Server Help Forum Index Server Help
Community forums for Subgame, ASSS, and bots
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   StatisticsStatistics   RegisterRegister 
 ProfileProfile   Login to check your private messagesLogin to check your private messages   LoginLogin (SSL) 

Server Help | ASSS Wiki (0) | Shanky.com
IE and Firefox blighted by fake login flaw

 
Post new topic   Reply to topic Printable version
 View previous topic  TT bug Post :: Post Idiots arguing over post counts and av...  View next topic  
Author Message
K'
You can win any war if you start a year early


Gender:Gender:Male
Joined: Jul 13 2006
Posts: 271
Location: Southtown
Offline

PostPosted: Thu Nov 23, 2006 12:12 pm   Post maybe stupid    Post subject: IE and Firefox blighted by fake login flaw Reply to topic Reply with quote

Source.

Quote:

MyPhish.com
By John Leyden ג†’ More by this authorPublished Thursday 23rd November 2006 14:02ֲ GMTGet The Register's new weekly newsletter for senior IT managers delivered to your inbox, click here. The latest versions of both Firefox and Internet Explorer are vulnerable to an unpatched flaw that allows hackers to snaffle users' login credentials via automated phishing attacks.

The information disclosure bug affects the password manager in Firefox 2.0 and its equivalent in IE7. Firefox's Password Manager, for example, fails to properly check URLs before filling in saved user credentials into web forms. As a result, hackers might be able to swipe users credentials via malicious forms in the same domain, providing users have already filled out forms on this domain.

Samples of attacks utilising the flaw have already been reported on MySpace. Firefox 2.0 users might be more at risk from the flaw because IE7 does not automatically fill in saved information. Security notification firm Secunia advises users to disable the "remember passwords for sites" option in their browsers pending the delivery of patches.

This so-called reverse cross-site request flaw was discovered by security researcher Robert Chapin, who explains the issue in greater depth in an advisory here. ®
Back to top
View users profile Send private message Add User to Ignore List
Maverick
broken record


Age:40
Gender:Gender:Male
Joined: Feb 26 2005
Posts: 1521
Location: The Netherlands
Offline

PostPosted: Thu Nov 23, 2006 4:11 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

ouch that sucks icon_confused.gif
I'm using FF's password manager icon_mad.gif
_________________
Nickname: Maverick (I changed my name!)
TWCore developer | Subspace statistics
Back to top
View users profile Send private message Add User to Ignore List Visit posters website
Quan Chi2
Member of "Sexy Teenagers that Code" Group
Member of


Age:34
Gender:Gender:Male
Joined: Mar 25 2005
Posts: 860
Location: NYC
Offline

PostPosted: Sat Nov 25, 2006 6:21 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Oh my god that's awesome. Nice find.
Back to top
View users profile Send private message Add User to Ignore List Send email Visit posters website AIM Address Yahoo Messenger MSN Messenger
daresay
Newbie


Joined: Nov 24 2006
Posts: 8
Offline

PostPosted: Sun Nov 26, 2006 3:34 am   Post maybe stupid    Post subject: Reply to topic Reply with quote

Anything that fucks with myspace emokids is okay in my book.
Back to top
View users profile Send private message Add User to Ignore List
Animate Dreams
Gotta buy them all!
(Consumer whore)


Age:37
Gender:Gender:Male
Joined: May 01 2004
Posts: 821
Location: Middle Tennessee
Offline

PostPosted: Sun Nov 26, 2006 11:53 pm   Post maybe stupid    Post subject: Reply to topic Reply with quote

Hmm.
I have a list of about 400 Myspace passwords from this VERY same exploit.
Not my own endeavors, but I have the list anyway.
Back to top
View users profile Send private message Add User to Ignore List Send email Visit posters website AIM Address MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic    Server Help Forum Index -> Trash Talk All times are GMT - 5 Hours
Page 1 of 1

 
Jump to:  
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum
View online users | View Statistics | View Ignored List


Software by php BB © php BB Group
Server Load: 131 page(s) served in previous 5 minutes.

phpBB Created this page in 0.644775 seconds : 29 queries executed (83.0%): GZIP compression disabled