Blogvaria

This page is brought to you by Blogvaria (http://blog.evaria.com).

To obtain more information, ask questions and interact please visit our website.

Back to Blogvaria landing page
Feedback
Subscribe
   
Blogvaria

 

The personal pages

FF vulnerability exploited via IE

TrackBack | Filed by Thomas under Internet stuff, Software | Post popularity 5%

A vulnerability in Firefox 2 announced this week could allow remote command execution. Only Window versions prior to Vista (XP ->) are affected.

The problem, according to Secunia, is that Firefox registers the “firefoxurl://” URI handler and allows invoking Firefox with arbitrary command line arguments. Using e.g. the “-chrome” parameter it is possible to execute arbitrary JavaScript in chrome context.

This can be exploited to execute arbitrary commands e.g. when a user visits a malicious web site using Microsoft Internet Explorer. The site xs-sniper.com shows examples of how to do this.

The vulnerability was first made known by Thor Larholm. However he believes the problem is related to Internet Explorer as it doesn’t escape the sign when passing data through to the command line.

Solution

Do not browse untrusted sites and disable the “Firefox URL” URI handler OR install the Firefox extension NoScript.

Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages.
  • BlinkList
  • blogmarks
  • del.icio.us
  • De.lirio.us
  • digg
  • Furl
  • NewsVine
  • Netscape
  • Reddit
  • Spurl
  • SphereIt
  • Technorati
  • YahooMyWeb
  • DZone
  • feedmelinks
  • Linkter
  • Ma.gnolia
  • Slashdot
  • StumbleUpon
  • TailRank
  • co.mments

No comments yet.

Leave a Comment

Akismet has protected Blogvaria from 78,976 spam comments. Design by Evaria.com. Powered by WordPress.
Our beloved and trusted server has rendered 383 pages so far today, an amazing 5.952 pages yesterday
and even more astonishingly 162.290 pages since 18 October 2008 alone without dropping a byte nor a pixel.

Close
E-mail It