Branding_print



Firefox flaw lets in phishers


A security researcher has found a problem in Mozilla's Firefox browser that could allow phishers to gather information such as passwords.


Firefox

A security researcher has found a problem in Mozilla's Firefox browser that could allow phishers to gather information such as passwords from unsuspecting surfers.

Robert Chapin, of Chapin Information Services, discovered a spoofed MySpace page and was disturbed to find that Firefox's Password Manager feature didn't realise that the page was actually in a domain he had not authorised to collect his passwords.

"I was shocked today to find an in-the-wild phish that uses nothing more than cross-site forms, and also extracts information from the Password Manger," said Chapin.

"I would have been thoroughly fooled by this page were it not for a tiny formatting error that the phisher overlooked, and could have been easily fixed. An unsuspecting user would only have to click the Login button on this legitimate-looking page for the phish to be complete," he continued.

The vulnerability is caused by the Password Manager not checking the URL before automatically filling in saved passwords into forms. Chapin sees this as a gaping hole in Firefox's defences.

"I realise there is a consideration for cross-site functionality on certain subdomains. However, I must say I am shocked that FireFox lacks a warning for... the Password Manager in this case," he said.

Danish security company Secunia rates the flaw as 'less critical', and recommends that Firefox users go to Tools, Options, Privacy and uncheck the box marked 'Remember what I enter in forms and the search bar'.

http://secunia.com/
http://www.info-svc.com/

More news via RSS
Post item to Del.icio.us
Post item to Digg.com

Top Stories


Latest consumer technology news and breaking web stories




  • Webfeed
  • Print
  • Share







Search


Latest Issue

227 3D Cover

Issue 227 - 19 November 2009

Web User is the UK's best-selling internet magazine - latest issue on sale from Thursday 19 November 2009!





Compare broadband deals








What do you think?

Take part in our latest poll...

How much online shopping will you be doing this Christmas?

Poll

  • More than last year (33%)
  • Less than last year (21%)
  • About the same (46%)

See all polls..







Search

Search

© Copyright IPC Media Limited 2009, All rights reserved