Contact Us / Feedback

 


INTERNET AND BROWSERS

FireFox javascript flaw claimed to be unfixable, turns out to be a hoax

At ToorCon hacker conference, two hackers claim to have discovered an infixable flaw in Mozilla Firefox; a day later say the entire thing was a hoax.

Two hackers claimed at ToorCon that the open-source web browser Mozilla Firefox is critically flawed in the way it handles JavaScript.An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said. The presentation sent Mozilla Corporation into a panic.

Spiegelmock detailed the Javascript 'flaw', showing a slide that displayed key parts of the attack code needed to exploit it and said that "the implementation is a "complete mess. It is impossible to patch." 

The two hackers claimed that the flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the Web. Javascript flaws have been a particularly nasty headache for Internet Explorer and Microsoft in the past. Various programming exploits cause a stack overflow error and allow a hacker to take control of a computer.

Snyder, chief security at Mozilla, had said she isn't happy with the disclosure and release of an apparent exploit during the presentation. "It looks like they had enough information in their slide for an attacker to reproduce it," she said. "I think it is unfortunate because it puts users at risk, but that seems to be their goal." "If it is in the JavaScript Virtual Machine, it is not going to be a quick fix," Snyder had said said. 

The hackers went on to claim they know of about 30 unpatched Firefox flaws. They said that they did not plan to disclose them, instead holding onto the bugs. 

Initially, security experts were doubtful and said that there was too much hype, and maybe the Forefox javascript flaw is not so easily exploitable. However, a day later, the hackers admitted that they intended the presentation to be humorous, and they have never done the exploit nor do they know about 30 other flaws. Snyder can sleep again!

 

INTERNET AND BROWSERS

Powerset Search Engine: The Google-killer is here! Or is it?
Another natural language search engine plans a launch. Will Powerset be something in the era of Google?

Ride the net with AOL’s OpenRide
AOL's OpenRide brings an interesting new interface to the Web that combines IM, surfing and email.

eBay and Opera team up for mobile transactions

Yahoo and eBay sign agreement to keep Microsoft and Google out

Google maps the entire New Zealand

eBay to merge with Microsoft?

Apple loses suit against bloggers

Wi-Fi network for New Orleans by EarthLink

Dell and Google sign agreement

Anti spam company Blue security accepts defeat

Anonymous browsing with Firefox: Stealther Firefox extension

Mozilla Firefox 2.0 alpha 2 release

 

 

 

 

 
Web This site

 

 
Microsoft Sci-tech Business Music Phones Computers
Internet and browsers Gaming Security Gizmos Vehicles