IE, Firefox Sport New Zero-Day Flaw

IE, Firefox Sport New Zero-Day Flaw

offline
  • SVITAC 
  • Legendarni građanin
  • Pridružio: 28 Apr 2003
  • Poruke: 5919
  • Gde živiš: Beograd

http://www.informationweek.com/story/showArticle.jhtml?articleID=188702223

By Gregg Keizer
TechWeb.com

Jun 6, 2006 07:53 PM

Multiple security organizations warned Tuesday that Internet Explorer, Firefox, Mozilla, and SeaMonkey -- on Windows, Linux, and the Mac -- are vulnerable to a JavaScript bug that could allow a determined attacker to dupe users into giving up sensitive personal information such as credit card or bank account numbers and passwords.

According to Symantec, which issued an alert late afternoon Tuesday, all versions of the Microsoft and Mozilla browsers could be used to harvest data through a JavaScript key-filtering vulnerability.

"This issue is triggered by utilizing JavaScript 'OnKeyDown' events to capture and duplicate keystrokes from users," went the Symantec warning.

The bug would let crafty criminals filter keystrokes entered into a form, say a credit card form to pay for online goods, to an invisible file upload dialog on the same Web page. Once the information's trapped in that hidden dialog -- the vulnerability discoverer used the analogy of the keystrokes "bouncing" from the legit (or at least legitimate-looking form) to the cloaked one -- the data could be sent to the attacker.

"Exploiting this issue requires that users manually type the full path of files that attackers wish to download…[and] may require substantial typing from targeted users, so keyboard-based games, blogs, or other similar pages are likely to be utilized by attackers to entice users to enter the required keyboard input to exploit this issue," continued Symantec.

Danish vulnerability tracker Secunia also posted warnings of the bug Tuesday, and ranked it as "less critical," the second-from-the-bottom rating in its five-step scoring system.

The bug is unusual in that it affects not only Internet Explorer -- including fully-patched IE 6.0 and even IE 7 Beta 2 -- but also Firefox (though the most current version 1.5.0.4), the Mozilla suite, and the separately-developed successor to Mozilla, SeaMonkey. It's also out of the ordinary by virtue of its multi-platform impact: users of those browsers running Windows, Linux, and Mac OS X are vulnerable, said Symantec.



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
offline
  • Pridružio: 11 Jun 2005
  • Poruke: 75

"Opera browser appears unaffected by this problem."

"Microsoft noted that it has not seen any malicious code that attempts to exploit the vulnerability."

news.zdnet.com/2100-1009_22-6081828.html?tag=zdnn.alert



Ko je trenutno na forumu
 

Ukupno su 1063 korisnika na forumu :: 41 registrovanih, 11 sakrivenih i 1011 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 3466 - dana 01 Jun 2021 17:07

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: A.R.Chafee.Jr., Apok, bankulen, bladesu, Bokiboks, bokisha253, cavatina, cinoeye, darkangel, dragoljub11987, drimer, esx66, Fog of War, goxin, HogarStrashni, hyla, ivan1973, Karla, kokodakalo, kunktator, kybonacci, Marko Marković, mercedesamg, milenko crazy north, mnn2, nemkea71, NoOneEver Dreams, Pikac-47, procesor, rajkoplje, RJ, sevenino, slonic_tonic, Srle993, stalja, Stoilkovic, Trpe Grozni, TwinHeadedEagle, vathra, Vatreni Zmaj, vladulns