Version: 2008
  • On CBS MoneyWatch: 5 Best College Towns to Live In

Comments on: Spoofing flaw resurfaces in Mozilla browsers

A 7-year-old security hole comes back to haunt the most recent version of Firefox and other Mozilla software.

Add a Comment (Log in or register) (11 Comments)
  • prev
  • 1
  • next
Requires both windows to be open....
by hion2000 June 6, 2005 6:09 PM PDT
...how "easy" is it to trick someone to do that?
Reply to this comment
very easily
by June 6, 2005 6:18 PM PDT
a malicious web site can create the second window linking to a common bank site or easily cash in on the spelling mistakes of domain names. Only takes someone gullible enough to think they must have accidently opened there banking site.

eg. register www.bankk.com, then when someone misspells it launch a second window with www.bank.com. using common spelling errors in domain names is a very common method for adware and would work here to exploit this vulnerability.
View reply
IE 6 does the same thing.
by System Tyrant June 6, 2005 8:41 PM PDT
Just for fun I tried the test located here

http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/

on Firefox 1.0.4 and IE 6. They both did the exact same thing. So I suppose it is a flaw with both IE and Firefox.

Well hopefully Mozilla and Microsoft will get it fixed. I am willing to be though that Firefox will see a patch before IE 7 does.
Reply to this comment
no
by June 6, 2005 9:00 PM PDT
MS had this vulnerability some time ago and it has been fixed for over a year.
View all 2 replies
Opera's safe from this one.
by June 6, 2005 9:42 PM PDT
Yet again.

Tried it in IE6, Firefox and Opera.
oops
by June 6, 2005 9:12 PM PDT
I take that back, seems MS had the same issue reoccur again as well lol.
Reply to this comment
(11 Comments)
  • prev
  • 1
  • next
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement