Pixalo Photography Community  

Go Back   Pixalo Photography Community > Photography Forums > Computer hardware, software, networking and internet

Computer hardware, software, networking and internet Discuss Internet Explorer 6/7 and Firefox Password Giveaway...From: - Firefox gives passwords away Firefox gives passwords away Bugged By Nick Farrell: Wednesday 22 November 2006, 08:27 THE ...

Welcome to the Pixalo Photography Community. As a Guest you are free to browse the site, but see what extras you get as a Member here.


Expired Thread The thread "Internet Explorer 6/7 and Firefox Password Giveaway" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient.

Reply
 
LinkBack Thread Tools Display Modes
Old 22-11-2006, 11:58   #1 (permalink)
Feet under the table
 
orangepeel's Avatar
 
Join Date: Mar 2006
Location: Edinburgh
Posts: 1,507
orangepeel is a glorious beacon of lightorangepeel is a glorious beacon of light
orangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of lightorangepeel is a glorious beacon of light

Image editing O.K.
User's Gallery
Users Camera Equipment List
Internet Explorer 6/7 and Firefox Password Giveaway

From: - Firefox gives passwords away


Firefox gives passwords away
Bugged
By Nick Farrell: Wednesday 22 November 2006, 08:27

THE MOZZARELLA Foundation has issued a security warning on its Firebadger open sauce browser.

Apparently the browser's secure password manager has a nasty habit of telling other people your user name and password.

The problem comes about because Firebadger supplies the username and password stored on one page on a domain to another page on a domain. For example the Username and password input tags on a Myspace user's site will be shared along with the visitor's Myspace.com credentials.

According to Robert Chapin, of Chapin Information Services, who reports the problem on Bugzilla, the flaw means that passwords can be stolen without punters being aware of it.

In the short term, Mozzarella is suggesting avoiding using Password Manager and the Master Password Timeout Firefox extension.

However, an exploit found in the wild mimicked the login.myspace.com site almost perfectly, causing many users to believe they needed to log in.

More here. µ
__________________
orangepeel is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 22-11-2006, 12:42   #2 (permalink)
Pixalo Crew
 
Steve's Avatar
 
Join Date: Jan 2005
Location: An Englishman living in Germany
Posts: 16,651
Steve is a jewel in the rough
Steve is a jewel in the roughSteve is a jewel in the rough

Image editing O.K.
User's Gallery
Users Camera Equipment List
Re: Internet Explorer 6/7 and Firefox Password Giveaway

Thanks for bringing this up.

After further research on your posted links it appears as though this behaviour is not exclusive to Firefox ... both IE6 & 7 (plus their derivatives) also suffer in exactly the same way (quotes below from the links you posted).

With that in mind I have changed the title of your post to make the IE users aware too

Quote:
------- Comment #3 From Bob Clary 2006-11-12 19:38 PST [reply] -------
Note MSIE6|7 do the same.
Quote:
(Microsoft's response on IE, "We are
aware of the issue you reported," makes me wonder if this attack will remain
viable on IE for some time, even after FireFox is fixed.)
Steve is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Expired Thread The thread "Internet Explorer 6/7 and Firefox Password Giveaway" has not received any replies for 18 months. It has been automatically closed as a result. Please start a new thread on the topic if the information in this thread is not sufficient.


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads
Thread Thread Starter Forum Replies Last Post
Virus disguised as Internet Explorer Steve Computer hardware, software, networking and internet 2 31-03-2007 09:12
Yahoo Messenger update may affect Internet Explorer stability Steve Computer hardware, software, networking and internet 0 16-12-2006 12:17
Internet Explorer 7 spxxxx Computer hardware, software, networking and internet 13 18-11-2006 20:01
Another Critical security Flaw in Internet explorer Steve Computer hardware, software, networking and internet 11 29-09-2006 15:02
Microsoft 'Highly Critical' Internet Explorer VML vulnerability Steve Computer hardware, software, networking and internet 0 22-09-2006 09:53


All times are GMT +1. The time now is 20:15.


vBulletin Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
ReviewPost & PhotoPost vB3 Enhanced, Copyright 2003-2006 All Enthusiast, Inc.
SEO by vBSEO 3.2.0
Copyright © 2006 - 2008 Pixalo.com

Remortgages | Mortgages | Free Advertising | Credit Report | Car Insurance

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98