Date: Tue, 03 Aug 2004 08:00:53 -0300 From: "Mark Dodel" Subject: [VOICENWS] SW: Mozilla / Mozilla Firefox User Interface Spoofing Vulnerability From: "Mark Dodel" Just so we are not completely lulled about the lack of exploits on OS/2, I thought I'd pass on this security alert about Mozilla based browsers that I saw on Dr. Jerry Pournelle's web site Since it uses Mozilla's internal programming language this is cross-platform and should effect the OS/2 versions as well.: Dear Dr Pournelle, < http://secunia.com/advisories/12188/ > Here we go again: "*Description*: A vulnerability has been reported in Mozilla and Mozilla Firefox, allowing malicious websites to spoof the user interface. The problem is that Mozilla and Mozilla Firefox don't restrict websites from including arbitrary, remote XUL (XML User Interface Language) files. This can be exploited to "hijack" most of the user interface (including tool bars, SSL certificate dialogs, address bar and more), thereby controlling almost anything the user sees. The Mozilla user interface is built using XUL files. A PoC (Proof of Concept) exploit for Mozilla Firefox has been published. The PoC spoofs a SSL secured PayPal website. This has been confirmed using Mozilla 1.7 for Linux, Mozilla Firefox 0.9.1 for Linux, Mozilla 1.7.1 for Windows and Mozilla Firefox 0.9.2 for Windows. Prior versions may also be affected. NOTE: This issue appears to be the same as Mozilla Bug 244965. [Moderator note: It is actually http://bugzilla.mozilla.org/show_bug.cgi?id=22183 ] *Solution*: Do not follow links from untrusted sites." Regards, TC -- Warpstock 2004, Denver, Colorado, October 21 - 24, 2004 http://www.warpstock.org Warpstock Europe 2004, Arnhem, The Netherlands, November 26-28th, 2004 http://www.warpstock.net [Moderator's note: All posts are sent without guarantee to the accuracy of the content. We try to verify details and URLs but this is an entirely volunteer run list, so 100% fact checking and the quality/useability of products announced here is impossible. If you respond to this post please remove the DESPAM from the poster's email addresses. Please do not send requests for information about a specific post to the moderator unless it is an update or I sent it.] -- To unsubscribe yourself from this list, send the following message to majormajor at os2voice.org unsubscribe news end Or, visit http://www.os2voice.org/MailingLists.html If you have an announcement you would like posted to the VOICE News list, please send it to submit at os2voice.org. Please include a valid reply address and a real contact name. If you wish to comment on this post, please reply to feedback at os2voice.org