Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Firefox > Phishing with Firefox!

Reply
Thread Tools

Phishing with Firefox!

 
 
Reg Mouatt
Guest
Posts: n/a
 
      11-03-2004
Food for thought - spotted this on:
http://www.theregister.co.uk/2004/11...bbed_browsers/

Secunia issued a security report detailing how most major web browsers
with the tabbed browsing feature were vulnerable to two different
vulnerabilities.

First, the browsers. Recognize any you use?

* Mozilla 1.7.3
* Mozilla Firefox 0.10.1
* Camino 0.8
* Opera 7.54
* Konqueror 3.2.2-6
* Netscape 7.2
* Avant Browser 9.02 build 101 and 10.0 build 029
* Maxthon (MyIE2) 1.1.039


Now, the vulnerabilities. One of them is pretty clever, and one of
them, I think, is a bit overstated, but I'll explain that in a second.

1. You have a couple of different websites open in a couple of
tabs. You open another tab and head over to a trusted website, like
PayPal's. You're on the PayPal site, when suddenly a dialog box opens,
apparently from PayPal, and asks you to enter your password and your
credit card info, "for verification purposes". You do so and keep
using the PayPal site, never realizing that it was not the PayPal tab
that spawned that dialog box, but a web site on a different, inactive
tab. To see what I'm talking about, open the demo site at Secunia with
an affected browser and follow the instructions. Very clever.

There are two problems here. First, the browser doesn't easily
keep the user informed as to which tab is responsible for the dialog
box. That's an easy fix. Second, the browser shouldn't allow inactive
tabs to spawn dialog boxes in the first place. Another easy fix. But
still - not good. Clearly, none of the organizations creating these
browsers ever envisioned such an attack. Of course, this attack will
only work if you're already on a shady web site to begin with, and if
that site knows you've gone to a site that it knows you trust, like
PayPal. As Secunia itself points out, for this sneaky stunt to work it
would "normally require that a user is tricked into opening a link
from a malicious web site to a trusted web site in a new tab".
Clearly, the likelihood of that string of events is pretty small. But
it's still clever, and it would undoubtedly get a lot of folks in
trouble if they somehow had both the "bad" and the "good" sites open
at the same time in separate tabs.
2. The second vulnerability strikes me as even less likely, but
perhaps I'm wrong. Let's say you have a couple of different web sites
open in a couple of tabs. You open another tab and head over to a
trusted website, like PayPal's. You type in your username and
password, but nothing shows up. You type it again. Still nothing.
Assuming that PayPal's site is temporarily borked, you close the tab
and continue on your merry way. Little do you know that everything you
typed actually went into a form on a site found on one of your other
tabs. If you want to see this in action, Secunia has a demo site up
for this one as well.

Reg
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Google anti-Phishing tool for Firefox History Fan Firefox 2 02-05-2006 06:51 PM
Netcraft anti-phishing Toolbar Stubby Firefox 4 06-07-2005 06:14 PM
Major Phishing Hole Found In IE and OE Jay Calvert Firefox 5 02-18-2005 03:30 AM
Firefox Phishing vulnerability Tony Raven Firefox 1 01-07-2005 06:41 PM
OT: Phishing Quiz catwalker63 MCSE 6 08-03-2004 06:01 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57