Vulnerability In Firefox Popup Blocker
cj writes in with news of a vulnerability in Firefox's stock popup blocker discovered by Michal Zalewski. The vulnerability can allow a malicious user to read files from an affected system. The attacker would "need to plant a predictably named file with exploit code on the target system. This sounds hard, but isn't," according to the article.
It takes a man to suffer ignorance and smile
Be yourself no matter what they say
This only affects the 1.5.x branch, not the current 2.x stuff...
That was quite possibly the most ignorant statement I have read on slashdot recently. I'm not particularly partial to either Firefox or IE, but exploit for exploit, your statement has no merit. What will be the deciding factor will be how fast it is patched.
From the fine article:
"When the user chooses to manually allow a blocked popup however, normal URL permission checks are bypassed. "
So you have to MANUALLY disable the popup blocker on a site you don't know in order to make this work. Also, the article keeps talking about c:\whatever. It does not indicate if this is a vulnerability in a non-Windows system.
Already fixed: https://bugzilla.mozilla.org/show_bug.cgi?id=36942 7
Only 6% of my users so far this year are using Firefox 1.5x compared to 68% using Firefox 2.0. There are still about 4% of users who are using IE 6 without service pack 2 on XP (or are using IE6 on older versions of Windows). Point: it's a vulnerability that hackers won't bother to exploit and Mozilla will probably patch quickly anyway.
- John
http://www.jabcreations.com/