ADVERTISEMENTS

According to reports, Mozilla Firefox 2 and Microsoft Internet Explorer 7 (IE) are both vulnerable to a bug that steals the login-id and password of users, with the help of a fake log-in page. The bug has been dubbed as "Reverse Cross Site Request vulnerability" (RCSR) by Robert Chapin, who first discovered the flaw.

Reportedly, the attack was first carried out from a profile page using a specially crafted HTML that hides the genuine MySpace content from the page, and displays the fake login page instead. The fake page is then sent to another Web site, along with information regarding MySpace users who visited the page using Firefox.

The attacks seen on My Space.com are likely to move on to Firefox as well because the Firefox Password Manager automatically enters any saved passwords and user-id/s into the form, whereas IE is not capable of filling in the saved information automatically. Therefore, Firefox is more likely to get affected by the flaw, as compared to IE.

According to Chapin, users of both Firefox and IE need to be aware that their information can be stolen in this way when visiting blog and forum Web sites at trusted addresses as well. Further, an RCSR attack is more likely to succeed than an XSS attack because neither IE nor Firefox are designed to check the destination of form data before the user submits them. Moreover, the browser doesn't indicate the exploitation as it is conducted on a trusted Web site. As of now, no fix has been issued by Mozilla, and it's not very clear if the other versions of Firefox are also affected by the flaw. Users have been advised to disable the "Remember passwords for sites" from the preference link in Firefox. Additionally, these attacks could also be highly effective against firewall of local network servers and HTTPS addresses that are not otherwise accessible because the attacker does not need direct access.

To prevent this: Install Netcraft toolbar, coz it has a better anti-phishing functionality.

No related posts.

Tweet This Tweet This Post!
Subscribe to comments Comment | Trackback |

Browse Timeline



Want to share this post? Give me a Linkback!

If you found this page useful, consider linking to it.
Simply copy and paste the code below into your web site (Ctrl+C to copy)
It will look like this: IE 7 Less Vulnerable than Firefox 2?

Comments ( 1 Comment )

testing

json added these pithy words on Nov 25 06 at 11:49 am

Add a Comment

You must be logged in to post a comment.


© Copyright 2012 jsonvLOG . Thanks for visiting! Obama
40 queries. 0.618 seconds