Leaky Addons Make for Security Risks for Firefox

Moderators: Moderator, Global Moderator

Post Reply
Tami
Administrator
Administrator
Posts: 0
Joined: Sun Apr 25, 2004 1:05 pm

Leaky Addons Make for Security Risks for Firefox

Post by Tami »

Leaky Addons Make for Big Security Risks for Firefox Users

by Mark 'Marcus_Soperus' Soper

Hacking Firefox? It's Easy When There's No JAR to Open

ZDnet's Security Blog reports that Firefox extensions that are not stored in JAR archive files (.JAR) leave users vulnerable to a vulnerability called a chrome URL handling directory transversal attack by hostile JavaScript files (Chrome URIs use extensions stored in the user's Chrome folder).

How big a deal is this? According to Gerry Eisenhaur of hiredhacker.com, who discovered the vulnerability earlier this month, merely opening a website that contains JavaScript aimed at this vulnerability could make Firefox display your preferences file (all.js) or find out what you've been doing by displaying the sessionstore.js file, just to name two examples (see his posting for demos).
Who's Vulnerable?

Mozilla is ranking this vulnerability as 'High Severity' because it can be exploited if you have any of over 600 add-ons installed, ranging from A (allcookies) to Z (Zipedia).

Read the Full Article
Image

[color=\"#41211C\"]It takes years to build up trust and only seconds to destroy it

[/color]
Post Reply

Return to “Security”