Topic: Password vulnerability in Firefox 2.0.0.5  (Read 1080 times)

0 Members and 1 Guest are viewing this topic.

Offline Nemesis

  • Captain Kayn
  • Global Moderator
  • Commodore
  • *
  • Posts: 13067
Password vulnerability in Firefox 2.0.0.5
« on: July 24, 2007, 09:56:06 pm »
Link to full article

Quote
According to a message posted over the weekend on the Full-Disclosure mailing list, the latest version of Firefox, 2.0.0.5, contains a password management vulnerability that can allow malicious Web sites to steal user passwords. If you have JavaScript enabled and allow Firefox to remember your passwords, you are at risk from this flaw.


Apparently the password can only be stolen for the site that the javascript is on.  It can't steal all passwords.
Do unto others as Frey has done unto you.
Seti Team    Free Software
I believe truth and principle do matter. If you have to sacrifice them to get the results you want, then the results aren't worth it.
 FoaS_XC : "Take great pains to distinguish a criticism vs. an attack. A person reading a post should never be able to confuse the two."

Offline Just plain old Punisher

  • Vice Admiral
  • *
  • Posts: 36927
  • Gender: Male
  • I'm not facist, I just like wearing jackboots
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #1 on: July 25, 2007, 03:47:14 pm »
So the site can steal the password only for people who sign up for that site -- which begs the question, shouldn't they already have the username and password?

"Sex is a lot like pizza.  If you're not careful you can blister your tongue". -Dracho

Offline Javora

  • America for Americans first.
  • Commander
  • *
  • Posts: 3002
  • Gender: Male
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #2 on: July 25, 2007, 05:31:39 pm »
So the site can steal the password only for people who sign up for that site -- which begs the question, shouldn't they already have the username and password?

No, not if they are spoofing another site, like a bank or some other place that deals with other peoples money.  Granted, it's a remote chance that something like that could happen but...  *shrugs*

Offline jualdeaux

  • The Quiet One
  • Global Moderator
  • Commander
  • *
  • Posts: 2758
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #3 on: July 25, 2007, 05:56:51 pm »
Ah, they'll get a fix out fairly quickly.
Only in America .....do we use the word 'politics' to describe the process so well: 'Poli' in Latin meaning 'many' and 'tics' meaning 'bloodsucking creatures'.

Offline Nemesis

  • Captain Kayn
  • Global Moderator
  • Commodore
  • *
  • Posts: 13067
Re: Password vulnerability in Firefox 2.0.0.5
« Reply #4 on: July 25, 2007, 07:30:50 pm »
So the site can steal the password only for people who sign up for that site -- which begs the question, shouldn't they already have the username and password?

Some sites also apparently allow members to add javascript to their own pages.  Those pages could grab the site password.
Do unto others as Frey has done unto you.
Seti Team    Free Software
I believe truth and principle do matter. If you have to sacrifice them to get the results you want, then the results aren't worth it.
 FoaS_XC : "Take great pains to distinguish a criticism vs. an attack. A person reading a post should never be able to confuse the two."