to be nothing short of perfect
Reply #37 Monday, June 13, 2005 9:02 AM
| That quote makes no sense to me because firefox is open source, so they dont hide their secrets. What you see is what exsist so far. Granted more will likely surface, but that only because mozilla is researching extensively to find them, but when they find the problems, they tell the public. Open source methodology suggest that your code is not perfect, so you show everybody everything you have, in hopes to make that code perfect. |
What I meant was that there are probly more Firefox vulnerabilities out there that are being exploited, but not reported. The Mozilla guys are pushing too much to try and show that M$ doesn't know what they're doing when it comes to security. That's gonna bite them in the a$$ later on because Microsoft has way more experienced people working for them than Mozilla does. Wait until FF gets more of the IE market share. Then, they're not gonna be able to support as good as they do right now.
The prob is that more people use IE (about 80%) than Firefox (about 8%), so there are more exploits for that reason. But when the use of FF increases, then so will the amount of exploits. Mean, hackers are going to go after the browser that more people use.
Perfect code? Never heard of no perfect code before.

Reply #38 Monday, June 13, 2005 10:30 AM
| Cause vulnerabilities is nothing new for Internet Explorer. If they reported this flaw for IE, IT professionals will be like "what else is new". With firefox its pretty big as the open source community want this software to be nothing short of perfect |
That's one way of looking at it. Another way of looking at it is that Firefox users are so arrogant and anal when it comes to browser security, that people get a kick out of pointing out when they have a problem. The same goes for Linux users.
At least that's a theory I've heard.
Reply #39 Monday, June 13, 2005 11:56 AM
Ka806 - I realize I owe you an apology. Obviously you do know more about this stuff than I do and all I've managed to do with my posts is make myself look like a fool. So I'm sorry.
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!








Reply #21 Saturday, June 11, 2005 6:17 PM
I've been using and fixing PC's for awhile now - years - I'm no noob.
I will not install SP2 due to the fact that SP2 has a weird affect on my system. It slows down boot time to 4 minutes. It slows down the whole system to the point that it takes 2 minutes to launch any application. I have an Nvidia Nforce chipset and I have read there is problems between SP2 and Nforce chipsets.
NO I will not install SP2 any time soon.
Long live IE.
I use nvidia nforce chipset myself and I use SP2 for windows and its perfectly fine. Mabey IE messed it up
So you can go say Long live IE for who knows what reason. But Im done on this issue with you. It be best if you dont go popping off on how firefox is not secure. Cause you are seriously putting your foot in your mouth because you dont even know what computer security is.