PDA

View Full Version : IE7 & FF vulnerability disclosed


Anusha
03-01-2007, 07:14 AM
Details of a Javascript "onUnload" event being mishandled by FF and IE7 have been released:
Although Mozilla Corp. patched one more Firefox bug last week than first reported, the researcher whose work has plagued the open-source browser for weeks has released details about another flaw.

Firefox does not properly handle JavaScript "onUnload" events and can be tricked into taking the user to an unintended destination, said security researcher Michal Zalewski. "This flaw allows the attacker to track your footsteps and either redirect you to the URL you wanted to visit, which wouldn't be noticed at all, or to a similarly named phishing Web site when you choose to visit a target of some significance," Zalewski said.

The bug affects the just-released Firefox 2.0.0.2 and 1.5.0.10 updates, as well as Microsoft's Internet Explorer 7. JavaScript can be disabled in the browsers to block such redirects.

"The big difference in the two browsers is that Firefox 2.0.0.2 displays the correct address for the redirected site in the address bar," Symantec Corp. said in a warning today. "IE7, however, continues to display the URL that the user typed into the address bar, leading to a false sense of security."
Full article at ComputerWorld (http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9011939&source=NLT_SEC&nlid=38)

Novindu
03-01-2007, 07:32 AM
hmmmmm 2 bad ha???? cmon man use opera;);)

Anusha
03-01-2007, 07:35 AM
hmmmmm 2 bad ha???? cmon man use opera;);)
No way! Opera sux!

Novindu
03-01-2007, 07:36 AM
No way! Opera sux!
u'll come i kno;);):lol::lol:

shan542
03-01-2007, 07:38 AM
hi,, nice to meet u

Novindu
03-01-2007, 07:43 AM
hi,, nice to meet u
nice ta meet u 2;)

sridanu
03-01-2007, 08:00 AM
hmmm. even with these flaws im sticking to firefox :)

No one Cant be perfect now can u :lol:

prasadana2
03-01-2007, 08:14 AM
i use 3
Firefox 2...
IE 7
Opera

Anusha
03-01-2007, 08:15 AM
u'll come i kno;);):lol::lol:
Wanna bet?

life
03-01-2007, 08:21 AM
hmmm. even with these flaws im sticking to firefox :)

No one Cant be perfect now can u :lol:
Yes! Firefox is the relatively best browser

Anusha
03-01-2007, 08:27 AM
In Opera, AI Roboform doesn't work. This is more than enough for me not to use Opera.