It is currently Tue May 06, 2025 8:09 pm View unanswered posts | View active topics |


Board index » Community » Community Discussion


Post new topic Reply to topic  [ 2 posts ] 
Author Message
 Post subject: For those that use Firefox
PostPosted: Fri Feb 25, 2005 2:14 pm 
The Mexican Reject
The Mexican Reject
User avatar

Joined: Wed Oct 27, 2004 9:18 am
Posts: 2121
Location: Spanking you from behind...
Heads up from another forum I whore...

Quote:
__Summary

Remember my Internet Explorer "scrollbar exploit" based on http-equiv's
"What a Drag"? When will people ever learn that "unusual user interaction"
can be hidden by common tasks...

Let's combine fireflashing, firetabbing, xul and javascript to run arbitrary
code by dragging a scrollbar two times.

__Proof-of-Concept

http://www.mikx.de/firescrolling/

__Status

The exploit is based on multiple vulnerabilities:

bugzilla.mozilla.org #280664 (fireflashing)
bugzilla.mozilla.org #280056 (firetabbing)
bugzilla.mozilla.org #281807 (firescrolling)

Upgrade to Firefox 1.0.1 or disable javascript.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the name CAN-2005-0527 to this issue.

__Affected Software

Tested with Firefox 1.0 on Windows and Linux (Fedora Core)

__Contact Informations

Michael Krax <mikx@mikx.de>
http://www.mikx.de/?p=11



In short: Go upgrade to 1.0.1 asap. :) [/code]


Top
 Profile  
 
 Post subject:
PostPosted: Fri Feb 25, 2005 6:08 pm 
The legend. Teh Ponuh™
User avatar

Joined: Thu Oct 07, 2004 6:36 pm
Posts: 7134
Location: I will eat you alive I will eat you alive
Ooo. I should do that for my PC

and since FIrefox copied the living shit out of safari i should go update that too LOL


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

Board index » Community » Community Discussion


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group