Slashdot Mirror


Hackers claim zero-day flaw in Firefox

An anonymous reader writes "The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon. An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here."

20 of 398 comments (clear)

  1. All security bugs are zero-day by Zeinfeld · · Score: 5, Insightful
    The term zero-day attack has become meaningless. In the days before there were mechanisms in place for rapidly distributing updates the majority of attacks used by hackers were age-old.

    Today the hackers have to work a bit harder so zero-day attacks are no longer rare. The vast majority of attacks are still from hackers who are reverse engineering the patches and distributing attacks before the patches are implemented.

    If someone reports a new attack against open source code it is by definition unknown before it is reported. Therefore all bug reports with security implications are 'zero-day'.

    What the idiots who released this exploit mean by 'zero day' was that they didn't allow time for the problem to be fixed before releasing the exploit.

    --
    Looking for an Information Security student project suggestion?
    Try http://dotcrimeManifesto.com/
  2. Re:Good policies will often save you. by Timesprout · · Score: 3, Insightful

    So we should not use anything that might dent the firefox is perfect myth? Maybe firefox should just fix their javascript implementation just like MS has to when these things arise and the rest of us can get back to enjoying the web.

    --
    Do not try to read the dupe, thats impossible. Instead, only try to realize the truth
    What truth?
    There is no dupe
  3. "For the greater good of the Internet" ??? by CharonX · · Score: 4, Insightful

    From the Article
    The hackers claim they know of about 30 unpatched Firefox flaws. They don't plan to disclose them, instead holding on to the bugs.

    Jesse Ruderman, a Mozilla security staffer, attended the presentation and was called up on the stage with the two hackers. He attempted to persuade the presenters to responsibly disclose flaws via Mozilla's bug bounty program instead of using them for malicious purposes such as creating networks of hijacked PCs, called botnets.

    "I do hope you guys change your minds and decide to report the holes to us and take away $500 per vulnerability instead of using them for botnets," Ruderman said.

    The two hackers laughed off the comment. "It is a double-edged sword, but what we're doing is really for the greater good of the Internet, we're setting up communication networks for black hats," Wbeelsoi said.

    First of all, guys, so you refuse to tell us what the bugs are, so we can't fix them and do this for the "greater good of the internet... setting up communication networks for black hats" WTF? What does having tens of thousands of additional zombie-machines that could DDoS or send SPAM do with the greater good of the internet. I almost hope you try to make money off the bugs (if you even know any more) so you get to know a nice prison cell and "Life without PC"(TM). Honestly, I think those guys are full of it, they probably don't know even one additional vulnerability and just try to show off how "big and powerful" they are.

    --
    +++ MELON MELON MELON +++ Out of Cheese Error +++ redo from start +++
    1. Re:"For the greater good of the Internet" ??? by Ant+P. · · Score: 3, Insightful

      Most black-hats have that scientology mindset. They really do believe their own bullshit, no matter how insane it sounds to real people.

  4. Re:Good policies will often save you. by failure-man · · Score: 3, Insightful

    Mozilla is better at getting problems fixed and sets better policies than Microsoft, but I'm not convinced that it's written much better than IE.

    Web browsers are, by their very nature, huge targets. Their job is to deal with arbitrary data from all over the damn place. The whole thing should probably be sandboxed, but short of that, it shouldn't be running code from random sites.

  5. Re:Proof? by Stephen+Samuel · · Score: 5, Insightful
    Yes they did have a live exploit. The complaint is that they didn't even try to give Mozilla foundation an opportunity to patch the bug before the released it to the black-hats (along with the white hats) at the conference.

    The only difference between a zero-day exploit and a normal exploit is whether the person who finds the exploit allows a fix to be crafted before (s)he releases the bug that allows it.

    The main difference between Open Source groups like Mozilla and Microsoft is that (responsible) open source projects will fix potential security bugs whenever they're informed of them and whether or not there is an exploit available, while Microsoft seems to have a habit of holding off on fixing a bug unless the exploit is blatently obvious and/or there is an proof of concept exploit already in existence (and sometimes even in the wild).

    Given the way that these guys are touting how Firefox is vulnerable because they were able to find a bug that they refused to warn the firefox team about (like that refusal is Firefox's fault) I wouldn't be at all surprised to find that they managed to get some funding (either direct or indirect) from Microsoftl.

    --
    Free Software: Like love, it grows best when given away.
  6. you are deluded by weierstrass · · Score: 4, Insightful

    >I wouldn't be at all surprised to find that they managed to get some funding (either direct or indirect) from Microsoftl[sic].

    complete bullshit and FUD.

    you know nothing about these ppl, they are blackhats, they ruin things for no other reason than to piss ppl off and have a laugh at their expense.

    --
    my password really is 'stinkypants'
    1. Re:you are deluded by causality · · Score: 4, Insightful
      you know nothing about these ppl, they are blackhats, they ruin things for no other reason than to piss ppl off and have a laugh at their expense.

      This is why good security is done in layers. If your sole defense against having your user account, your root account, and possibly even your identity owned by some script kiddie is to depend on the maintainers of $PROGRAM to patch all exploitable flaws in a timely manner, this is what you call putting all of your eggs into one basket. For this, there are things like the Gentoo Hardened Project, which ensure that a mere buffer overflow alone will not grant someone access to your system (of course this is not Gentoo-specific; Gentoo has merely organized such things as PaX and Grsecurity and the toolchain in such a way that it is a relatively simple matter to use the Hardened profile). In my opinion, you're crazy not to take some kind of extra measures like this, if you are going to use a potentially hostile network on a daily basis.

      Ideally, the good people who maintain Firefox can stay on top of the arms race to improve the browser's security as fast as flaws can be found. But the odds are against them -- in order to succeed, they have to find every possible security flaw; the blackhats only need to find the one thing that they missed to have a workable exploit. If you don't like being exploited, then this situation is not good. There is no such thing as absolute security, and no programmer is perfect, but precisely because programmers make mistakes, there are non-executable stacks, random memory addresses, user-space SSP protections, chroot() jail restrictions, and many other measures one can take to ensure that security does not have a single point of failure.
      --
      It is a miracle that curiosity survives formal education. - Einstein
  7. Re:Proof? by LaughingCoder · · Score: 4, Insightful
    Given the way that these guys are touting how Firefox is vulnerable because they were able to find a bug that they refused to warn the firefox team about (like that refusal is Firefox's fault) I wouldn't be at all surprised to find that they managed to get some funding (either direct or indirect) from Microsoftl.
    Or perhaps, being black hat types, they are trying to discredit Firefox because it makes their jobs tougher than IE does. Maybe they want to drive people back to IE.
    --
    The more you regulate a company, the worse its products become.
  8. How Java Script Should Be Handled by TheZorch · · Score: 3, Insightful

    The environment of a browser should be like a virtual machine. The Javascript or JavaApp running in it should be isolated from the rest of the system so that such exploits aren't possible. Mechanisms in the browser could be built in to allow you to still attach files to email in web based email sites whcih use Javascript while maintaining security.

    --
    Michael "TheZorch" Haney
    thezorch@gmail.com
    http://thezorch.googlepages.com/home
  9. Re:Good policies will often save you. by x2A · · Score: 3, Insightful

    "the only real way to fix the javascript implementation is to remove it"

    No... the only real way to fix it is to leave it there, so you can keep finding and fixing the problems. Removing something doesn't fix it... it removes it and all the functionality that it provides.

    Javascript within the browser should be for accessing and manipulating the DOM, and is extremely useful. Whether you are capable of conceiving of uses for it or not says nothing except for the limit of your own imagination.

    Javascript is an interpreted language, there are absolutely no fundamental reasons why security holes in implementations should exist, other than that programmers can make mistakes. How many security flaws have been found in document viewers, compression/encryption libraries etc, where no code in the data is run at all?

    --
    The revolution will not be televised... but it will have a page on Wikipedia
  10. Selling bugs to the highest bidder by louarnkoz · · Score: 4, Insightful
    The two hackers laughed off the comment. "It is a double-edged sword, but what we're doing is really for the greater good of the Internet, we're setting up communication networks for black hats," Wbeelsoi said.

    Yeah, right. What they are really saying is, why give away a bug for $500 when we can sell it for much more on the black market?

    In fact, the public advertisement of a "zero day exploit" makes a lot of sense if you want to establish yourself as a seller of other undisclosed exploits. Publishing the exploit is a gambit. You will loose the exploit as soon as it gets fixed, but you get your name in the trade press, on Slashdot, etc. Doing so, you establish credibility as a merchant of malware. You can set up shop, and advertise 30 other previously undisclosed bugs. Now, the botnet herders, spammers and other DDOS extortionists know were to buy a new exploit if they need one.

  11. Bastards. by Grendel+Drago · · Score: 3, Insightful
    but what we're doing is really for the greater good of the Internet, we're setting up communication networks for black hats,
    What does that even mean? I've read it a dozen times now, and I still can't tell what he's saying.

    The only thing they're doing by holding onto the security bugs is making the internet a more dangerous place. Yes, Firefox should have been written better in the first place. Yes, the security team should have found these already. No, none of that justifies the childish actions they're taking now.

    Or perhaps they're just talking smack, trying to look like big bad grayhats because they found a single flaw. I'd like to think that.
    --
    Laws do not persuade just because they threaten. --Seneca
  12. Re:Slightly offtopic... by failure-man · · Score: 4, Insightful

    I am a Linux user. Yes, a Firefox exploit will not hose my box. It can certainly hose my ~/ however, possibly stealing data in the process.

  13. Re:One of these guys works for SixApart by dorkygeek · · Score: 5, Insightful
    [...] Spiegelmock, who in everyday life works at blog company SixApart.

    This guy is simply a liability for SixApart, and should get fired immediately. Imagine what could happen if he manages to get the exploit code for this or one of the other 30 exploits they claim to have discovered into one of SixApart's blogging tools.

    But what do we know, maybe they have already done so. Judging from their strange "for the greater good" believes, I wouldn't be surprised about it. I sure as hell wont advise anyone to use any of their products until they've reviewed their code to make sure it doesn't sport one of Spiegelmock's toys.

    --
    Windows is like decaf - it tastes like the real thing, but it won't get you through the day.
  14. Re:"Non-disclosure is a heroic endeavor. Be a hero by noamsml · · Score: 3, Insightful
    What an eloquent, well spoken bunch of bullshit.

    Breaking into people's personal computers is every bit as romantic as shooting someone in the face. The fact of the matter is that an arbitrary execution flaw will not be used to free up the flow of information, except for the flow of information about p3n1s p1lls onto every fresh patch of the `net, always provided to us graciously by zombie machines.

    You want to wake up? Here's some up-waking for you: Hacking isn't about allowing "free speech" on the internet (which already exists), it's about getting big money from underground Mafias. These people aren't disclosing the flaws to Mozilla's bug bounty program simply because they think they can make more than $500 via spyware and virii.

  15. "sandbox" is a pathetic rationalization here by Anonymous Coward · · Score: 3, Insightful
    How can we be elitist now? Easy. I run Firefox on Linux. No problem here. Hijack my browser all you want, you're sandboxed. This is still only an issue with Firefox running on Windows. Which again is an issue with the security of Windows.
    Your comment is so wrong on so many levels, it's difficult to know where to start correcting you. Let's start here, though: Do you ever enter secret information like user ids and passwords using your browser? Do you do any banking or investing online? How good does your sandbox sound now? Most people use their browser to do just those sorts of things, relying on no more than passwords for authentication, and the "you're sandboxed" argument is nothing but poorly thought out rationalization when it comes to a comporomized browser, since the browser can now collect those passwords and give them to an attacker. Oh, now I suppose you're going to start rationalizing that it's the fault of websites that only rely on single-factor authentication if their users' accounts are compromised. Instead of trying to pass the buck, why don't you be honest and thoughtful. It's just this sort of half-baked analysis you've done that causes problems when it comes to secuirty.

    It should also be pointed out the Windows can run a browser from a sandbox, too. Just like Linux, privilege escalation exploits aren't uncommon. And just like Linux, a compromised browser is a major problem.
  16. Re:Proof? by jlarocco · · Score: 4, Insightful
    Yes they did have a live exploit. The complaint is that they didn't even try to give Mozilla foundation an opportunity to patch the bug before the released it to the black-hats (along with the white hats) at the conference.

    Welcome to real life. Firefox is getting large enough to be a target. And when a piece of software is a target, people aren't going to just file a bug report when they find an exploitable bug. Look at Windows/IE. Every time you hear about a new exploit on Windows/IE, it's because it's being exploited. It'd be nice if they filed a bug report first, but you definitely can't expect it. They're black hats for a reason, you know.

    Given the way that these guys are touting how Firefox is vulnerable because they were able to find a bug that they refused to warn the firefox team about (like that refusal is Firefox's fault) I wouldn't be at all surprised to find that they managed to get some funding (either direct or indirect) from Microsoftl.

    That is the most ridiculous thing I've heard all week. Black hat hackers release exploits all the time without warning the software's creator. The fact you think Microsoft is involoved says a lot more about you being a Firefox Fanboy than anything else. Get a clue.

  17. So I wrote to SixApart by Anonymous Coward · · Score: 5, Insightful

    Maybe you want to as well? This is absolutely retarded behavior.

    From: [me]
    Subject: Responsible disclosure and wreckless behavior
    Date: 1 October 2006 14.23.23 GMT-04:00
    To: mena@sixapart.com, ben@sixapart.com, brad@danga.com
    Cc: mischa@sixapart.com

    Hello,

    I read this article on ZDNet describing how your employee Mischa Spiegelmock found and revealed a zero-day Firefox flaw:

    http://news.zdnet.com/2100-1009_22-6121608.html

    Mischa and his co-researcher Wbeelsoi refuse to reveal specific details on the flaw--or 30 others they found--to the Mozilla Foundation:

    "The two hackers laughed off the comment. 'It is a double-edged sword, but what we're doing is really for the greater good of the Internet, we're setting up communication networks for black hats, Wbeelsoi said."

    Considering LiveJournal's recent security flaws causing everyone to change their passwords due to browser-based flaws, do you really want someone working for you who makes the problem worse? To be sure, there is merit to the argument that revealing the flaws would allow Mozilla to continue to use a badly buggy implementation; however, there seems to be more to this.

    From FireFox's IRC channel, some dialogue from Jesse Ruderman of the Mozilla foundation, who attended (via Slashdot: http://it.slashdot.org/comments.pl?sid=198519&cid= 16265621 )

    " they claim they can make $10,000 or $20,000 selling a vuln in firefox
      compared to $500 telling us about it
      selling to other blackhats, anonymously, using onion networks, of course"

    Is one of your employees looking to profit of vulnerabilities in Firefox? With the large number of huge enterprises using TypePad and SixApart software, do you really want to risk him embedding JavaScript code to activate this flaw in your products? If he's saving these flaws to profit from them, what's to say he won't look for the bigger payouts of actively punching holes in your products?

    That's unlikely--but more likely is that your customers will hear about this and refuse to do business with you because you have an employee who is actively seeking to make the Internet a more dangerous place.

    If I misunderstood anything in these articles, I apologize completely. However, what was described in the article was so outrageous that I had to write.

    Best regards,
    [me]

  18. Re:IRC by RealGrouchy · · Score: 3, Insightful
    So, if a firefox vulnerability is worth $10k, then an IE vulnerability must be worth $100k considering how many more people use it.


    Ah, but supply and demand are two separate variables. IE vulnerabilities are a dime a dozen, are they not?

    - RG>
    --
    Hey pal, this isn't a pleasantforest, so don't waste my time with pleasantries!