On BNET: 3 worst things about the iPhone 3G S
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers
Posted on ZDNet News: Oct 1, 2006 5:57:00 AM

SAN DIEGO--The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon. Hackers' presentation

An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said.

"Internet Explorer, everybody knows, is not very secure. But Firefox is also fairly insecure," said Spiegelmock, who in everyday life works at blog company SixApart. He detailed the flaw, showing a slide that displayed key parts of the attack code needed to exploit it.

Click here to Play

Video: Hackers claim Firefox zero-day flaw
Is the browser more vulnerable than thought?

Click here to Play

Video: Hackers vs. Firefox
Mozilla antsy about expolited Firefox flaws.

The flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the Web. In particular, various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a "complete mess," he said. "It is impossible to patch."

The JavaScript issue appears to be a real vulnerability, Window Snyder, Mozilla's security chief, said after watching a video of the presentation Saturday night. "What they are describing might be a variation on an old attack," she said. "We're going to do some investigating."

Snyder said she isn't happy with the disclosure and release of an apparent exploit during the presentation. "It looks like they had enough information in their slide for an attacker to reproduce it," she said. "I think it is unfortunate because it puts users at risk, but that seems to be their goal."

At the same time, the presentation probably gives Mozilla enough data to fix the apparent flaw, Snyder said. However, because the possible flaw appears to be in the part of the browser that deals with JavaScript, addressing it might be tougher than the average patch, she added. "If it is in the JavaScript Virtual Machine, it is not going to be a quick fix," Snyder said.

The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding onto the bugs.

Jesse Ruderman, a Mozilla security staffer, attended the presentation and was called up on the stage with the two hackers. He attempted to persuade the presenters to responsibly disclose flaws via Mozilla's bug bounty program instead of using them for malicious purposes such as creating networks of hijacked PCs, called botnets.

"I do hope you guys change your minds and decide to report the holes to us and take away $500 per vulnerability instead of using them for botnets," Ruderman said.

The two hackers laughed off the comment. "It is a double-edged sword, but what we're doing is really for the greater good of the Internet. We're setting up communication networks for black hats," Wbeelsoi said.

Since the presentation, Spiegelmock has backpedalled on the zero-day claims. In a note posted to the Mozilla Web site on Monday, he says that he was never able to exploit the supposed vulnerability to hijack computers.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 159 Talkback(s)
Stack-Smashing Protector
If you?re building your own copy of Firefox with GCC (and ProPolice) you can enable stack protection with -fstack-protector or -fstack-protector-all as a short-term soluti... (Read the rest)
Posted by: boshem Posted on: 11/10/06 You are currently: a Guest | | Terms of Use
the best solution...  drew30319 | 10/01/06
Thanks for the info , the extension is very useful .  Intellihence | 10/01/06
knee jerk reaction  nrlz | 10/01/06
no one said it turns off javasccript -  galileon | 10/01/06
So, jerk my knee anytime  flatliner | 10/01/06
Hey! Careful!  GuyAlanDye | 10/02/06
Nobody's throwing out the baby.  CobraA1 | 10/02/06
hey, people still drive ford...  linuxoverwindows | 10/02/06
Yup, and they still ...  Media-Ted@... | 10/02/06
Java + Javascript--do what Drew suggests or forget them altogether!!  Irritated_User | 10/02/06
You do know that NOAA  Media-Ted@... | 10/02/06
No simple solution  zoroaster | 10/02/06
Unfortunately, I've no simple solution except proper vigilance.  Irritated_User | 10/03/06
maintenance nightmare  xuniL_z | 10/03/06
That's why most of the extension stuff should be in the base code.  Irritated_User | 10/03/06
surely you're joking  revnomad | 10/04/06
No, I'm not kidding, FIREFOX REALLY IS A SICK JOKE-Look at the evidence.  Irritated_User | 10/13/06
Funny that you have to download this as ...  ShadeTree | 10/03/06
Ha-Ha!  savatar | 10/01/06
If you read the story properly , you would have noticed  Intellihence | 10/01/06
O'RLY?  Suicida| | 10/01/06
And your point would be?  savatar | 10/01/06
NO-SCRIPT PLUGIN!!!!  galileon | 10/01/06
Hmmm  Qbt | 10/01/06
Time to educate you... again!  Linux User 147560 | 10/01/06
Nice try fan-boy  Harly69 | 10/02/06
One who wishes he owned a harley...  Linux User 147560 | 10/02/06
this just in...  linuxoverwindows | 10/02/06
at least, an EXISTING tool can be used as band-aid!! whereas in windoze/IE  galileon | 10/01/06
Yet...  Qbt | 10/01/06
PETERWETER!! even if you THINK you have no infection,  galileon | 10/02/06
Oh, just face it  Qbt | 10/02/06
in that ase One-care is also band-aid!!!!  galileon | 10/03/06
Galileon's right, and you're wrong, PeterWeter.  Joel R | 10/03/06
Underlying problem  glocks out | 10/02/06
The problem with both FireFox and Explorer  maldain | 10/02/06
Just because they said it...  Greenknight_z | 10/03/06
In fact the whole thing  Hrothgar - PCLinuxOS User | 10/04/06
Microsoft Zealot Alert  voska | 10/03/06
Here here. Someone had to say it.  Irritated_User | 10/03/06
Are you serious?  xuniL_z | 10/03/06
As I've said for ages. ..some bright spark ought to .  Irritated_User | 10/03/06
As a matter of fact...  craptacular@... | 10/03/06
BandAid???  Media-Ted@... | 10/02/06
Why are you saying something as blatant as that?  Irritated_User | 10/03/06
JavaScript is dispensible if you don't do very much  escoles@... | 10/03/06
Such as what?  Irritated_User | 10/03/06
WHY do they have to continually make lies up about Firefox?  John Zern | 10/02/06
How is your reading?  the_seb | 10/02/06
Nonetheless, Firefox barely bobs above the mediocre, even on a good day!  Irritated_User | 10/02/06
It's up to the extension author  Greenknight_z | 10/03/06
No! It's a fundamental design flaw in Firefox!  Irritated_User | 10/03/06
Fundamental design  fshtank | 10/03/06
There's really no other option but to state Firefox's problems as they are.  Irritated_User | 10/03/06
You make some good points.  Joel R | 10/03/06
We obviously think along similar lines.  Irritated_User | 10/03/06
Firefox is the bastard child of intra-organizational politics  escoles@... | 10/03/06
Well said. And more concise than my more general comments.  Irritated_User | 10/03/06
Firefox is not "a decade newer"  critic-at-arms | 10/02/06
If you're going to correct people, get it right  escoles@... | 10/03/06
OK, good point  xuniL_z | 10/03/06
As stated before, the NoScript plug-in  Linux User 147560 | 10/01/06
It is only a band-aid  Qbt | 10/01/06
If the Fox has 30 ...  Henaway | 10/02/06
All we NEED is a Band-Aid  critic-at-arms | 10/02/06
It's not a band aid  jolumoar | 10/02/06
Right On  _dietrich | 10/02/06
NoScript comes pre-installed and configured?  NonZealot | 10/02/06
Again, though  xuniL_z | 10/03/06
Repropbates to the extreme  Steve LeMaster | 10/01/06
"30 vulnerabilities"  ddagolfr | 10/01/06
extortion?  glocks out | 10/02/06
To create communication networks for black hats  schlice | 10/02/06
Yes, and 57 communists in the state department!  ericha8 | 10/02/06
hear, hear! (or - what if it was the lock on your front door, instead?)  jlafitte | 10/03/06
ha, ha, very funny  jlafitte | 10/11/06
No prejudices...  ddagolfr | 10/01/06
Mine are easy  Linux User 147560 | 10/01/06
UraBuS  _dietrich | 10/02/06
Since the Navy only uses nuclear and ...  ShadeTree | 10/03/06
OS Choices  chal | 10/02/06
Dual-boot? Not necessary  _dietrich | 10/02/06
no prejudices - preferences based on personal experience  fencer | 10/02/06
My biases  maldain | 10/02/06
Interesting....  mikeholli | 10/02/06
Buddy, that's it in one.  Irritated_User | 10/03/06
My Bias?  Media-Ted@... | 10/02/06
Amen Brother !  acanez@... | 10/02/06
No real probs using Windows or Linux  Boot_Agnostic | 10/02/06
BA: So incoherent it's almost poetic  A.Typical Zork | 10/02/06
So true  ken@... | 10/02/06
So you tear me apart  Boot_Agnostic | 10/02/06
Not my intent to tear you apart  A.Typical Zork | 10/02/06
Maybe I should not post this  www.cybertopcops.com | 10/03/06
Oh My! Firefox is not Secure?  jpr75_z | 10/02/06
Poor programming...  jasonp@... | 10/02/06
Poor design is worse than poor programming...  Resuna | 10/02/06
Not really a developer are you  TonyMcS | 10/02/06
From somebody who's been in the code mines  draciron@... | 10/03/06
lack of ... accuracy  notstupid6 | 10/03/06
But he's right.  beaner1111@... | 10/03/06
Absolutely. Argue the points  Irritated_User | 10/03/06
William Fencedoors' laceware  geum | 10/03/06
There are plenty of secure closed-source programs...  Resuna | 10/02/06
Why don't they include elementary checks?  geum | 10/03/06
Research  a53bug30 | 10/02/06
It is not propaganda...  beaner1111@... | 10/02/06
beaner1111 says it all  a53bug30 | 10/02/06
Oh My! Firefox Exploit a Hoax!?  UserLand | 10/03/06
It was true  Linux User 1 | 10/03/06
I'll bet you microshills a dollar  zmud | 10/02/06
"greater good"?  CobraA1 | 10/02/06
And to say that openly....  techboy_z | 10/02/06
Fer crissake ...  code_flogger | 10/02/06
Ah, the "Village Idiots" have moved on...  Confused by religion | 10/02/06
Bigger Bounty  zdnet_bozz | 10/02/06
Firefox Javascript vulnerability  bworkman@... | 10/02/06
Upside down Inside out  whoozhe@... | 10/02/06
Just for grins....  Harly69 | 10/02/06
Hmm again  Krazyken39 | 10/02/06
They already tried that one  quantumstate | 10/02/06
maybe some penalty should be levied at them  Castanet | 10/02/06
Motor vehicle?  MacGeek2121 | 10/02/06
Must be a liberal  hoozafrizitz | 10/02/06
It's not the people, Stupid  Irritated_User | 10/03/06
NoScript--essential to Internet security in the 21st century  Jeffhs | 10/02/06
Agree entirely - the number of scripts that want to run  Castanet | 10/02/06
I've been using the Java blocker for a year or two  critic-at-arms | 10/02/06
A rewrite of the JavaScript interpreter is needed  michael_t | 10/02/06
Hmmm, time to bust a myth  maldain | 10/02/06
Three simple points  michael_t | 10/02/06
Restrictions  a53bug30 | 10/02/06
And besides...  a53bug30 | 10/02/06
It is being done in UNIX since early 90s  michael_t | 10/02/06
From what I've been reading here...  Harly69 | 10/02/06
think of that all by yourself??  Monkey_MCSE | 10/02/06
30 Vulnerbilities  truls_rohk | 10/02/06
update- no 30 vulnerabilities?  balaknair | 10/03/06
Why keep hanging flaws against the big clock?  www.cybertopcops.com | 10/02/06
Six Apart employs blackhats  Someguy2 | 10/02/06
Egg their cars, after the weather gets really nasty  Rick S._z | 10/02/06
Missing the Point  SikosisZDNet | 10/02/06
john gabriel's 'greater internet ****wad theory'  nhac | 10/02/06
Well I hope they Tell about them  jackie40d@... | 10/02/06
Just more proof for the marketshare argument  NonZealot | 10/02/06
It is simply not true but humor.  ZaphodBreebleBrox | 10/03/06
Does NOT Take Over the Computer - See Link  BanjoPaterson | 10/03/06
Claim...Not proof!  linux for me | 10/03/06
Exactly - a hoax!  NetArch. | 10/03/06
Who turns the computer on for these hackers?  BALTHOR | 10/03/06
THIS STORY HAS BEEN PROVEN FALSE  beaner1111@... | 10/03/06
devil  Linux User 1 | 10/03/06
ZDNet has now reported that this is FALSE  jjarman | 10/05/06
yup, it's BS... time for an update guys...  doctorSpoc | 10/03/06
Simple Truth as I see it  dracolich_prgrm | 10/04/06
Beware overconfidence  dbrimlow | 10/06/06
I bet you antiMS shills  Boot_Agnostic | 10/04/06
Honk if you love Jesus and Microsoft  Boomslang | 10/08/06
Stack-Smashing Protector  boshem | 11/10/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

advertisement
Click Here