Firefox 2.0.0.5 Password Vulnerability

By admin | Jul 23, 2007
If you are new here, you may want to subscribe to our feed.

Just a quick note to make you aware of a serious password vulnerability in Firefox 2.0.0.5. Over the weekend, Secunia, in its Full Disclosure mailing list, announced this vulnerability. The vulnerability revolves around Firefox’s password management feature. Of course, because it is convenient, a lot of people use this. It just allows Firefox to retain usernames and passwords for various websites. Well, it seems that there is a javascript exploit that will allow malicious websites to grab those usernames and passwords.

Heise Security has a working demonstration of the exploit. Go and try it. The easiest way to stop this exploit is to disable javascript from within Firefox. I would recommend that you do so until they come up with a fix for it.



Related Posts:

Frame Injection Vulnerability in Firefox
Secunia has issued an alert for Mozilla and firefox. The vulnerability is actually a re-introduction of a seven year...

Make Firefox Soar
Ok, you cruise the internet a lot. And you like Firefox because, well, a lot of things, one of...

Firefox 3 Alpha 5 Available
The latest and greatest incarnation of the Internet's best browser is available: Firefox 3 Alpha 5. While this update won't...

Nasty Adobe Flash Player Exploit
You need to be aware that a particularly nasty exploit is being actively exploited in the wild.  The actual exploit...

Firefox CPU Usage Issue
Don't get me wrong, I love Firefox....
2 Comments so far
  1. Covarr July 24, 2007 11:47 pm

    An easier and less inconvenient solution would be to simply remember your passwords. It’s not that hard.

  2. Tyler Menezes July 28, 2007 3:01 am

    No, it’s not much of an exploit. Look at the source. Firefox populates the same exact fields IF it’s on the same domain. This “exploit” just allows it to populate those fields (they have the same names, and they’re on the same domain as the ones you submitted earlier), then reads the result. It would work with any browser that has this feature. It’s not an exploit at all. Just a website trying to scare people.

Leave a Comment

If you would like to make a comment, please fill out the form below.

Name (required)

Email (required)

Website

Comments

© 2007 PaulTech Network, - Daily Blog Tips Themes