On CNET: Best budget PCs under $600
BNET Business Network:
BNET
TechRepublic
ZDNet

By Joris Evers, News.com
Posted on ZDNet News: Oct 1, 2006 5:57:00 AM

SAN DIEGO--The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon. Hackers' presentation

An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said.

"Internet Explorer, everybody knows, is not very secure. But Firefox is also fairly insecure," said Spiegelmock, who in everyday life works at blog company SixApart. He detailed the flaw, showing a slide that displayed key parts of the attack code needed to exploit it.

Click here to Play

Video: Hackers claim Firefox zero-day flaw
Is the browser more vulnerable than thought?

Click here to Play

Video: Hackers vs. Firefox
Mozilla antsy about expolited Firefox flaws.

The flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the Web. In particular, various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a "complete mess," he said. "It is impossible to patch."

The JavaScript issue appears to be a real vulnerability, Window Snyder, Mozilla's security chief, said after watching a video of the presentation Saturday night. "What they are describing might be a variation on an old attack," she said. "We're going to do some investigating."

Snyder said she isn't happy with the disclosure and release of an apparent exploit during the presentation. "It looks like they had enough information in their slide for an attacker to reproduce it," she said. "I think it is unfortunate because it puts users at risk, but that seems to be their goal."

At the same time, the presentation probably gives Mozilla enough data to fix the apparent flaw, Snyder said. However, because the possible flaw appears to be in the part of the browser that deals with JavaScript, addressing it might be tougher than the average patch, she added. "If it is in the JavaScript Virtual Machine, it is not going to be a quick fix," Snyder said.

The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding onto the bugs.

Jesse Ruderman, a Mozilla security staffer, attended the presentation and was called up on the stage with the two hackers. He attempted to persuade the presenters to responsibly disclose flaws via Mozilla's bug bounty program instead of using them for malicious purposes such as creating networks of hijacked PCs, called botnets.

"I do hope you guys change your minds and decide to report the holes to us and take away $500 per vulnerability instead of using them for botnets," Ruderman said.

The two hackers laughed off the comment. "It is a double-edged sword, but what we're doing is really for the greater good of the Internet. We're setting up communication networks for black hats," Wbeelsoi said.

Since the presentation, Spiegelmock has backpedalled on the zero-day claims. In a note posted to the Mozilla Web site on Monday, he says that he was never able to exploit the supposed vulnerability to hijack computers.

  • Talkback
  • Most Recent of 159 Talkback(s)
Stack-Smashing Protector
If you’re building your own copy of Firefox with GCC (and ProPolice) you can enable stack protection with -fstack-protector or -fstack-protector-all as a short-term soluti... (Read the rest)
Posted by: boshem Posted on: 11/10/06 You are currently: Logged In | Log out
the best solution... drew30319   | 10/01/06
Thanks for the info , the extension is very useful . <NT> Beyond the Vista, a Leopard is stalking .   | 10/01/06
knee jerk reaction nrlz   | 10/01/06
no one said it turns off javasccript - galileon   | 10/01/06
So, jerk my knee anytime flatliner   | 10/01/06
Hey! Careful! GuyAlanDye   | 10/02/06
Nobody's throwing out the baby. CobraA1   | 10/02/06
hey, people still drive ford... linuxoverwindows   | 10/02/06
Yup, and they still ... Media-Ted@...   | 10/02/06
Java + Javascript--do what Drew suggests or forget them altogether!! Irritated_User   | 10/02/06
You do know that NOAA Media-Ted@...   | 10/02/06
No simple solution zoroaster   | 10/02/06
Unfortunately, I've no simple solution except proper vigilance. Irritated_User   | 10/03/06
maintenance nightmare xuniL_z   | 10/03/06
That's why most of the extension stuff should be in the base code. Irritated_User   | 10/03/06
surely you're joking revnomad   | 10/04/06
No, I'm not kidding, FIREFOX REALLY IS A SICK JOKE-Look at the evidence. Irritated_User   | 10/13/06
Funny that you have to download this as ... ShadeTree   | 10/03/06
Ha-Ha! savatar   | 10/01/06
If you read the story properly , you would have noticed Beyond the Vista, a Leopard is stalking .   | 10/01/06
O'RLY? Suicida|   | 10/01/06
And your point would be? savatar   | 10/01/06
NO-SCRIPT PLUGIN!!!! galileon   | 10/01/06
Hmmm Qbt   | 10/01/06
Time to educate you... again! Linux User 147560   | 10/01/06
Nice try fan-boy Harly69   | 10/02/06
One who wishes he owned a harley... Linux User 147560   | 10/02/06
this just in... linuxoverwindows   | 10/02/06
at least, an EXISTING tool can be used as band-aid!! whereas in windoze/IE galileon   | 10/01/06
Yet... Qbt   | 10/01/06
PETERWETER!! even if you THINK you have no infection, galileon   | 10/02/06
Oh, just face it Qbt   | 10/02/06
in that ase One-care is also band-aid!!!! galileon   | 10/03/06
Galileon's right, and you're wrong, PeterWeter. Joel R   | 10/03/06
Underlying problem glocks out   | 10/02/06
The problem with both FireFox and Explorer maldain   | 10/02/06
Just because they said it... Greenknight_z   | 10/03/06
In fact the whole thing Hrothgar - PCLinuxOS User   | 10/04/06
Microsoft Zealot Alert voska   | 10/03/06
Here here. Someone had to say it. Irritated_User   | 10/03/06
Are you serious? xuniL_z   | 10/03/06
As I've said for ages. ..some bright spark ought to . Irritated_User   | 10/03/06
As a matter of fact... craptacular@...   | 10/03/06
BandAid??? Media-Ted@...   | 10/02/06
Why are you saying something as blatant as that? Irritated_User   | 10/03/06
JavaScript is dispensible if you don't do very much escoles@...   | 10/03/06
Such as what? Irritated_User   | 10/03/06
WHY do they have to continually make lies up about Firefox? John Zern   | 10/02/06
How is your reading? the_seb   | 10/02/06
Nonetheless, Firefox barely bobs above the mediocre, even on a good day! Irritated_User   | 10/02/06
It's up to the extension author Greenknight_z   | 10/03/06
No! It's a fundamental design flaw in Firefox! Irritated_User   | 10/03/06
Fundamental design fshtank   | 10/03/06
There's really no other option but to state Firefox's problems as they are. Irritated_User   | 10/03/06
You make some good points. Joel R   | 10/03/06
We obviously think along similar lines. Irritated_User   | 10/03/06
Firefox is the bastard child of intra-organizational politics escoles@...   | 10/03/06
Well said. And more concise than my more general comments. Irritated_User   | 10/03/06
Firefox is not "a decade newer" critic-at-arms   | 10/02/06
If you're going to correct people, get it right escoles@...   | 10/03/06
OK, good point xuniL_z   | 10/03/06
As stated before, the NoScript plug-in Linux User 147560   | 10/01/06
It is only a band-aid Qbt   | 10/01/06
If the Fox has 30 ... Henaway   | 10/02/06
All we NEED is a Band-Aid critic-at-arms   | 10/02/06
It's not a band aid jolumoar   | 10/02/06
Right On _dietrich   | 10/02/06
NoScript comes pre-installed and configured? NonZealot   | 10/02/06
Again, though xuniL_z   | 10/03/06
Repropbates to the extreme Steve LeMaster   | 10/01/06
"30 vulnerabilities" ddagolfr   | 10/01/06
extortion? glocks out   | 10/02/06
To create communication networks for black hats schlice   | 10/02/06
Yes, and 57 communists in the state department! ericha8   | 10/02/06
hear, hear! (or - what if it was the lock on your front door, instead?) jlafitte   | 10/03/06
ha, ha, very funny jlafitte   | 10/11/06
No prejudices... ddagolfr   | 10/01/06
Mine are easy Linux User 147560   | 10/01/06
UraBuS _dietrich   | 10/02/06
Since the Navy only uses nuclear and ... ShadeTree   | 10/03/06
OS Choices chal   | 10/02/06
Dual-boot? Not necessary _dietrich   | 10/02/06
no prejudices - preferences based on personal experience fencer   | 10/02/06
My biases maldain   | 10/02/06
Interesting.... mikeholli   | 10/02/06
Buddy, that's it in one. Irritated_User   | 10/03/06
My Bias? Media-Ted@...   | 10/02/06
Amen Brother ! acanez@...   | 10/02/06
No real probs using Windows or Linux Boot_Agnostic   | 10/02/06
BA: So incoherent it's almost poetic A.Typical Zork   | 10/02/06
So true ken@...   | 10/02/06
So you tear me apart Boot_Agnostic   | 10/02/06
Not my intent to tear you apart A.Typical Zork   | 10/02/06
Maybe I should not post this www.cybertopcops.com   | 10/03/06
Oh My! Firefox is not Secure? jpr75_z   | 10/02/06
Poor programming... jasonp@...   | 10/02/06
Poor design is worse than poor programming... Resuna   | 10/02/06
Not really a developer are you TonyMcS   | 10/02/06
From somebody who's been in the code mines draciron@...   | 10/03/06
lack of ... accuracy notstupid6   | 10/03/06
But he's right. beaner1111@...   | 10/03/06
Absolutely. Argue the points Irritated_User   | 10/03/06
William Fencedoors' laceware geum   | 10/03/06
There are plenty of secure closed-source programs... Resuna   | 10/02/06
Why don't they include elementary checks? geum   | 10/03/06
Research a53bug30   | 10/02/06
It is not propaganda... beaner1111@...   | 10/02/06
beaner1111 says it all a53bug30   | 10/02/06
Oh My! Firefox Exploit a Hoax!? UserLand   | 10/03/06
It was true Linux User 1   | 10/03/06
I'll bet you microshills a dollar zmud   | 10/02/06
"greater good"? CobraA1   | 10/02/06
And to say that openly.... techboy_z   | 10/02/06
Fer crissake ... Code_Flogger   | 10/02/06
Ah, the "Village Idiots" have moved on... Confused by religion   | 10/02/06
Bigger Bounty zdnet_bozz   | 10/02/06
Firefox Javascript vulnerability bworkman@...   | 10/02/06
Upside down Inside out whoozhe@...   | 10/02/06
Just for grins.... Harly69   | 10/02/06
Hmm again Krazyken39   | 10/02/06
They already tried that one quantumstate   | 10/02/06
maybe some penalty should be levied at them Castanet   | 10/02/06
Motor vehicle? MacGeek2121   | 10/02/06
Must be a liberal hoozafrizitz   | 10/02/06
It's not the people, Stupid Irritated_User   | 10/03/06
NoScript--essential to Internet security in the 21st century Jeffhs   | 10/02/06
Agree entirely - the number of scripts that want to run Castanet   | 10/02/06
I've been using the Java blocker for a year or two critic-at-arms   | 10/02/06
A rewrite of the JavaScript interpreter is needed michael_t   | 10/02/06
Hmmm, time to bust a myth maldain   | 10/02/06
Three simple points michael_t   | 10/02/06
Restrictions a53bug30   | 10/02/06
And besides... a53bug30   | 10/02/06
It is being done in UNIX since early 90s michael_t   | 10/02/06
From what I've been reading here... Harly69   | 10/02/06
think of that all by yourself?? Monkey_MCSE   | 10/02/06
30 Vulnerbilities truls_rohk   | 10/02/06
update- no 30 vulnerabilities? balaknair   | 10/03/06
Why keep hanging flaws against the big clock? www.cybertopcops.com   | 10/02/06
Six Apart employs blackhats Someguy2   | 10/02/06
Egg their cars, after the weather gets really nasty Rick S._z   | 10/02/06
Missing the Point SikosisZDNet   | 10/02/06
john gabriel's 'greater internet ****wad theory' nhac   | 10/02/06
Well I hope they Tell about them jackie40d@...   | 10/02/06
Just more proof for the marketshare argument NonZealot   | 10/02/06
It is simply not true but humor. ZaphodBreebleBrox   | 10/03/06
Does NOT Take Over the Computer - See Link BanjoPaterson   | 10/03/06
Claim...Not proof! linux for me   | 10/03/06
Exactly - a hoax! NetArch.   | 10/03/06
Who turns the computer on for these hackers? BALTHOR   | 10/03/06
THIS STORY HAS BEEN PROVEN FALSE beaner1111@...   | 10/03/06
]:) Linux User 1   | 10/03/06
ZDNet has now reported that this is FALSE jjarman   | 10/05/06
yup, it's BS... time for an update guys... doctorSpoc   | 10/03/06
Simple Truth as I see it dracolich_prgrm   | 10/04/06
Beware overconfidence dbrimlow   | 10/06/06
I bet you antiMS shills Boot_Agnostic   | 10/04/06
Honk if you love Jesus and Microsoft Boomslang   | 10/08/06
Stack-Smashing Protector boshem   | 11/10/06

What do you think?

advertisement
advertisement

Whitepapers & Webcasts

The Green Enterprise

  • The Green Enterprise
  • A look into the enterprise to explore eco-friendly practices and innovations. In this ZDNet video series learn about what's motivating green tech, and how green technologies are impacting IT. 0:42