On GameFAQs: What is error code 80710092 on the PS3?
BNET Business Network:
BNET
TechRepublic
ZDNet

By Tom Espiner
Posted on ZDNet News: Nov 22, 2006 3:09:00 PM

Mozilla's Firefox 2 and Microsoft's Internet Explorer 7 are vulnerable to a flaw that could allow attackers to steal passwords.

Dubbed a reverse cross-site request, or RCSR, vulnerability by its discoverer, Robert Chapin, the flaw lets hackers compromise users' passwords and usernames by presenting them with a fake login form. Firefox Password Manager will automatically enter any saved passwords and usernames into the form.

The data is then automatically sent to an attacker's computer without the user's knowledge, according to the Chapin Information Services site.

An exploit for this flaw has already been seen on social-networking site MySpace.com, and it could affect anyone using a blog or forum that allows user-generated HTML code to be added, according to Chapin.

"Users of both Firefox and Internet Explorer need to be aware that their information can be stolen in this way when visiting blog and forum Web sites at trusted addresses," Chapin said.

According to security company Netcraft, which discovered the exploit being used on MySpace, a fraudulent login page was hosted on the company's own servers.

As the page did not exhibit any signs of external content, such as cross-site scripting (XSS) or open redirects, it is "convincing, and even security-conscious users are at risk of becoming victims," CIS said.

The attack was launched from a profile page, and it used specially crafted HTML to hide the genuine MySpace content from the page and instead display its own login form.

According to Chapin, an RCSR attack is much more likely to succeed than an XSS attack because neither Internet Explorer nor Firefox is designed to check the destination of form data before the user submits them. The browser doesn't sound an alarm because the exploit is conducted at the trusted Web site.

Two weeks ago, CIS reported to Mozilla that the Firefox Web browser will automatically fill saved usernames and passwords into RCSR forms. Attacks are more likely to succeed in Firefox because Internet Explorer will not automatically fill in saved usernames and passwords, unless the RCSR form appears on the same page as a legitimate login form.

No fix had been issued by Mozilla at the time of writing, though a bug report has been filed. The organization is reportedly working on a fix for Firefox 2, but it's not clear whether earlier versions are also affected. Security company Secunia has advised users to disable the "Remember passwords for sites" option in Firefox preferences.

To take advantage of the flaw, a malicious hacker would have to create a fake login form on a trusted Web site. CIS has recommended that all Webmasters review their server code for the possibility of XSS and RCSR injections, especially operators of encrypted Web sites.

"These attacks could be highly effective against firewalled local network servers and HTTPS addresses that are not otherwise accessible because the attacker does not need direct access," the CIS site said.

Tom Espiner of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 49 Talkback(s)
Here's another $20
Hmm, if you were to listen to the zealots on
ZDNet, you would swear that Windows is the only
OS that ever endangers its users.


Then maybe you shouldn't do that. Unless, of
c... (Read the rest)
Posted by: Still Lynn Posted on: 11/29/06 You are currently: a Guest | | Terms of Use
Oh where art thou FireFox  Linux User 1 | 11/22/06
Well Well Well...  Shelendrea | 11/22/06
Again, hardened computer saves me!  NonZealot | 11/22/06
Curious minds want to know....  thelemite | 11/22/06
I'll answer your question  NonZealot | 11/22/06
good lord  slow_descent | 11/22/06
(nt)What is a "looser"?  toadlife | 11/22/06
I know what a "looser" is!  NonZealot | 11/22/06
And me as well!  999ad@... | 11/22/06
Inaccurate on 2 counts  Havin_it | 11/23/06
Thanks for the reply  NonZealot | 11/23/06
Here's another $20  Still Lynn | 11/29/06
Big Annoyance  Loverock Davidson | 11/22/06
Especially when  Shelendrea | 11/22/06
Easily done  Greenknight_z | 11/28/06
Oops  Greenknight_z | 11/28/06
TalkBack: Reply to message Well Well Well...  Chipper1963 | 11/22/06
Testing line breaks in subject...

End test...
 Grayson Peddie | 11/23/06
Interesting...
I never thought the subject line
 Grayson Peddie | 11/23/06
You do realize that  DarbyOhara | 11/23/06
damn, I am going back to windows  galileon | 11/22/06
Alas, IE7 is affected ...  phburks | 11/22/06
YHBT  galileon | 11/23/06
Ah, . . . progress  Boot_Agnostic | 11/22/06
What's the difference on how  billmichie | 11/22/06
True, true but  999ad@... | 11/22/06
Not easy to identify  Greenknight_z | 11/28/06
below it there's..  brain- | 11/22/06
Much hubbub 'bout nothing new  douglen@... | 11/22/06
What about Safari and Opera? (nt)  markbn | 11/22/06
Ridiculous headline since this is a Firefox bug  georgeou | 11/22/06
Have you checked this?  CobraA1 | 11/22/06
There is a risk with both but much more serious with FF2  georgeou | 11/22/06
I still don't get it  CobraA1 | 11/24/06
From the article  NonZealot | 11/24/06
Firefox isn't doint =that=, George...  John Le'Brecage | 11/22/06
Point is it's much more serious for FF2  georgeou | 11/22/06
Ridiculous assertion since it's ... well, WRONG.  escoles@... | 11/27/06
No, it's not  Greenknight_z | 11/28/06
No matter the computer and browser...  Grayson Peddie | 11/22/06
will firefox win over IE?  humble99 | 11/22/06
The maximum time I took for staying away from IE is 21 seconds.  Grayson Peddie | 11/22/06
22.172 seconds :P  markbn | 11/23/06
Let us keep it simple  kmashraf | 11/22/06
For passwords, me either.  Grayson Peddie | 11/22/06
To Be Not Human...  dustybear1 | 11/24/06
I found a fake page  troubled241 | 11/27/06
Does Roboform get around this?  jsperko | 11/27/06
Most sites not at risk  Greenknight_z | 11/28/06

What do you think?

advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here