This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

DoS exploit for Firefox 1.5 released

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://www.securityfocus.com/brief/73
2005-12-07
"An exploit for the new Firefox 1.5 browser was released today that causes a denial of service condition using a simple web page as a trigger. The heart of the problem lies with the history.dat file that Firefox creates… The exploit creates a very large entry which Firefox then saves into the history.dat file. This causes the browser to crash the next time it is opened, and each time after that until the history.dat file is deleted from the system. The author of the exploit points out that average users may have difficulty figuring out this fix, preventing browser use and effectively creating a denial of service condition. In the past there have been debates over browser bugs and if they are truly denial of service attacks - today’s bug is sure to rekindle these arguments…"

:ph34r:
FYI…

- http://isc.sans.org/diary.php?storyid=920
Last Updated: 2005-12-08 02:24:41 UTC
"…Packetstorm Security has released proof of concept code that causes a buffer overflow and denial of service on the Firefox browser. Long and short of it is, history.dat stores various pieces of information on websites you've visited. If the topic of a page is crafted to be long enough, it will crash the browser each time it is started after going to such a page. This vulnerability has been tested and does work, and no known patches are available at this time. Once this happens, firefox will be unable to be started until you erase the history.dat file manually. Presumably, if the topic was more tightly crafted than in the proof-of-concept code, a more malicious attack could be crafted that would install malware on the machine with the extra fun step of being reinstalled after each restart of firefox (unless you erase history.dat). As we research this more, details will be added on to this post…
POSSIBLE WORKAROUND
However, the following is a workaround that should work…
Go to Tools -> Options.
Select the Privacy Icon, and then the History tab. Set the number of days to save pages at 0. This will disable writing anything to history.dat as far as I can tell, and should nullify the exploit.
HOW TO LOCATE THE PROFILE FOLDER
If you need to delete your history.dat file (in case you tested this PoC code), it can be difficult to locate where exactly this file is. You can find instructions for locating the profile folder at the following URL:
- http://www.mozilla.org/support/firefox/edit#profile …"

.
FYI…

- http://isc.sans.org/diary.php?compare=1&storyid;=920
Last Updated: 2005-12-09 15:33:49 UTC
"Update 2: The official response from the folks at mozilla.org can be found here*. Their results match our testing, that we were able to make it take a long time for Firefox to start, but were not able to make it crash. Further, there doesn't seem to be any credible evidence at this time that this could be exploited to execute arbitrary code."

* http://www.mozilla.org/security/history-title.html

:scratch:
FYI…(per http://isc.sans.org/diary.php?storyid=920 - the "NoScript extension" workaround choice):

- http://www.noscript.net/whats
"1.1.3.5 is out!
Main good news:
* NoScript already protects users against this Firefox DOS exploit. However, it would be theoretically possible to exploit bug 319004 from the server side (no JavaScript). Hence the new NoScript "Truncate title" option (enabled by default) is a quick and dirty additional protection which will work even on whitelisted sites…"
- http://www.noscript.net/changelog

Get it!:
- https://addons.mozilla.org/extensions/moreinfo.php?id=722

.
Or not…

Firefox History Information Denial of Service Weakness
- http://secunia.com/advisories/17934/
Last Update: 2005-12-09
Critical: Not critical …

- http://stuff.techwhack.com/archives/2005/1…law-in-firefox/
10 Dec 2005
"…patch is expected to be released early next year and the users of the Mozilla Firefox 1.5 browsers would get it through the integrated auto-update mechanism. The patch would be included in the next regularly scheduled stability build of Firefox. This means that the next updated version is expected to arrive by late January or early February…"

:wtf: