BetaONE will rise again!


Reply
  #1  
Old 17th Nov 07, 10:47 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 30,785
NewsBot will become famous soon enough
Firefox Exploit leads to Hack for Google Accounts
Google user accounts are vulnerable to cross-site scripting attacks through a dangerous Firefox exploit, which is still in the wild some 10 days after its discovery. A client or server-side exploit can be inserted into .zip files via open document formats from Microsoft Office 2007 and OpenOffice, and uploaded to a server where the Firefox JAR protocol extracts the compressed data. Affected platforms range from Web mail clients, collaboration and document sharing systems and other Web 2.0 applications from large software vendors. Users can download a NoScript add-on for Firefox to block JavaScript and executable content from untrusted Web sites, and can secure their Google accounts by remaining signed out whenever possible.

The reason Google accounts, including Gmail, can be targeted more easily is because of a 302 redirect error in Google, discovered by bedford.org's Morgan Lowtech, which creates a domain-wide cross-site scripting attack. This allows hackers to gain access and modify Google user accounts including e-mails, contact lists and online presence. While Mozilla has not issued a solution to the problem, application firewalls and proxy servers can be used to block Windows Universal Resource Identifiers (URIs) that contain the JAR protocol, while Web administrators can use a reverse proxy to prevent malicious content from being uploaded.

News source: PC World

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Canada Leads the Way in Firefox Usage NewsBot NeoWin News 0 22nd May 06 05:30 PM
Firefox 1.5 Exploit NewsBot ieXbeta News 0 12th Dec 05 04:00 AM
Neowin Member Interview: Asa Dotzler - Firefox Developer NewsBot NeoWin News 0 20th Jul 05 10:30 PM
Firefox breaks 25 million downloads in less than 100 days NewsBot NeoWin News 0 18th Feb 05 08:30 AM
Firefox: The Road Ahead NewsBot NeoWin News 0 15th Jan 05 03:00 AM


All times are GMT +1. The time now is 12:22 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.