On mySimon: Vinturi Essential Wine Aerator
BNET Business Network:
BNET
TechRepublic
ZDNet

By Ingrid Marson
Posted on ZDNet News: Jan 7, 2005 7:06:00 PM

A vulnerability in Firefox could expose users of the open-source browser to the risk of phishing scams, security experts have warned.

The flaw in Mozilla Firefox 1.0, details of which were published by security company Secunia on Tuesday, could allow hackers to spoof the URL in the download dialog box that pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hypponen, director of antivirus research at software maker F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," he said.

To fall victim to such a scam, a Firefox user would have to click on a link in an e-mail that pointed to a spoofed Web site and then download malicious software from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said that phishers aren't likely to take advantage of this flaw in Firefox, because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," Emm said. "After all, Firefox has a much, much smaller install base than IE, and it's likely that hackers will continue to pay more attention to (IE) instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based software, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, but Mozilla developers are expected to fix this bug in an upcoming version of the product.

The Secunia advisory and Mozilla bug report are available online.

Ingrid Marson of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 34 Talkback(s)
Alternate Browsers
Just to clarify, I use Flash Peak Slim Browser as my my main Browser but still use IE upon occasion and also play with Opera. I have a Spyware detector and free alternative virus software that is free... (Read the rest)
Posted by: k9skip@... Posted on: 01/26/05 You are currently: a Guest | | Terms of Use
I'm surprised it took this long for ZDNet to report this  Michael Kelly | 01/07/05
Sounds pretty thin  Roger Ramjet | 01/07/05
Your hypochracy knows no bounds!  ShadeTree | 01/07/05
Your hypochracy knows no bounds!  Squawkbox | 01/07/05
I'm not sure anybody would be faster or slower ...  George Jay | 01/08/05
Ummm SHADETREE did you happen to read this  Squawkbox | 01/07/05
IE's flaw does not excuse Firefox's flaw  Michael Kelly | 01/07/05
I never said that Firefox should be excused.  Squawkbox | 01/07/05
Doesn't matter  Michael Kelly | 01/07/05
Stupid users will be stupid users.  The King's Servant | 01/24/05
Time for a Change!  soulcircus | 01/07/05
Nothings better than Linux  FilledOut | 01/08/05
How about a period every now and then?  ejhonda | 01/10/05
User action required  PA-ITGuy | 01/07/05
User education required  Anti_Zealot | 01/07/05
OK...  PA-ITGuy | 01/07/05
the bug is in the download dialog window  bobjones68@... | 01/08/05
to truncate, or not to truncate...  linuxoverwindows | 01/08/05
In my Firefox version 1.0 I see the site as....  The King's Servant | 01/24/05
giving out your password  linuxoverwindows | 01/08/05
Security?  Rodney Davis | 01/07/05
Slight correction  AmusedAtItAll | 01/07/05
You said:  Rodney Davis | 01/07/05
Rodney Said, Bill Said  BXLE | 01/08/05
Not nearly as easy.  The King's Servant | 01/24/05
Not completely disagreeing but...  IT Scion | 01/08/05
ive seen...  linuxoverwindows | 01/08/05
Not looking back  BXLE | 01/08/05
Top 11 New Firefox Extensions  Squawkbox | 01/09/05
Extensions  SC-man | 01/10/05
MS Apologists? Where are you?  boomslang_z | 01/10/05
They have their hands full  Squawkbox | 01/10/05
Alternate Browsers  k9skip@... | 01/26/05
Alternate browsers  k9skip@... | 01/26/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads