Jump to content


Firefox Cookie Bug


10 replies to this topic

#1 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 15 February 2007 - 09:47 PM

Quote

There's a new bug reported in the way Firefox handles writes to the 'location.hostname' DOM property. The vulnerability could potentially allow a malicious website to manipulate the authentication cookies for a third-party site. The bug was submitted by Michal Zalewski and was tested with the current version of Firefox.

The bug could allow for the browser to appear as if were connecting to a bank, when in fact it would instead be receiving data from a bad guy.A demo of the vulnerability and a suggested work-around can be found here.
F-secure article

#2 OFFLINE   krit86lr

    Power Member

  • Members
  • PipPipPipPip
  • 1,958 posts
  • Gender:Female
  • Location:Missouri, USA

Posted 15 February 2007 - 09:51 PM

Oh, no! :( I hope it's fixed quickly.

#3 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 15 February 2007 - 10:10 PM

When I tested FF the noscript extension stopped the test site.

I then allowed the test site and I was supposedly vulnerable so I implemented the "about:config" setting and that seemed to fix it.

#4 OFFLINE   Andavari

    Captain Spectacular

  • Moderators
  • 13,324 posts
  • Gender:Male
  • Location:Shadow Moses

Posted 16 February 2007 - 08:58 PM

View PostHumpty, on Feb 15 2007, 04:10 PM, said:

I then allowed the test site and I was supposedly vulnerable so I implemented the "about:config" setting and that seemed to fix it.
Ditto, the fix works for me too in the interim. I wonder though if/when Mozilla fixes it if we'll have to remove the fix.
Complexity of incoherent design.

#5 OFFLINE   JDPower

    Cydonian Knight

  • Members
  • PipPipPipPipPip
  • 2,952 posts
  • Gender:Male
  • Location:England

Posted 16 February 2007 - 10:08 PM

View PostAndavari, on Feb 16 2007, 08:58 PM, said:

Ditto, the fix works for me too in the interim. I wonder though if/when Mozilla fixes it if we'll have to remove the fix.
With it being a Mozilla suggested fix I wouldn't think so (wouldn't be surprised if the official fix just does the same thing)

#6 OFFLINE   fireryone

    Lets Get Dangerous

  • Members
  • PipPipPipPip
  • 1,626 posts
  • Gender:Male
  • Location:QLD,Australia
  • Interests:PC, LOTRO

Posted 17 February 2007 - 12:53 AM

Quote

There's a new bug reported in the way Firefox...
Thanks I've fixed mine :)
fireryone



There are 10 types of people in this world.
Those who understand binary, and those who don't.

#7 OFFLINE   Sputnik

    Advanced Member

  • Members
  • PipPipPip
  • 238 posts

Posted 17 February 2007 - 07:49 PM

View Postfireryone, on Feb 17 2007, 01:53 AM, said:

Thanks I've fixed mine

Dito :)
Ceci n'est pas une signature

#8 OFFLINE   TeeJay3800

    Power Member

  • Members
  • PipPipPipPip
  • 675 posts
  • Gender:Male
  • Location:Metro Detroit

Posted 20 February 2007 - 01:57 AM

I fixed mine too, but now www.howardforums.com will not load for me. Is this happening to anyone else?
Dell Latitude D600
Windows 7 Ultimate 32-bit SP1

Posted Image

#9 OFFLINE   Humpty

    Super Hero

  • Members
  • PipPipPipPipPip
  • 2,125 posts

Posted 20 February 2007 - 02:02 AM

Howards Forum is loading OK here.

In case the test site for the fix can't be accessed.

An interim workaround suggested by Firefox developers is to Open Firefox, go to the Address Bar and type: about:config
Then right-click anywhere on the page to add a new string key: capability.policy.default.Location.hostname.set
Set its value to noAccess

#10 OFFLINE   JDPower

    Cydonian Knight

  • Members
  • PipPipPipPipPip
  • 2,952 posts
  • Gender:Male
  • Location:England

Posted 20 February 2007 - 06:18 AM

View PostHumpty, on Feb 20 2007, 02:02 AM, said:

Working fine here too.

#11 OFFLINE   Woody

    Advanced Member

  • Members
  • PipPipPip
  • 457 posts
  • Gender:Male
  • Location:Manchester. UK

Posted 20 February 2007 - 01:42 PM

Works here as well.

God isn't that site weird? One guy on there has over 7500 posts, all about mobile phones! :unsure:

The words Get and Life spring to mind. :lol:
It is never difficult to distinguish between a Scotsman with a grievance and a ray of sunshine. P. G. Wodehouse