Quantcast
PC World: Technology Advice You Can Trust
Find a Review
Free Newsletters
Receive the latest reviews, how-to's, news, and more.
Weekly Brief
Daily Downloads
Daily Technology News
WiFi Finder
Locate wireless services by a specific address, city, state, country, airport, or zip code.
RSS Feeds
Get our latest content via convenient RSS feeds.
Latest News
Today @ PC World
Become a PCW Member
Join the community and start enjoying the benefits:
  • Get tech advice from thousands of PC World Members
  • Rate and recommend the latest tech products
  • Share your thoughts in blog and article comments
  • Get free excerpts and exclusive discounts on Super Guides
Read More About: Browser BugsMozilla

Attack Targets Mozilla

Hacker posts code to take control of computers running unpatched versions of Firefox browser.

Robert McMillan, IDG News Service

Tuesday, December 13, 2005 7:00 AM PST
Recommend this story?

Computer users who have not upgraded to the latest version of Mozilla's Firefox browser may now have an extra incentive to do so, thanks to a hacker who has posted an exploit.

Exploit Shown

On Sunday, a hacker going by the name of Aviv Raff published sample code that could be used to take over the computers of Firefox users running version 1.0.4 or earlier of the browser. The exploit takes advantage of a known bug in the way Firefox processes the popular Javascript Web programming language.

"I think it's been enough time for people to upgrade from v1.0.4. of Firefox. So, here is the PoC [proof of concept] exploit for the ... vulnerability," he wrote on his blog.

The bug was fixed in Mozilla version 1.0.5, which was released during the summer, and has also been fixed in version 1.7.9 of the Mozilla Suite, said Mike Schroepfer, vice president of engineering with Mozilla. "As long as users keep updated to the latest version, they're, in general, very safe."

Similar to IE Flaw

In some ways, this latest exploit is similar to highly publicized attack code that has been circulating for the Microsoft Internet Explorer browser, said Russ Cooper, editor of the NTBugtraq newslist and a scientist with security vendor Cybertrust.

"It can install and run code of the attacker's choice if a victim visits a malicious Web site," he said of the IE bug in an interview via instant message.

Users who are not already in the habit of frequently updating their browsers should change their ways, because browsers are "historically broken," Cooper said. "That means they have vulnerabilities regularly," he added. "You should keep them updated within 30 days of patches being made available, regardless of what the patch is for."

The IE code, which was published in November, takes advantage of a Javascript problem that has not yet been patched.

Many security experts expect Microsoft to patch its Javascript bug on Tuesday, but the Redmond, Washington, software giant has not confirmed that this will be the case.


Recommend this story?

Comments
Latest News
The former chairman and CEO of PurchasePro.com, a business-to-business software broker that died during the dot-com bust, has... 16-May-2008
Vodafone is acquiring ZYB, a Danish company that has developed a social networking and online management tool for backing-up... 16-May-2008
The iPhone's reach expanded again Friday, with Orange announcing plans to sell the phone in Europe, the Middle East and... 16-May-2008
A new train simulator codeveloped by Fujitsu offers unparalleled realism thanks to high-definition video shot on actual train... 16-May-2008
Samsung Electronics will unveil this weekend the first prototype of a new LCD (liquid crystal display) technology that won't... 16-May-2008
With all the time spent on the road, most drivers consider their cars to be their second homes. Reaching their primary home... 16-May-2008
Internet users in China have begun expressing solidarity with the victims of Monday's earthquake via their instant messaging... 15-May-2008
Sony has promoted a senior executive at its U.S. games studio to lead its global studios, it said Friday. 15-May-2008
Fujitsu has developed a prototype electronic paper screen that tackles one of the technology's biggest weaknesses: the amount... 15-May-2008
The One Laptop Per Child Project and Microsoft plan to make both Windows and Linux available on a version of the project's XO... 15-May-2008

PC World's Marketplace

PC World's Free Whitepapers

Name City
Address 1 State Zip
Address 2 E-mail (optional)