Google Community
Latest Forums Rules Resources
Custom Search

Go Back   Google Community > Webmaster Forums > Web Browsers and Statistics

GoogleCommunity Sponsor
Cirtex Hosting
Use coupon "forum" for 50% Off!

Reply
 
LinkBack Thread Tools Display Modes
Old 10-21-2004, 08:45 AM   #1 (permalink)
Google Guru
 
Join Date: Aug 2004
Location: Toronto, Ontario, Canada.
Posts: 2,395
Thanks: 0
Thanked 0 Times in 0 Posts
Eric
Send a message via ICQ to Eric Send a message via AIM to Eric Send a message via MSN to Eric Send a message via Yahoo to Eric
Firefox 'tabs' exploitation/vulnerability

A research firm know as Secunia Research has discovered two vulnerabilities in Firefox(and many other browsers which have the 'tabbed browsing' feature), which can be exploited by malicious web sites to obtain sensitive information and spoof dialog boxes.

1). Inactive tabs can launch dialog boxes so they appear to be displayed by a web site in another tab. This can be exploited by a malicious web site to show a dialog box, which seems to originate from a trusted web site. Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

Other vulnerable browsers:

* Konqueror
* Opera
* Netscape
* Avant
* MyIE/Maxthon
* Safari

2). Inactive tabs can gain focus from form fields on web sites in another tab. This can potentially be exploited to collect sensitive data entered in form fields on other web sites. Successful exploitation would normally require that a user is tricked into opening a link from a malicious web site to a trusted web site in a new tab.

Other vulnerable browsers:

* Netscape
* Avant Browser
* MyIE/Maxthon

I always knew that an exploit like this would pop up sooner or later :/...I'm not a darn bit surprised...So we can now see that even the best browsers have security issues sadly
Eric is offline   Reply With Quote
 
Sponsored Links
Old 10-21-2004, 10:24 AM   #2 (permalink)
Senior Googler
 
Join Date: Sep 2004
Location: Bosom of Dixie
Posts: 201
Thanks: 0
Thanked 0 Times in 0 Posts
Ashes
Send a message via ICQ to Ashes Send a message via AIM to Ashes Send a message via MSN to Ashes
At least it's a user issue, and not inherent in the browser like the .jpg attacks through IE.
Ashes is offline   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Watchfire Discovers Google Desktop Vulnerability That Hackers ... - Business Wire (press release) News Alerts Google in the News 0 02-21-2007 08:48 AM
Gmail Vulnerability... Captain_Goggles Gmail Forum 0 01-02-2007 10:26 AM
Help Please -- Using G. Toolbar with IE7 Tabs psbecker Other Google Features 3 11-07-2006 06:28 PM
Parent using Google Desktop Search to keep tabs on kids? Anonymous Google Desktop Search Forum 1 05-09-2005 02:14 PM
Help Please -- Using G. Toolbar with IE7 Tabs psbecker GC Announcements 3 01-01-1970 10:21 PM


All times are GMT -8. The time now is 02:31 AM.


Powered by vBulletin®
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.1.0
© 2004–2007 Google Community