Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > The World Wide Web > Browser & General Internet Questions » Firefox 3 Untimely Security Advisory
Closed Thread
Old 06-27-2008, 10:15 AM   #1 (permalink)
Osiris's Avatar
 

Join Date: Jan 2005

Location: Kentucky

Posts: 32,219

Osiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the roughOsiris is a jewel in the rough

Send a message via ICQ to Osiris Send a message via AIM to Osiris Send a message via MSN to Osiris Send a message via Yahoo to Osiris Send a message via Skype™ to Osiris
Default Firefox 3 Untimely Security Advisory

Although all the source code of Firefox is public and can be scrutinized during development at any time, a Tipping Point Security Advisory has been announced right in the middle of the Firefox 3 download day.
A unlucky coincidence, of course: only a conspiracy theorist could suspect that the timing had been chosen in order to maximize the hype effect for the Zero Day Initiative.
However Mozilla developers are working around the clock, and there’s already a patch being privately tested. All the information publicly available so far is that this vulnerability allows a malicious web page to trigger the execution of arbitrary code on the client side, and affects Firefox 2, 3 and likely all the products based on the same rendering engines. Technical details and exploitation proof of concepts are being kept private by Tipping Point as well until the patch is shipped, therefore Mozilla users should be relatively safe: after all we can be 99.99% sure every browser out there is vulnerable to something; we just hope that the bad guys don’t know the details yet.
I can add that, even in this case, NoScript users are the safest.

hackademix.net - Giorgio Maone's answers to the Web, the Universe, and Everything
__________________
Osiris is offline  
Old 06-27-2008, 01:32 PM   #2 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,722

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Re: Firefox 3 Untimely Security Advisory

So now there are 2 known flaws in Firefox 3 that happened on Download Day. :laughing:

There was the one that was found 5 hours into it and now this one. Unless they are the same thing. But still goes to show you that even with the extra RC testing it wasnt ready.

Cheers,
Mak
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is offline  
Old 06-27-2008, 03:26 PM   #3 (permalink)
Trotter's Avatar
 

Join Date: Jan 2005

Location: The South

Posts: 19,959

Trotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to all

Default Re: Firefox 3 Untimely Security Advisory

No code is ever completely invulnerable. At least they were found quickly and are being fixed.

It amazes me how some of these holes work... "If you twist your arm backwards and cross your eyes while holding your breath and biting on a wintergreen Certs, you have the possibility of clicking a fuzzy link on a broken website written in prehistoric hieroglyphics which could allow a retarded chimpanzee to have access to you Recycle Bin. This flaw has been rated super-duper extremely criticalitious."
__________________
R.I.P. Danny L. Trotter , 14 Nov 1945 - 4 Sept 2009




DFI LanParty-UT SLI-D - Windows 7 64-bit - AMD Athlon X2 4200+ w/CNPS9500
4GB RAM(4x1GB) - Razer Lachesis - EVGA GTX 260 Core 216 896MB


>>>> I am looking for donated DDR2 (link) <<<<

< < < < < If I've been helpful, rep me. . . .
Trotter is offline  
Old 06-27-2008, 03:48 PM   #4 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,722

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Re: Firefox 3 Untimely Security Advisory

I am not saying that there is code that cant be hacked. Just a shame that they got 2 flaws with brand new code reported on the first day. Even with 3 different RC versions. That just sucks.
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is offline  
Old 06-27-2008, 04:21 PM   #5 (permalink)
Trotter's Avatar
 

Join Date: Jan 2005

Location: The South

Posts: 19,959

Trotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to allTrotter is a name known to all

Default Re: Firefox 3 Untimely Security Advisory

That it does.
__________________
R.I.P. Danny L. Trotter , 14 Nov 1945 - 4 Sept 2009




DFI LanParty-UT SLI-D - Windows 7 64-bit - AMD Athlon X2 4200+ w/CNPS9500
4GB RAM(4x1GB) - Razer Lachesis - EVGA GTX 260 Core 216 896MB


>>>> I am looking for donated DDR2 (link) <<<<

< < < < < If I've been helpful, rep me. . . .
Trotter is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need steps for getting rid of SystemDefender.exe Trotter Virus - Spyware Protection / Detection 16 04-07-2008 06:57 PM
Firefox Security and Stability Update Osiris Windows Operating Systems and Software 8 02-09-2008 02:19 PM
Homeland Security computers hacked Osiris Virus - Spyware Protection / Detection 0 09-25-2007 07:57 AM
Critical Security Flaw Discovered In IE & Firefox Osiris Browser & General Internet Questions 6 07-18-2007 09:04 PM
User Locked Out of Account....Its Weird Though.... qbbraveheart Computer Networking & Internet Access 2 05-07-2007 09:58 AM