This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Firefox Pwd Mgr Info Disclosure - workaround available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/23046/
Release Date: 2006-11-22
Critical: Less critical
Impact: Exposure of sensitive information
Where: From remote
Solution Status: Unpatched
Software: Mozilla Firefox 1.x, Mozilla Firefox 2.x
…This may be exploited to steal user credentials via malicious forms in the same domain.
The vulnerability is confirmed in version 2.0.0. Other versions may also be affected.
Solution: Disable the "Remember passwords for sites" option in the preferences…
Original Advisory: http://www.info-svc.com/news/11-21-2006/
Other References: https://bugzilla.mozilla.org/show_bug.cgi?id=360493 …"

:ph34r:
More…

- http://www.newsfactor.com/story.xhtml?story_id=1200044XT8ZC
November 24, 2006
"…Microsoft has also admitted that RCSR attacks -can- affect Internet Explorer, but most reports indicate that Firefox is the more likely target because of the way it stores user names and passwords. Neither Mozilla nor Microsoft has released a patch for the problem… Mozilla has indicated that it plans a fix in Firefox version 2.0.0.1 or 2.0.0.2…"

EDIT/ADD:
- http://www.sans.org/newsletters/newsbites/…mp;rss=Y#sID306

.
FYI…

- http://www.securityfocus.com/infocus/1883/2
2006-12-11
"…Risk of subversion and compromise to the password storage mechanisms of web browsers such as Internet Explorer and Firefox need further evaluation. Any system that controls the keys to the kingdom or many kingdoms should be further scrutinized. Users need to become more aware of the risks and benefits of using password management systems. Current methods of mitigation such as avoidance, immobilization, alternative storage, and password complexity are only temporary solutions. Users expect security to be transparent, usable, and secure. Thus the next generation of password management systems should take all those considerations into account for design decisions."

:ph34r: