On The Insider: Sexy Aussie Babes
BNET Business Network:
BNET
TechRepublic
ZDNet

By Ingrid Marson, News.com
Posted on ZDNet News: Jan 7, 2005 7:06:00 PM

A vulnerability in Firefox could expose users of the open-source browser to the risk of phishing scams, security experts have warned.

The flaw in Mozilla Firefox 1.0, details of which were published by security company Secunia on Tuesday, could allow hackers to spoof the URL in the download dialog box that pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hypponen, director of antivirus research at software maker F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," he said.

To fall victim to such a scam, a Firefox user would have to click on a link in an e-mail that pointed to a spoofed Web site and then download malicious software from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said that phishers aren't likely to take advantage of this flaw in Firefox, because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," Emm said. "After all, Firefox has a much, much smaller install base than IE, and it's likely that hackers will continue to pay more attention to (IE) instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based software, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, but Mozilla developers are expected to fix this bug in an upcoming version of the product.

The Secunia advisory and Mozilla bug report are available online.

Ingrid Marson of ZDNet UK reported from London.

  • Talkback
  • Most Recent of 34 Talkback(s)
Alternate Browsers
Just to clarify, I use Flash Peak Slim Browser as my my main Browser but still use IE upon occasion and also play with Opera. I have a Spyware detector and free alternative virus software that is free... (Read the rest)
Posted by: k9skip@... Posted on: 01/26/05 You are currently: Logged In | Log out
I'm surprised it took this long for ZDNet to report this Michael Kelly   | 01/07/05
Sounds pretty thin Roger Ramjet   | 01/07/05
Your hypochracy knows no bounds! ShadeTree   | 01/07/05
Your hypochracy knows no bounds! Squawkbox   | 01/07/05
I'm not sure anybody would be faster or slower ... George Jay   | 01/08/05
Ummm SHADETREE did you happen to read this Squawkbox   | 01/07/05
IE's flaw does not excuse Firefox's flaw Michael Kelly   | 01/07/05
I never said that Firefox should be excused. Squawkbox   | 01/07/05
Doesn't matter Michael Kelly   | 01/07/05
Stupid users will be stupid users. The King's Servant   | 01/24/05
Time for a Change! soulcircus   | 01/07/05
Nothings better than Linux FilledOut   | 01/08/05
How about a period every now and then? EJHonda   | 01/10/05
User action required PA-ITGuy   | 01/07/05
User education required Anti_Zealot   | 01/07/05
OK... PA-ITGuy   | 01/07/05
the bug is in the download dialog window bobjones68@...   | 01/08/05
to truncate, or not to truncate... linuxoverwindows   | 01/08/05
In my Firefox version 1.0 I see the site as.... The King's Servant   | 01/24/05
giving out your password linuxoverwindows   | 01/08/05
Security? Rodney Davis   | 01/07/05
Slight correction AmusedAtItAll   | 01/07/05
You said: Rodney Davis   | 01/07/05
Rodney Said, Bill Said BXLE   | 01/08/05
Not nearly as easy. The King's Servant   | 01/24/05
Not completely disagreeing but... IT Scion   | 01/08/05
ive seen... linuxoverwindows   | 01/08/05
Not looking back BXLE   | 01/08/05
Top 11 New Firefox Extensions Squawkbox   | 01/09/05
Extensions SC-man   | 01/10/05
MS Apologists? Where are you? boomslang_z   | 01/10/05
They have their hands full Squawkbox   | 01/10/05
Alternate Browsers k9skip@...   | 01/26/05
Alternate browsers k9skip@...   | 01/26/05

What do you think?

advertisement
advertisement