Firefox Quickies
First, Gypsy2012 writes with a highly critical security flaw involving both Firefox 2.0 and Internet Explorer, which could allow a malicious attacker to gain remote control of a user's system. It exploits the "firefoxurl://" URI handler. ... Next, reader dsinc sends word that the beta for Firefox 3 has slipped by 6 weeks. The new target date is September 18 at the earliest. The article wonders whether the final release will slip into 2008. ... Finally, reader jktowns points out new anti-phishing features in the latest nightly build of Firefox 3. One of them was added into the code base by the guy who developed the LocationBar2 extension.
Demonstration
Cmd.exe
This should launch cmd.exe....
Notice that you must click that link from internet explorer, firefox will warn you that an external application is being called.
above example taken from here
NewslilySocial News. No lolcats allowed.
Finally!
First, Gypsy2012 writes with a highly critical security flaw involving both Firefox 2.0 and Internet Explorer
Earlier when Microsoft's IE team flew over to Mozilla HQ to ask them about their RSS icon, I knew it that's the beginning of a wonderful partnership.
but anyhow, has anybody else been paying attention to the fx javascript additions? Stuff like let, Array.forEach, etc. And what's the deal with the javascript 2.0 proposal? Am I the only one that thinks they're trying to ruin it?
Do you even lift?
These aren't the 'roids you're looking for.
Granted if it's a bug it needs fixed regardless, but I would be more shocked if it said "allows a person to gain remote access on ALL systems running said software".
Why are you bolding things in a style not normally used on Slashdot?
There are some sites that don't work with Firefox.
Hell, I've got Firefox on my WIndows system (but Opera is my main browser,) and I usually end up using IE for some sites.
Sorry, can't try it right now as I'm on Ubuntu (Feisty Fawn). But I'll look into it tomorrow when I get to work.
Yes QA testers. Or people who don't really pay attention and use Firefox normally. But when an app or email says "click this link" and IE is the default browser if pops up.
I use IE from time to time when some stupid web page isn't compatible with Firefox or when some stupid web page fails to render or process forms correctly even after disabling NoScript.
Normally, I'm surfing with Firefox and NoScript and AdBlock and ....
It keeps me safe.
If a site doesn't work with that, then fuck them. I only need IE for some work related sites that have stupid ActiveX controls.
So this will only hit me if I have Firefox and Internet Explorer installed?
What's Internet Explorer?
In fact, this is my primary usage model. I use IE 7.0 for most general browsing since it's "good enough" and it's actually more reliable than FF (crashes less often). But Firefox tabs are just way faster (actually, it's the other way around - IE tabs are horrendously slow). So for my morning-news scenario, I launch my RSS aggregator through FF and middle-click away.
I actually figured out the issue on a intranet site at work. When IE (which has become the default expected behavior) passes a field into a url, if its blank it inserts a null character, when firefox does it, it omits the field. This borks code that doesn't expect the field to be omitted.
My Babylon
Firefox crashes for you? Read the MozillaZine Knowledge Base article about Firefox crashes and you can probably fix your problem.
What a fool believes, he sees, no wise man has the power to reason away.
In case anyone was wondering. Seems like skipping version 2 was a good choice after all.
Firefox hasn't released a fix for this, and there is no mention of it on their web site.
Now this blows:
http://secunia.com/advisories/25984/
> Solution:
> Do not browse untrusted sites.
> Disable the "Firefox URL" URI handler.
The first is impractical. The second begs the question, "Sure, How?" Read on:
> Extended Solution:
> The "Extended Solution" section is available for Secunia customers only.
> Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.
So these guys are publishing zero day security flaws, then making you reach for your credit card. Very grubby.
The CNET article doesn't tell you what the fix is either. Google has nothing. Anyone?
Open Windows Exporer (not Internet Explorer) and from the Tools menu select "Folder Options" menu. On the dialog that appears select the "File Types" tab.
Now in the list of registered file types find the one that says:
"(NONE)" for extension and "Firefox URL" for file type
Select it and click on delete button to delete it.
Click on "OK" to close the "Folder Options" dialog.
As the island of our knowledge grows, so does the shore of our ignorance.
Firefox will warn you if a program tries to use other protocols. It will allow you to suppress the warning, however, which can cause the same problem as IE, but at least you can't say you weren't warned. So from this POV, it is IE's problem moreso than Firefox's, especially when it's considered that the URLs can't do anything from WITHIN Firefox, and that (I haven't checked this, just heard it somewhere) the protocol was requested by MS for some Vista compatibility thing or some such nonsense. Not sure if there's anything to that.
However, on the flip side, anyone who implements a protocol needs to be aware any web page can invoke the protocol at will, without the consent of the user (well, thanks to IE's "standards"). This results in being able to do things like this. This webpage redirects the browser to steam://open/main, which will open the main Steam window. The user never sees the actual url. This could work with the firefoxurl protocol as well. Here are some other things that can be done, some of the uglier ones have confirmation screens I believe, but launching a game or connecting to a server does not. Note the first one which promises that it can redirect command line arguments, just like firefoxurl... however I cannot get that to work (I tried -shutdown and it just focused the main window like my current sample does). Also note the hackish steam://openurl/, which is designed to allow Steam's built-in IE browser to invoke the computer's default browser. Theoretically this could be used to bypass a popup blocker.
Of course it would appear that Steam at least can't run arbitrary programs and is limited to it's own folder in terms of effects (I could force you to join my UBER LAME COUNTER STRIKE SERVER but that's about it).
I think both Microsoft and Mozilla need to take steps to fix this problem. Microsoft needs to improve external protocol handling to at least what Firefox does (Firefox could even secure its own handling more, but that might detract too much from the flexibility. Not that that's stopped anybody before). Mozilla should remove this silly firefoxurl bit. I can't think of any legitimate reason for it (anyone have any clue?).
As for Valve with Steam... steam://openurl/ is a bit much I think. It's expected for users who don't know what MSHTML or ActiveX are to think it's a bug that external windows open in IE, but us devs know that, internally, IE is just spawning a new window for a page. Since when were you browsing the web in IE and click on a link and it popped open in Firefox? I wouldn't want that to happen if I preferred IE! (Yeah... firefoxurl is definitely useless.) I mean, can't Valve say that because Steam uses Internet Explorer internally for the Store, all launched webpages will appear in Internet Explorer and there's no way around it? Eh probably not. The technically inclined probably think everything is great now and wouldn't care if anyone told them Valve used a hackish and possibly unsafe solution.
Although at the least they could use a whitelist for urls to use for openurl... IE steampowered.com and whatever other sites they link to... although considering the number of third party games being added it could be a largish list. :(
Perhaps steam could kick the steam:// thing entirely, but the only alternative I can think of is an Internet Explorer BHO (ick, not worth the trouble IMO), unless they can do something fancy with javascript or java or flash or something.
Here's a bonus for reading all this: You can see what available protocols Windows / Internet Explorer can use (Firefox too, although it has its own extras like about: and data:) by checking HKEY_CLASSES_ROOT in regedit. Search for Values with the exact name of "URL Protocol" and the keys you find (or maybe it's in the default value?) are the protocol names. With a look it can be easy to figure out how
Got another reason to love Opera..I used it as my main browser cus i i just find firefox too slow to startup compared to opera and the page rendering is slower too. Plus opera comes with everything I need out of the box: adblock, mouse gesture, password wand, and fast forwarding backwarding. By the way, opera looks somehow whacked up when installed on my ubuntu feisty.. must be the font or something????
The fact is that the URI handler firefoxurl:// is installed by.... Firefox.
In other words, IE is redirecting to the firefoxurl DLL or EXE installed by Firefox, and that is the code which is executing user input without warning.
To me it seems disingenuous to blame the IE implementation for handing control to the Firefox protocol handler, which is treated like a shell plug-in. It seems the responsibility to prompt the user should rest on the protocol handler. Otherwise, IE would be expected to prompt on the execution of any protocol handler that was unknown at the time that IE shipped, or some such "prompting heuristic." This would be inconvenient and also subjected to ridicule on /.
Apparently, the NoScript firefox plugin solves this problem (or so they claim at the website: http://noscript.net/).
So this will serve as a workaround for those who wanted one.
I knew there was a reason to use Safari :-)
Dear Sir,
LOL!
Sincerely,
Me
Same as in town, fifty bucks
What?
It's called Konqueror.
After reading about "firefoxurl" and what it does, I only have one simple question: what on earth were they thinking when they implemented it? What's it supposed to be useful for?
As far as I can tell, the only use it could possibly have is creating desktop URLs that always open in Firefox, however there's no reason why they would have to create a URL handler to do that. Otherwise, it's completely worthless and, as discovered, a security risk, to boot.
For added fun, attempting to use a "firefoxurl" URL while Firefox is already running creates an infinite loop. (It just keeps on asking you to allow an "external application" to launch. It doesn't even seem to actually work. I get the same results when launching it directly from IE through the address bar.)
Why was this implemented? What was it supposed to do?
And, for bonus points, is it possible to write a firefoxurl that, when opened in IE, would unregister the firefoxurl handler?
You are in a maze of twisty little relative jumps, all alike.
which ones? I've never encountered one of these mythical sites...
I could imagine web developers in the position you describe--especially old ones who are used to using IE. They still keep FF on hand to check compatability.
As for myself (I am not a web developer) I have FF installed but don't usually use it--I primarily use Opera.
curse the slashdot moderators and die.
www.purevolume.com/martyd
MSDN didn't work with Firefox for a while back in the 1.x days. I had IETab to fix that. Seems to work fine for me now though. The local Intranet at work here doesn't get the menus working right (they unroll in the top left hand corner of the screen, no matter where they were supposed to) which makes browsing the intranet a hassle. Other than that I have no issues either.
Most people using Firefox wouldn't be browsing MSDN anyway, and only IT people where I work would be able to have Firefox installed, so its not really a big deal.
Cheers, Chris
I interpret that as saying that the Firefox installer messed with Windows and Internet Explorer, opening a hole. Is Window/IE really to blame when another application adds "features" that end up being holes?
If Windows/IE were to filter what can and cannot happen through URI handlers, I could see developers crying foul for preventing access and locking out competition.
Further, is the onus now on Microsoft to fix a hole created by Firefox? And once they fix it, and legit things break because of it, who's fault will that be?
-David
That's why we have IE Tab. https://addons.mozilla.org/en-US/firefox/addon/141 9
"It's never the things that happen to us that upset us, it's our view of them." -Epictetus
Hey, don't get mad at ME if this "Firefox exploit" depends upon IE being insecure.
An application is only as secure as the system it runs on.
I'll stick to Ubuntu where I have a choice.
If that offends you, too bad. Get a life and stop trying to make a religious war out of an OS.
Does this exploit create the ability to extend privliges beyond those that the user logged in has?
He who said 1,000,000 monkeys on 1,000,000 typewriters would eventually type the great novel, never saw an AOL chat room
For firefoxurl:
Notice that removing the firefoxurl from Folder Options/File Types does not solve the issue, as FF rebuilds the association once it restarts.
So, here's another way that appears to work, at least in XP:
1- Click on the test link above (or run a firefoxurl)
2- When the dialog box opens, check the box to automatically apply the same answer in the future.
3- Press Cancel (and not OK)
firefoxurl should now be disabled without further dialog boxes. Enjoy
I tried a number of the examples provided at http://www.xs-sniper.com/sniperscope/IE-Pwns-Firef ox.html, but they don't seem to work on my test system.
He who said 1,000,000 monkeys on 1,000,000 typewriters would eventually type the great novel, never saw an AOL chat room
In Brazil, almost all internet banking sites require IE because of this or that. I think there must be some cases like this in other countries.
And thought, first my girlfriend, now firefox. I'll see a doctor about it, just stop complaining. You're just giving me performance anxiety.
Your ad here. Ask me how!
Just highlighting domains of phishing sites isn't going to be enough. Here's today's list of domains that "sort of look like Paypal". These are after subdomain truncation.u i.ork.pl"
"paypal-checker.com"
"paypal-contact.net"
"paypal-customize.com"
"paypal-erreur2.com"
"paypal-security.com"
"paypal-web-dll-scrnupdateaccount.ici.st"
"paypal-web-scrn-dll-pl-dai-pl-webscrndllfs-werty
"paypal.powered.at"
"paypal.q.fm"
"paypalaccverify.com"
"paypalcomcgibinwebscrcmd.by.ru"
"paypalcomcgibinwebscrcmm.by.ru"
"paypalcomcgibinwebscre.by.ru"
"paypalconstomers.com"
"paypalct.com"
"paypall.ro"
"paypalmd.com"
"paypalobjects.us"
"paypalsecuritycenter.org"
"paypalverification.org"
"paypel-acc-5.com"
"paypilpal.com"
"paypll-wscr.com"
"paypluspl.com"
These are from PhishTank, which blacklists at the URL level based on manual reports. For SiteTruth", we're in the process of converting to blacklisting phishing sites by the entire base domain. That's because we now see hundreds of entries like "session-624333.nationalcity.com.userpro.tw", which has to be treated as a bad indicator for all of "userpro.tw".
There's collateral damage. There are days when "tinyurl.com" and "notlong.com" get blacklisted, because phishing sites use them. MSN gets complaints about this. Today, anybody running something like "tinyurl" needs to continually check the phishing databases for attempts to abuse their service, or their own reputation is toast.
If the lame 'I use Opera post...' gets a 5, then so should yours! I should imagine that most users here do NOT use IE as their default browser, and if using Firefox, have it loaded up with Adblock, Noscript, phishtank...as do I
Well, there is always:F irefox_-_Remote_hacker_automatic_control
http://www.beskerming.com/security/2007/07/11/35/
The solution is in there, along with the report. Even when disclosing content that is extremely time sensitive, that information will always be available from our site.
InfoSec that matters, when it counts.
From Arstechnica: http://arstechnica.com/journals/microsoft.ars/2007 /07/10/firefox-and-internet-explorer-team-together -for-critical-vulnerability
Thor Larholm, the researcher who discovered the flaw, insists that the blame falls on the back of Internet Explorer. "Firefox is the current attack vector but Internet Explorer is to blame for not escaping quote characters when passing on the input to the command line." He also notes that Internet Explorer behaves similarly with other handlers. "Internet Explorer doesn't filter the input for the irc:// or aim:// URL protocol handlers either. The exploitability on those depend on what arguments each application accepts."
The director of Symantec's Security Response Center, Oliver Friedrichs, believes that both browsers should share the heat. "You have two very complex applications that are not playing well together and leading to a security issue. The components themselves are secure as stand-alone products but not together."
Does not work in XP. The entry is rebuilt by FF once FF is restarted
I do not get waht the fuss is all about. If firefox is started from IE that has to ring a bell. Second I get a warning from Firefox that it wants to start an external application and I can click no and nothing happens. I have never before seen that question from firefox so I have run into a website that uses this vulnerability. Beside this happens when you are surfing using IE. If you surf using IE then you are asking for problems in the first place.
What sites are those? I haven't come across a site that didn't work in Mozilla in 3 or 4 years.
I still have more fans than freaks. WTF is wrong with you people?
We know that IE or Windows have its shares of security problems, but Firefox does not help by adding more security hole. While this will cause trouble for advanced users on slashdot, it sure will cause problems for the average joe user out there (for example: your mom or sister)
Neither of these that are mentioned in this link. IE7, Winxp sp2, firefox 2.0.0.4, limited user account. Links only open a blank tab in firefox, and a firefox warning to launch sth that doesn't launch. No new profile, no text.txt (although I've created one as instructed) no cmd, no nothing
Well shit, then they CAN'T exist! AuMatar hasn't seen them!
Why don't you give some examples then dumbass?
I wouldn't call it laughing. "You are coming to a sad realization. Cancel or allow?"
"If you've used Windows Vista for more than 3.7 minutes, you know what UAC (User Account Control) is.. it's the obnoxious, nagging popup window that will be your life for the next 3-5 years... Note: Disabling UAC will lead to a less secure system, so be warned. -- The How-to Geek
"~ $ ie
bash: ie: command not found" Internet Explorer is a Windows program. Does wine iexplore.exe work any better?
Open IE.
Go here http://www.xs-sniper.com/sniperscope/IE-Pwns-Fire
There is a solution for avoiding phishing: two-way login. Not only the user logs into a site, but the site submits a password to the user during the login sequence. The 2nd password is created during registration. If a site fails to submit the correct password to the user, then it's clearly a phishing site, even if the url is the same.
clicking that link in IE made Firefox try to run CMD.exe, but it still warned me, so i don't see how that's a security flaw.
-Clio
Karma: Bad (mostly from not giving a fuck)
Blog: http://clintjcl.wordpress.com
If IE tabs are too slow (which they are) and Firefox crashes too often (which it does); have you tried Opera? Best of both worlds.
What's purple and commutes? An Abelian grape.
I've got it installed, but all javascript enabled. If you read my previous post, the exploits don't work with my setup.
Because google can do a better job than I can, dumbass. Try acting like someone who walks erect for once.
Whoa! Been a long time since the Quickies happened! And it's not even a Friday!
Help us build a better map!
I run Vista, have both IE7 and FireFox 2 installed, and at present am browsing using IE7.
Clicking the link first caused IE7 to ask permission to open a program outside Protected Mode (Firefox, in this case). Click OK, and Firefox opens (well, it waits a while then prompts me to restore a session that ended when I last rebooted into Linux). Ok, so I finally get a blank Firefox window, and Firefox prompts me to open an external program (Firefox again, ironically). Click OK to that... and nothing happens. Meanwhile, IE7 throws out an error message stating it can't find the URL "firefoxurl:test" and I should make sure I typed it correctly. I click OK to that, close Firefox, and IE7 states that it can't even find a program that will handle the request.
Overall, I'm not too terrified of these firefoxurl: links. Two dialog boxes (not counting the session restore one), and in the end it did... nothing at all. Oh, the horrors; you might trick me into needing to close error messages! Bah... I really can't say I'm worried.
There's no place I could be, since I've found Serenity...
- Click link from IE7:
- IE7 says it needs to launch another program (Firefox) to handle this URL, that said program will open outside of Protected Mode, and that I should only do so if I trust the website.
- Click OK, and Firefox starts to open, either with a blank window or the Restore Session dialog followed by a blank window.
- Firefox says it needs to open an external program (itself, ironically), gives me a few seconds of unintelligible URL reading before it lets me click the OK button.
- Click OK... and nothing happens in Firefox and no program opens in Windows, so I close Firefox.
- IE7 tosses up a pair of error dialogs stating that the URL doesn't go anywhere and that the helper application rejected the protocol (firefoxurl).
Terrifying, ain't it! You could trick me into... closing error messages!There's no place I could be, since I've found Serenity...