Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Internet & Networking > Firefox, Thunderbird & SeaMonkey

Firefox, Thunderbird & SeaMonkey Post your questions about Mozilla based products (Firefox, Thunderbird & SeaMonkey) here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Reply
 
LinkBack Thread Tools
Old 12th November 2007   #1
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 807
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


Exclamation Firefox "jar:url" exploit may be triggered via Google XSS vector

Hi

the (currently unpatched) jar:url problem with Firefox can be set off via Google it seems

(at time of posting) Secunia have the exploit as a "less critical": however their workaround is avoid clicking on "jar:url" links
http://secunia.com/advisories/27605/

...so I don't think they've (yet) realised that you can't really "avoid clicking" on these if they get cursed onto you via a Google 302 open redirect

I'm not the world's expert in these matters, so mentioning it here so that someone who knows what they are doing can better gauge the severity of the problem. To my limited comprehension, this looks potentially rather nasty (sneaky, easy to work, comes at you out of the blue, poc is out, Google has plenty of 302's, Google's just one example...)

refs:
http://isc.sans.org/diary.html
http://www.gnucitizen.org/blog/sever...rotocol-issues
http://www.gnucitizen.org/blog/web-m...rotocol-issues

(perhaps this should have gone to "general security" but FF appears to be the only browser affected)

best wishes, HJ


Last edited by Hugh Jarss; 12th November 2007 at 01:51. Reason: clarity
Hugh Jarss is offline   Reply With Quote
Didn't find the information you thought to find?
Check out these Similar Threads
Old 12th November 2007   #2
Geek Member
 
Profile:
Join Date: Jul 2002
Location: Peterborough, UK
Posts: 807
Computer Experience:
SC/MP
Hugh Jarss Reputation Level


a comment to SANS suggests the "noscript" firefox add-on, which can act against this type of attack - I've just installed it

stay safe & best wishes, HJ

==

**edit**
pls use the link below for the SANS article, rather than the one given in post #1 (unfortunately the time to edit that post has expired)

...using the link below will take you to the correct diary (rather than to "today's" diary):
http://isc.sans.org/diary.html?date=2007-11-11

BTW, that "noscript" add-on is truly wonderful


Last edited by Hugh Jarss; 13th November 2007 at 03:51. Reason: because I couldn't fix the SANS link date on post#1
Hugh Jarss is offline   Reply With Quote
Old 24th November 2007   #3
Staff
 
Ramona's Avatar
 
Profile:
Join Date: Dec 2001
Location: Missouri
Posts: 7,445
Computer Experience:
Experienced Learner
Ramona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation LevelRamona Reputation Level

My System

Hugh,

Thanks very much for posting this security vulnerability! Following is what the Secunia Advisory stated:

TITLE:
Mozilla Firefox "jar:" Protocol Handling Cross-Site Scripting Security Issue
Quote:
SECUNIA ADVISORY ID:
SA27605

VERIFY ADVISORY:
http://secunia.com/advisories/27605/

CRITICAL:
Less critical

IMPACT:
Cross Site Scripting

WHERE:
>From remote

SOFTWARE:
Mozilla Firefox 2.0.x
http://secunia.com/product/12434/

DESCRIPTION:
A security issue has been reported in Mozilla Firefox, which can be
exploited by malicious people to conduct cross-site scripting
attacks.

The problem is that the "jar:" protocol handler does not validate the
MIME type of the contents of an archive, which are then executed in
the context of the site hosting the archive. This can be exploited to
conduct cross-site scripting attacks on sites that allow a user to
upload certain files (e.g. .zip, .png, .doc, .odt, .txt).

SOLUTION:
Do not follow untrusted "jar:" links or browse untrusted websites.

PROVIDED AND/OR DISCOVERED BY:
Reported by Jesse Ruderman in a Bugzilla entry.

Independently discovered by pdp.

ORIGINAL ADVISORY:
Mozilla:
https://bugzilla.mozilla.org/show_bug.cgi?id=369814

GNUCITIZEN:
http://www.gnucitizen.org/blog/web-m...rotocol-issues

OTHER REFERENCES:
US-CERT VU#715737:
http://www.kb.cert.org/vuls/id/715737

Ramona is offline   Reply With Quote
Old 27th November 2007   #4
SuperGeek
Lifetime Subscription
 
mailman's Avatar
 
Profile:
Join Date: Jan 2004
Posts: 1,730
Computer Experience:
Intermediate Tinkering
mailman Reputation Levelmailman Reputation Level


Apparently this vulnerability and two other vulnerabilities are fixed with v2.0.0.10 released November 26, 2007.

http://www.mozilla.org/projects/secu...irefox2.0.0.10
Quote:
Fixed in Firefox 2.0.0.10
MFSA 2007-39 Referer-spoofing via window.location race condition
MFSA 2007-38 Memory corruption vulnerabilities (rv:1.8.1.10)
MFSA 2007-37 jar: URI scheme XSS hazard

mailman is offline   Reply With Quote
Reply

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
Firefox 1.5 and Google aks Firefox, Thunderbird & SeaMonkey 3 9th February 2006 06:16
Google Toolbar (beta) for Firefox Antony Firefox, Thunderbird & SeaMonkey 4 14th July 2005 16:16
Firefox and Thunderbird Upgrading FAQ's Ramona Firefox, Thunderbird & SeaMonkey 0 9th March 2005 01:32
Google and Firefox -- A Class act Dennis L Firefox, Thunderbird & SeaMonkey 1 3rd February 2005 19:42
Searchfast - Malware Geri Malware and Virus Removal 13 5th November 2004 02:35


All times are GMT +1. The time now is 04:03.






Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Copyright © 2002 - 2008 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]