Filed Under (Internet, Software, security) by Telix on January-24-2008

Mozilla researchers has confirmed a proof of concept information leak flaw in Firefox–even fully patched versions. Firefox leaks information that can allow an attacker to load any javascript file on a machine. A visited attacking page is able to load images, scripts, or stylesheets from known locations on the disk. Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed. Some extensions, such as Download Statusbar and Greasemonkey may store information in Javascript files and an attacker may be able to retrieve them.





Comments

[…] (Internet, Software, security) by Telix on January-31-2008 After researcher Gerry Eisenhaur reported about Firefox flaw about information leaks that can allow an attacker to load any javascript file […]

Post a comment
Name: 
Email: 
URL: 
Comments: