Forum Moderators: open

Message Too Old, No Replies

New browser vulnerability

...and it's not just IE this time

         

bedlam

5:29 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Secunia Research has reported a vulnerability, which affects most browsers. The vulnerability can be exploited by a malicious web site to "hi-jack" a named browser window, regardless of which web site is the true "owner" of the window.

Link: [secunia.com ]

Sounds like a good opportunity to compare the relative response times of the IE, Safari and Mozilla teams :)

-B

jatar_k

6:14 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



i tested it and I got

exploit doesnt work in firefox or moz and only works in IE with pop up blocker on

bedlam

6:19 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



It definitely does work on Mozilla 1.7.x and Firefox 1.0 browsers (on a Win 2k system), but apparently only once per session, as I have to restart the browser to get it to happen again.

-B

jatar_k

6:26 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



hm

i did that as well and couldn't get it to work cept in IE

I am on windows xp with sp2
moz 1.7.3
ff 1.0
ie 6.0.2..... up to date anyway

bedlam

6:31 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Weird! That's the identical set of browsers I tested it with...

-B

jatar_k

6:33 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



maybe win2k against xp sp2?

that is weird

and I wasn't calling you a liar I just found it odd, I should have explained more sorry.

bedlam

7:00 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Oh, I didn't mean to give the impression that I was peeved at being contradicted either :)

Seems odd that Secunia would have missed an OS difference. It's odd.

-B

It will also be side-splittingly hilarious if it turns out that SP2 protects some other applications from exploits that IE is still vulnerable to...

jatar_k

7:07 am on Dec 9, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



hehe, yes it would ;)

Solution1

7:22 pm on Dec 9, 2004 (gmt 0)

10+ Year Member Top Contributors Of The Month



You have to left-click on the link, or else it doesn't work. So if you're used to right-click and select "open link in new tab," you might be investigating this less than thorough.

On my Win2k system the exploit works with Firefox 1.0, Opera 7.54, Netscape 7.1 and IE6.

jatar_k

7:28 pm on Dec 9, 2004 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



I left clicked

mifi601

8:16 pm on Dec 9, 2004 (gmt 0)

10+ Year Member



It does not work on Mozilla 1.6, win2k

Philosopher

8:27 pm on Dec 9, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Works in ff 1.0 on WinXp with no service pack installed.

tedster

6:52 pm on Dec 13, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Looks like Opera is the first to fix this:

[webmasterworld.com...]