BetaONE will rise again!


Reply
  #1  
Old 10th Feb 08, 12:05 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,216
NewsBot will become famous soon enough
Firefox 2.0.0.12 is still vulnerable to directory traversal
A few hours after the release, a hacker has discovered the flaw, where he recommends using the NoScript plugin. In the mean time you can either use another browser, or install the NoScript plugin to mitigate these issues.

"Don't patch vulnerabilities for fifty percent, take the time and fix the cause. Because directory traversal through plugins is all nice and such, we don't need it. We can trick Firefox itself in traversing directories back. I found another information leak that is very serious because we are able to read out all preferences set in Firefox, or just open or include about every file stored in the Mozilla program files directory, and this without any mandatory settings or plugins.," said Ronald van den Heetkamp to Mozilla.

A proof of concept is available at this web site http://www.0x000000.com

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Firefox 2.0.0.12 NewsBot NeoWin News 0 8th Feb 08 02:10 PM
Firefox Vulnerable to Protocol-Handling Bug Attacks NewsBot NeoWin News 0 5th Sep 07 12:39 PM
Neowin Member Interview: Asa Dotzler - Firefox Developer NewsBot NeoWin News 0 20th Jul 05 09:30 PM
Firefox breaks 25 million downloads in less than 100 days NewsBot NeoWin News 0 18th Feb 05 07:30 AM
Firefox: The Road Ahead NewsBot NeoWin News 0 15th Jan 05 02:00 AM


All times are GMT +1. The time now is 02:29 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.