Go Back   CPS Forums > General Discussion > News

» Online Users: 3
0 members and 3 guests
Members: No Members online
Online: Most users ever online was 98, 27-06-2010 at 07:04.
» Stats
Members: 222
Threads: 6,380
Posts: 24,519
Top Poster: Top Poster: Dai_Nasty (3,936)
Newest Member: Welcome to our newest member, hooligan
 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1 (permalink)  
Old 24-11-2006
Private Parts's Avatar
Senior Admin
 
Profile: Private Parts is offline
: 7 Hours Ago 22:43
Join Date: Jan 2004
Age: 34
Posts: 2,508
Rep Power:
Private Parts has disabled reputation
Send a message via MSN to Private Parts Send a message via Skype™ to Private Parts
IE and Firefox blighted by fake login flaw

Source: The Register The latest versions of both Firefox and Internet Explorer are vulnerable to an unpatched flaw that allows hackers to snaffle users' login credentials via automated phishing attacks.

The information disclosure bug affects the password manager in Firefox 2.0 and its equivalent in IE7. Firefox's Password Manager, for example, fails to properly check URLs before filling in saved user credentials into web forms. As a result, hackers might be able to swipe users credentials via malicious forms in the same domain, providing users have already filled out forms on this domain.

Samples of attacks utilising the flaw have already been reported on MySpace. Firefox 2.0 users might be more at risk from the flaw because IE7 does not automatically fill in saved information. Security notification firm Secunia advises users to disable the "remember passwords for sites" option in their browsers pending the delivery of patches.
This so-called reverse cross-site request flaw was discovered by security researcher Robert Chapin, who explains the issue in greater depth in an advisory here.



Reply With Quote
 

Bookmarks

Tags
blighted, fake, firefox, flaw, login


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Facebook fixes embarrassing flaw gothic BBC Technology News 0 06-05-2010 04:36
Serious security flaw found in IE gothic News 1 16-12-2008 22:19
Internet flaw Vostrikov News 3 10-07-2008 08:40
No fix yet for zero-day flaw in Word gothic News 0 08-12-2006 05:05
Servers and Login smokinggussie The Spearhead Server 1 30-04-2006 23:14


© 2002 - 2010 Fairfield Designs

All times are GMT +1. The time now is 06:08.

Home | Forums | Archive | Contact Us | Top-Of-Page
Powered by vBadvanced CMPS v3.2.1
Who links to my website?