Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM
Web

Another Firefox URL handler bug revealed; researcher says more on the way

  • Email a Friend
  • Print Page
Another Firefox URL handler bug revealed; researcher says more on the way
By Frank Washkuch
Jul 27, 2007 10:05 AM
Tags: Another | Firefox | URL | handler | bug | revealed; | researcher | says | more | on | the | way
The latest flaw affects users browsing with IE7, said Rios during a post on his blog, warning that other browsers have similar issues.

"It’s time to take a good look at the registered URL handlers and how browsers interact with those registered URL handlers," he said.

"Developers who intend to [or have already] registered URLs for their applications must understand that registering a URL handler exponentially increases the attack surface for that application. Please review your registered URL handling mechanisms and audit the functionality called by those URLs."

On Monday, Mozilla Chief Something-or-Other Window Snyder said on the Mozilla Security Blog that a protocol handing issue exists in Firefox as well as IE. Mozilla had previously blamed the problem on Microsoft, urging the Redmond, Wash.-based company to release a fix for the problem.

The flaw, which can be exploited when IE refers a malicious URL to Firefox, was patched by Mozilla on 17 July when Mozilla released Firefox 2.0.0.5.

Snyder said today on Mozilla’s security blog that the company is investigating the issue. She said the flaw’s impact "appears to be unknown at this time," and advised caution when browsing unknown sites until the Mountain View, Calif.-based company releases a patch.

Rios revealed a list of 13 flaws that he and Mcfeeters have discovered over the past month, telling SCMagazine.com  that "these URL handling flaws are really rampant."

"You’ll see that it affects a wide range of products including Internet Explorer, Firefox, Mozilla, Netscape Navigator and Trillian.

We still have a few vulnerabilities that we have discovered, but haven’t disclosed yet," he said. "As security researchers begin to understand the dangers of URL handlers, we’ll start to see even more of these types of flaws."

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers