Hackers dig into Firefox
Date: October 06, 2006Source: software.silicon.com
The open source Firefox web browser is critically flawed in the way it handles JavaScript, two hackers said on Saturday afternoon.
An attacker could commandeer a computer running the browser simply by crafting a web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference in San Diego. The flaw affects Firefox on Windows, Apple's Mac OS X and Linux, they said.
The flaw is specific to Firefox's implementation of JavaScript, a 10-year-old scripting language widely used on the web. In particular, various programming tricks can cause a stack overflow error, Spiegelmock said. The implementation is a "complete mess", he said, adding: "It is impossible to patch."
The JavaScript issue appears to be a real vulnerability, Window Snyder, Mozilla's security chief, said after watching a video of the presentation on Saturday night. "What they are describing might be a variation on an old attack," she said. "We're going to do some investigating."
Snyder said she isn't happy with the disclosure and release of an apparent exploit during the presentation. "It looks like they had enough information in their slide for an attacker to reproduce it," she said. "I think it is unfortunate because it puts users at risk but that seems to be their goal."
Add comment Email to a Friend