Computer ForumsComputers  

Go Back   Computer Forums > The World Wide Web > Browser & General Internet Questions

Reply
 
LinkBack Thread Tools Display Modes
Old 11-17-2007, 05:47 PM   #1 (permalink)
Security/Hacking Mod
 
Osiris's Avatar
 
Join Date: Jan 2005
Location: USA
Posts: 24,712
Default Firefox users: Beware of Gmail XSS Attack

Firefox users: Beware of Gmail XSS Attack

An exploit for Firefox, reported 10 days ago and as of yet still not patched, is giving attackers access to Google accounts, including gmail.
Firefox users are advised to use NoScript or turn off javacript on unknown webpages and stay logged out of their Google Accounts until a fix is issued.

A 302 redirect error in Google, discovered by bedford.org's Morgan Lowtech aka tx, creates a domain-wide cross-site scripting attack allowing hackers to gain access and modify Google user accounts including e-mails, contact lists and online presence.

Osiris is offline   Reply With Quote
Old 11-17-2007, 07:12 PM   #2 (permalink)
Admin
Das BanHammer
 
Trotter's Avatar
 
Join Date: Jan 2005
Location: The South
Posts: 14,383
Default Re: Firefox users: Beware of Gmail XSS Attack

Thanks for the heads up. NoScript should be a part of everyone's extension library.
__________________
-Das Banhammer-



DFI LanParty UT nF4 SLI-D - AMD Athlon X2 4200+ w/ Zalman CNPS9500
2GB (2x1 GB) G.SKILL ZS Razer Lachesis - ATI 3850 w/Accelero S1

Use OpenDNS
Trotter is online now   Reply With Quote
Old 11-20-2007, 02:51 PM   #3 (permalink)
Wizard Techie
 
Join Date: Feb 2007
Location: Sidlesham
Posts: 3,186
Send a message via MSN to Nick
Default Re: Firefox users: Beware of Gmail XSS Attack

just when i was thinking how reliable firefox was
__________________
nIcK

Quote:
Originally Posted by Trotter View Post
Any friend of Nick's just means more work for us on the mod team, as all of them are nothing but trouble and must be watched like a hawk... just like Nick.
Nick is online now   Reply With Quote
Old 11-20-2007, 03:55 PM   #4 (permalink)
Admin
Das BanHammer
 
Trotter's Avatar
 
Join Date: Jan 2005
Location: The South
Posts: 14,383
Default Re: Firefox users: Beware of Gmail XSS Attack

It still is, Nick. People are constantly looking for chinks in everything's armor. the good part is that it is known and there is a way to address it until it is officially sealed.

Javascript can do some amazing stuff, but it can also be used maliciously as we have seen here.
__________________
-Das Banhammer-



DFI LanParty UT nF4 SLI-D - AMD Athlon X2 4200+ w/ Zalman CNPS9500
2GB (2x1 GB) G.SKILL ZS Razer Lachesis - ATI 3850 w/Accelero S1

Use OpenDNS
Trotter is online now   Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firefox 2.0.0.9 is out Osiris Windows Operating Systems and Software 4 11-02-2007 11:33 AM
Mozilla Firefox May Disclose Files or Information to Remote Users Osiris Virus - Spyware Protection / Detection 2 10-20-2007 04:03 PM
Unholy trinity of flaws put Google users at risk Osiris Virus - Spyware Protection / Detection 1 09-25-2007 01:38 PM
Some Cool Firefox Tricks That Might Make You Crazy .. mantoadmire Browser & General Internet Questions 0 07-25-2007 06:44 AM
Firefox 2.0 users brrymnvette Computer Networking & Internet Access 9 06-07-2007 02:46 PM


All times are GMT -5. The time now is 09:44 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0