1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Frame Injection vuln affects all browsers

Discussion in 'Firefox, Thunderbird & SeaMonkey' started by Antony, 2004/07/05.

Thread Status:
Not open for further replies.
  1. 2004/07/05
    Antony

    Antony Inactive Thread Starter

    Joined:
    2002/01/01
    Messages:
    405
    Likes Received:
    0
    (not sure if this should be posted here.)

    According to Secunia, an old vulnerability was discovered in many modern browsers, allowing malicious people to spoof the content of websites. The affected browsers include Safari, Konqueror, Opera, MSIE, and all Mozilla (Gecko-based) browsers.

    You can test your browser with this detailed instructions.

    > More information: Multiple Browsers Frame Injection Vulnerability
    Internet Explorer Frame Injection Vulnerability

    I do not know if there's any fixes available, however, you can safeguard yourself by checking the Page Info from context menu or View menu and check the child-window (frame)'s actual URL.
     
  2. 2004/07/05
    Hugh Jarss

    Hugh Jarss Inactive

    Joined:
    2002/07/22
    Messages:
    908
    Likes Received:
    6
    Hi Antony

    it's actually in another thread over here but hiding pretty well - try post#39

    as it affects just about all browsers, not Moz/NN specific, perhaps prepare to move!

    thing is, how easy is it to nail the problem?

    with IE, you simply turn off the "Navigate Sub-Frames across domains" option

    if there's a similar way to nobble that "feature" in Netscape/Moz (or indeed any browser whatsoever) it would be highly useful if someone could give clear directions how to do it - regret I cannot answer either how, or indeed whether it can be done for Moz/NN - this computer isn't powerful enough for me to run them

    the ability to put sites into security zones helps a lot

    best wishes, HJ
     

  3. to hide this advert.

  4. 2004/07/05
    Antony

    Antony Inactive Thread Starter

    Joined:
    2002/01/01
    Messages:
    405
    Likes Received:
    0
    Thanks HJ,

    A SillyDog701 user reported Mozilla 1.7 on SuSE Linux is not affected.
    Mozilla Firefox 0.91 and Mozilla 1.7 are not affected.
     
    Last edited: 2004/07/05
  5. 2004/07/05
    GPaDavis

    GPaDavis Inactive

    Joined:
    2002/01/07
    Messages:
    194
    Likes Received:
    0
    Using Mozilla 1.7, WXp Home

    Mozilla 1.7 w/windows Xp home seems not to be vulnerable. At least I couldn't find any "injection ".

    Bob
     
  6. 2004/07/05
    Ramona

    Ramona Geek Member Alumni

    Joined:
    2001/12/31
    Messages:
    7,481
    Likes Received:
    2
    Hi Antony,

    Thanks very much for alerting us to this vulnerability. I find that Netscape 7.1 is indeed vulnerable, however, Mozilla 1.7 passed the test with flying colors, as did Firefox 0.9.1.

    Ramona
     
  7. 2004/07/05
    Westside

    Westside Inactive Alumni

    Joined:
    2003/03/30
    Messages:
    4,506
    Likes Received:
    14
    Everything else I tested is vulnerable, from earlier Netscapes, and Mozilla through 1.6. I was told that even 1.7RC3 is vulnerable.
     
  8. 2004/07/06
    HeyJeff

    HeyJeff Well-Known Member

    Joined:
    2004/03/13
    Messages:
    31
    Likes Received:
    1
    Firefox 0.9.1 passed for me, but Opera 7.51 failed. :eek:
     
  9. 2004/07/06
    Westside

    Westside Inactive Alumni

    Joined:
    2003/03/30
    Messages:
    4,506
    Likes Received:
    14
    I verified this, and you are correct. IE6, and AOL9.0 are no longer vulnerable.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.