Leaky Addons Make for Security Risks for Firefox
Posted: Wed Mar 05, 2008 5:36 am
Leaky Addons Make for Big Security Risks for Firefox Users
by Mark 'Marcus_Soperus' Soper
Hacking Firefox? It's Easy When There's No JAR to Open
ZDnet's Security Blog reports that Firefox extensions that are not stored in JAR archive files (.JAR) leave users vulnerable to a vulnerability called a chrome URL handling directory transversal attack by hostile JavaScript files (Chrome URIs use extensions stored in the user's Chrome folder).
How big a deal is this? According to Gerry Eisenhaur of [url=\"http://www.hiredhacker.com/\"]hiredhacker.com[/url], who discovered [url=\"http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/\"]the vulnerability[/url] earlier this month, merely opening a website that contains JavaScript aimed at this vulnerability could make Firefox display your preferences file (all.js) or find out what you've been doing by displaying the sessionstore.js file, just to name two examples (see his posting for demos).
Who's Vulnerable?
Mozilla is ranking this vulnerability as 'High Severity' because it can be exploited if you have any of over [url=\"https://bugzilla.mozilla.org/attachment.cgi?id=300181\"]600 add-ons[/url] installed, ranging from A (allcookies) to Z (Zipedia).
[i][url=\"http://www.maximumpc.com/article/leaky_addons_make_for_big_security_risks_for_firefox_users\"]Read the Full Article[/url][/i]
by Mark 'Marcus_Soperus' Soper
Hacking Firefox? It's Easy When There's No JAR to Open
ZDnet's Security Blog reports that Firefox extensions that are not stored in JAR archive files (.JAR) leave users vulnerable to a vulnerability called a chrome URL handling directory transversal attack by hostile JavaScript files (Chrome URIs use extensions stored in the user's Chrome folder).
How big a deal is this? According to Gerry Eisenhaur of [url=\"http://www.hiredhacker.com/\"]hiredhacker.com[/url], who discovered [url=\"http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/\"]the vulnerability[/url] earlier this month, merely opening a website that contains JavaScript aimed at this vulnerability could make Firefox display your preferences file (all.js) or find out what you've been doing by displaying the sessionstore.js file, just to name two examples (see his posting for demos).
Who's Vulnerable?
Mozilla is ranking this vulnerability as 'High Severity' because it can be exploited if you have any of over [url=\"https://bugzilla.mozilla.org/attachment.cgi?id=300181\"]600 add-ons[/url] installed, ranging from A (allcookies) to Z (Zipedia).
[i][url=\"http://www.maximumpc.com/article/leaky_addons_make_for_big_security_risks_for_firefox_users\"]Read the Full Article[/url][/i]