|
 |
dimecres, 22 / novembre / 2006 |
|
|
[Via Slashdot] Mozilla ha fet public el bug #360493, Cross-Site Forms + Password Manager = Security Failure on es documenta una vulnerabilitat al Firefox 2.0 que pot ser utilitzada en una web malčvola per obtenir les credencials (usuari i contrasenya) enregistrades al gestor de contrasenyes de Firefox 2.0.
Hi ha disponible una prova de concepte de la vulnerabilitat. Més detalls sobre la vulnerabilitata a CIS Finds Flaws in Firefox v2 Password Manager
Chapin Information Services (CIS) has discovered a new flaw in the Mozilla Firefox web browser that exposes saved passwords to clever attackers.
Given the new nature of this type of attack, CIS has named this a Reverse Cross-Site Request (RCSR) vulnerability.
This flaw could affect anyone visiting a weblog or forum website that allows user-contributed HTML codes to be added.
(...)
The Password Manager component of FireFox can be exploited to send a username and password combination to an attacker's computer without the user's knowledge.
Users of both Firefox and Internet Explorer need to be aware that their information can be stolen in this way when visiting blog and forum websites at trusted addresses.
A recent large-scale attack using RCSR targeted MySpace.com users and was first reported by Netcraft 10/27/2006. That incident involved fake login forms on the MySpace website inviting users to type in their username and password.
|
11:55 (# Enllaç permanent) | Comentaris: | Trackback:
|
|
© Copyright 1996-2006 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicčncia Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.
|
 |
 |
 |
 |
Contingut actualitzat
Categories
Darrers comentaris
Arxiu
Contingut antic
(ja no s'actualitza)
Versions anteriors
d'aquesta pàgina
|
 |
 |
 |
 |
|