Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Security hole hits Internet Explorer and Firefox

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Latest Breaking News Donate to DU
 
Bucky Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 04:57 PM
Original message
Security hole hits Internet Explorer and Firefox
Security hole hits Internet Explorer and Firefox
Tom Sanders in California, vnunet.com 07 Jun 2006

Microsoft's Internet Explorer and Mozilla's Firefox are both vulnerable to a new JavaScript flaw that could allow attackers to steal confidential information.

The flaw affects fully patched browsers on Windows, Linux and Mac systems, according to a posting on the Full Disclosure security mailing list.

The issue is caused by the 'OnKeyDown' JavaScript feature that allows websites to capture and duplicate keystrokes entered into data fields, including fields where users enter credit card information.

Security experts noted that exploiting the flaw would require the user to type a fair amount of text. Attackers would therefore most likely target online games or blogs.



Printer Friendly | Permalink |  | Top
BadGimp Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 05:00 PM
Response to Original message
1. This is just frickin great!
Printer Friendly | Permalink |  | Top
 
truthisfreedom Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 05:02 PM
Response to Original message
2. K'nR, thanks!
Printer Friendly | Permalink |  | Top
 
LifeDuringWartime Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 05:08 PM
Response to Original message
3. use NoScript
for Firefox users, Noscript is an extension that allows to you optionally allow Javascript for each page you visit, and from each domain it is run from.

http://www.noscript.net/whats
Printer Friendly | Permalink |  | Top
 
CatholicEdHead Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 07:14 PM
Response to Reply #3
8. I have it and it works great
No Javascript issues for me.
Printer Friendly | Permalink |  | Top
 
mcscajun Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 08:21 PM
Response to Reply #3
13. It's the #2 "Top Download" on Firefox Central today.
No surprise there. :)

I just got it, thanks!
Printer Friendly | Permalink |  | Top
 
jbnow Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-08-06 03:13 AM
Response to Reply #3
15. Thanks. I got it but
can you tell me what we do need Javascript for? When we would have to allow it? I noticed here we need it for spell check. Is that how we find out? See what doesn't work when we have it disabled?
Printer Friendly | Permalink |  | Top
 
Massacure Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-08-06 09:01 AM
Response to Reply #15
17. Java script is what opens the spell check window at DU.
If you disable it, you cannot get the spell check window to pop up. Java script does a lot of interesting things that make browsers more functional. The biggest problem with it is that some sites they will abuse the ability to resize windows or switch orders and such, usually trying to pitch advertisements at you. It's more annoying than anything. In those situations you can just turn java script off in the fire fox brewers, reload, and it prevents them from resizing windows. I think Internet Explorer can disable java script too, but I'm not sure where it is, the browser is much more complex.
Printer Friendly | Permalink |  | Top
 
McKenzie Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 05:10 PM
Response to Original message
4. Simple solution people
disable JavaScript irrespective of browser type. I suspect this exploit will affect any browser if it's based upon a JavaScript trick.

I'm on a Mac using Safari just now although I usually use Opera but I'm stll leery of JS; I rarely ever surf with JS enabled.
Printer Friendly | Permalink |  | Top
 
bananas Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 07:03 PM
Response to Reply #4
6. The NoScript extension for firefox
disables javascript, java, flash, and everything else,
except for sites you specify.
Printer Friendly | Permalink |  | Top
 
PetraPooh Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 07:07 PM
Response to Reply #4
7. Agree and support recommendation. Firefox makes it so easy
this is why I like Firefox so much. The noscript is easy to install and an icon in the lower right corner allows one to enable java selectively and temporarily for the sites that just need it enabled to work (usually I know which they are as the "clicks" don't appear to work until the java is re-enabled temporarily). I like the temporary aspect because it keeps me from enabling and then forgetting to re-disable.
Printer Friendly | Permalink |  | Top
 
electron_blue Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 11:03 PM
Response to Reply #4
14. Can you give basic instructions for how to disable it?
Printer Friendly | Permalink |  | Top
 
AlamoDemoc Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 05:36 PM
Response to Original message
5. K & R ...thank you
Printer Friendly | Permalink |  | Top
 
UpInArms Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 07:15 PM
Response to Original message
9. can I offer a suggestion?
www.opera.com

:loveya: Opera
Printer Friendly | Permalink |  | Top
 
checks-n-balances Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 08:04 PM
Response to Original message
10. Even my beloved Firefox is vulnerable:( - so THANKS for the heads up!
n/t
Printer Friendly | Permalink |  | Top
 
Pierre.Suave Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 08:07 PM
Response to Original message
11. I wonder...
if this affects Camino in the same way as it does Firefox?
Printer Friendly | Permalink |  | Top
 
Sgent Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Jun-07-06 08:09 PM
Response to Original message
12. There is a real quesiton
if this is even a security hole in the first place. If it is -- its not critical by most standards.

The exploit this uses requires:

1) That a website is compromised by an attacker (or you visit a rogure website, beware of warez).
2) That you upload a file.
3) That the website uses javascript (vs other methods) for you to select the file to upload.
4) That in the file selection box, you type the file instead of selecting it (using the browse button).
5) In that case, the attacker get's access to the uploaded file -- but not access to your computer or anything else.

The reason for this is complex, but this is an exploit of Javascript which behaves exactly as designed. The only method of correcting this is to override the "onKeypressDown" method -- which takes a lot of functionality out of JS.
Printer Friendly | Permalink |  | Top
 
Born Free Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Jun-08-06 04:28 AM
Response to Reply #12
16. There is a real quesiton
If you are correct, as long as you don't upload any files with confidential information you are ok.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri May 03rd 2024, 09:43 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Latest Breaking News Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC