Spoofing flaw resurfaces in Mozilla browsers
A 7-year-old flaw that could let an attacker place malicious content on trusted Web sites has resurfaced
Friday, June 10, 2005 by Tarkus | Discussion: WinCustomize News
The flaw, which also affects some other Mozilla Foundation programs, lies in the way the software handles frames, which are a way of showing Web content in separate parts of the browser window. The applications don't check whether the frames displayed in a single window all originate from the same Web site, Secunia said in an advisory on Monday. Firefox 1.x, Mozilla 1.7.x and Camino 0.x versions are vulnerable to the flaw, the security monitoring company said.
Reply #2 Friday, June 10, 2005 5:49 PM
There will always be firefox flaws being reported. Mozilla is by far handling it the best by actively seeking the problem reporting it, and fixing it promptly. Look at how fast 1.4 came after getting their first critical flaw.
Mozilla works very closely with secunia to actively find these flaws. You have noticed how the flaw is actually reported first.....rather than in the IE world where a couple of people have to be hacked.......and then microsoft might issue some warning at the most.
People can dog open source all they want, but if there is one thing where it will reign supreme, its browsers, cause that is what people use the most, and its the hackers gateway to personal information. Having a dedicated community working at it goes much farther then having some large corporation that is worrying about their OS and lawsuits and tons of other applications.
Of course with the firefox adoption, flaws will start to appear, but as you can see with 1.04, the mozilla team is up to the task.
If microsoft disclosed all of the flaws like mozilla is doing people would be like

Reply #3 Friday, June 10, 2005 7:08 PM
| Ummm browse security aint clear cut like that. There will always be firefox flaws being reported. Mozilla is by far handling it the best by actively seeking the problem reporting it, and fixing it promptly. Look at how fast 1.4 came after getting their first critical flaw. Mozilla works very closely with secunia to actively find these flaws. You have noticed how the flaw is actually reported first.....rather than in the IE world where a couple of people have to be hacked.......and then microsoft might issue some warning at the most. |
Good points. I guess it ain't that simple. And Mozilla probly does do a better job at notification. But they (and M$) should do more extensive testing with how browsers handle scripts and code... but of course part of the prob is the way web design keeps changing all time, and just how many things you can actually do with code.
I'm already like
with Microsoft cuz they just got too many bugs with thier OS's. 
Reply #5 Friday, June 10, 2005 8:59 PM
| And there are those that say Firefox is secure... |
It's better than IE. For more detail, read the second comment.
Reply #6 Friday, June 10, 2005 9:38 PM
Reply #7 Saturday, June 11, 2005 12:18 AM

Reply #8 Saturday, June 11, 2005 12:47 AM
I don't remember saying that a browser is good for virus and hacker protection...
Reply #9 Saturday, June 11, 2005 1:45 AM
| Actually it has been proven that IE is faster then Firefox both from a cold start and display times. I had a test a while back that showed you that IE was faster. As far as pop-ups well my google toolbar takes care of that and I think MS included a pop-up blocker in SP2. (I don't use SP2) |
yes firefox doesnt load as fast as IE....cause its not integrated into the OS. Thats the same reason that IT professionals dubbed IE beyond repair. And with display times your just plain wrong, because you can turn on broadband optimizations which make it blaze right by IE.and the google toolbar compares in no way to the ease of use with and functionality of firefox's built in popup blocker. And dont even mention MS pop-upblocker, that is just pathetic.
Browsers arent there for virus and hacker protection. But they are THE first line of defense and IE is like a piece of raggity cloth, while firefox is a diamond sheild. And security IS NOT one of the things that you want to bet on with IE. Browsers need to think with virus and hacker prevention in mind. And just mentioning something like ActiveX goes against that mindset.
Yeah you can stick with IE and all that. Many people do (cause they think it follows website standards more .....which is one of the biggest lies in the IT world). I dont care though Ill just enjoy my tabbed browsing, wealth of plugins, loads of themes, and rock hard security.
Im sorry if the fact that a company working very closely with mozilla to make firefox more secure found a security flaw.....which will probably fixed before its even exploited, like the .jar bug. If that discreadits the fact that firefox is secure then thats unfortunate

Reply #10 Saturday, June 11, 2005 1:46 AM
Reply #11 Saturday, June 11, 2005 1:51 AM
| perhaps it's horses for courses. ofcourse IE doesn't offer multi-tabs which would be nice. or a function that enables mouse gestures. or the ability to remove frames and annoying ads. or a scrapbook facility for saving pages without having to invest in third party software. or an online community of developers that don't wish to charge at every turn. but then that's the way open source operates, non? |
Ill tell my boss not to test the software we produce. Cause we might find bugs in and it will be less secure. Ill get a raise for sure

Reply #12 Saturday, June 11, 2005 3:56 AM
I'll stick to IE and will be even happier when IE7 comes out in a few months.
Reply #13 Saturday, June 11, 2005 4:58 AM
| Ka806 - Explain to me why I have never gotten a virus using IE (while employing a virus scanner) and why I don't get more than 10 to 15 spyware entries in ad-aware or the fact that I have never been hacked. I'll stick to IE and will be even happier when IE7 comes out in a few months |
I mean to put you on ice. I never got one, one piece of ad-aware entry since i have use mozilla. Not even mentioning viruses. And I use plenty of spyware/adware checkers including adaware professional.....
And I think you grossly misunderstand the idea of security. Just because you havent gotten hacked/gotten a virus/gotten loads of spyware, that doesnt mean your safe. Chances are you probably do have a ENORMOUS amount of data mining software that is undetectable by adaware. But moving aside from that you cant just sit there and ignore things like:
http://www.nytimes.com/2004/08/12/technology/circuits/12brow.html?ex=1250049600&en=2e6b25eafd7f2db7&ei=5090&partner=rssuserland
http://www.usatoday.com/tech/news/2004-07-01-cyber-threat_x.htm
http://www.theinquirer.net/?article=16922
http://www.eweek.com/article2/0,1759,1637596,00.asp
http://slate.msn.com/id/2103152/
http://channels.lockergnome.com/news/archives/20050325_internet_explorer_unsafe_98_percent_of_the_time.phtml
http://www.dnzone.com/ShowDetail.asp?NewsId=1258
http://wired-vig.wired.com/news/infostructure/0,1377,64065,00.html
Things like IE unsafe 98% !!! of the time. The government even explicitly warns the public against it.
You can say junk like what you said. But look at where your at. Your walking blind in the middle of highway thinking your invincible because you didnt get hit. LOTS of harddrives have been reformated thanks to internet explorer
oh and if your gonna think that adaware spots everything... your really wrong. If I could Id bet 20$ I could use my linux drive to do a slocate on your nfts part and find so many discrepencies between a clean system and your system. In other words its most likely messed up. Security = prevention, not sitting there being happy that nothing happen to you, especially when things are happeing to everyone around you.
I mean fine you can stick to your IE and get things you most likely dont know about (oh and ms doesnt report their flaws!!!). But there is not one advantage I can think of. After Broadband optimizations firefox indeed displays info much faster than IE and if you even mention the startup time then the resource consumption of running multiple IE versions compared to 1 tabbed firefox version easily puts firefox ahead. I mean I dont even want to mention ActiveX
oh did I mention I have not gotten 1 piece of adware on my nfts after using firefox. And thats with doing a manual slocate check on my nfts. lol when was the last time I ran adaware. I think ill run it now cause the application gets no love
It might offend yout but this point in the game, I can honestly honestly say that If you like IE better than............u know forget firefox, to say IE is better than any gecko based brower (safari, ephiphany, mozilla) is just pure blindness and an insult to the people that developed those applications. Its just my opinion dont take it to heart. (Alot of people I know would just straight up yell at and post some 100 links as to why IE is unsafe, then hack you through ActiveX, and run some sort of hash script to show you all the "presents" IE left you =P.
But hey open source is about choice... so you can choose IE. Moderate use shouldn't put you in any real danger. Just some processes to take up a little bit of resources.
Well finally adaware is finished and still nothing
. Screw that Im uninstalling it

Reply #14 Saturday, June 11, 2005 5:06 AM
{
Oh and saying this might also offend you but its just my opinion so dont take it to heart.
But I think this does in fact show the damaging effects of microsoft's monopoly in the IT industry. People dont even know what security means, and they are content with not knowing what their computer is doing.
I almost find it disgusting
}

Reply #15 Saturday, June 11, 2005 5:10 AM
Reply #16 Saturday, June 11, 2005 7:03 AM
| Oh and one more thing. I would HIGHLY HIGHLY HIGHLY HIGHLY suggest you get SP2 on your machine if its running XP. |
That's a good idea cuz way too many people don't want to get SP2. It's more secure than SP1 is for sure. I got it. BUT, I have been able to get past SP2 Heap protection and bypass DEP... but with a lot more work than it would have taken to break SP1 though.

Reply #17 Saturday, June 11, 2005 1:13 PM
I've been using and fixing PC's for awhile now - years - I'm no noob.
I will not install SP2 due to the fact that SP2 has a weird affect on my system. It slows down boot time to 4 minutes. It slows down the whole system to the point that it takes 2 minutes to launch any application. I have an Nvidia Nforce chipset and I have read there is problems between SP2 and Nforce chipsets.
NO I will not install SP2 any time soon.
Long live IE.

Reply #18 Saturday, June 11, 2005 1:46 PM
Nevermind.

Reply #19 Saturday, June 11, 2005 3:39 PM
Reply #20 Saturday, June 11, 2005 4:33 PM
perhaps the real question here is not whether firefox has a security flaw or not but whether it is addressing that flaw. afterall cannot the same not be said of IE as well?:
Link
Please login to comment and/or vote for this skin.
Welcome Guest! Please take the time to register with us.
There are many great features available to you once you register, including:
- Richer content, access to many features that are disabled for guests like commenting on the forums and downloading skins.
- Access to a great community, with a massive database of many, many areas of interest.
- Access to contests & subscription offers like exclusive emails.
- It's simple, and FREE!







Reply #1 Friday, June 10, 2005 5:12 PM