As Israeli security researcher Aviv Raff reports he has found couple Firefox 2 vulnerabilities that can leave its users susceptible to an identity theft attack. A bug allows spoofing and enables an attacker to conduct phishing attacks, by tricking the user to believe that the authentication dialog box is from a trusted website. The versions affected include Firefox v2.0.0.11 and prior versions. Mr Raff suggests avoiding sites that require password authentication and give you a dialog that looks like this one:
Mozilla developing team has been informed about this vulnerability and we’re expecting some patches soon.