Infesting you with Virus News
 

News

Contributed by: Lauren Gerber
Date: July 28, 2009
Lauren Gerber
2
Vote
0

Don't Let Your Firefox Browser Get Spoofed

 

How many browsers have you used in your lifetime? Have you experienced a few different browsers or have you remained loyal to one? As the saying goes, "better the devil you know than the devil you don't", this can be applied to Internet browsers as well. The saying could be changed to "rather the browser that you know than the browser you don't". Some people have simply remained with the one browser that makes them feel comfortable. For many people that browser is none other than the Mozilla Firefox browser. I am here to tell you that a new vulnerability has been reported in the Mozilla Firefox browser.25Firefox.jpg

Let me give you some more information with regard to this Firefox issue. Basically the unfortunate news is that with the use of a vulnerable Mozilla browser malicious attackers will be able to perform URL spoofing attacks. With regard to URL Spoofing the dangers are extremely high due to the factor that all a malicious individual really needs to do is make one website look exactly like another. The victim that is visiting the URL is not going to know the difference, but the reality of the situation is that the provided information will go to an entirely different location to where the victim thinks it is going. A good example of this could be that a victim goes to their bank site to do an online transfer and although it appears identical to their normal bank site, it is actually a site which has been set up by a malicious online attacker in order to steal the victims banking information.

If a malicious online attacker wishes to take advantage of this Mozilla Firefox vulnerability then he may do so fairly easily. An online attacker could insert certain arbitrary content in order to spoof the URL which has been delivered to an innocent victim, whose computer knowledge may be limited. It would be ideal for the attacker if the victim's computer knowledge is limited but his/her bank balance is quite the opposite, which is limitless. Victims are often tricked into trusting such sites, as they look legitimate but in reality they are fake.

It was not very long ago at all, in fact it was fairly recently that the new 3.0.12 Mozilla Firefox version was released. One of the reasons why this update came into existence was in order to fix a combination of vulnerabilities that were present in the Mozilla Fire 3.0 version. Some of the files of Mozilla Firefox 2 may include the following: channel-prefs.js, FeedConverter.js, inspector-cmdline.js, nsURLFormatter.js as well as Fox.jpgWebContentConverter.js. One of the files of Mozilla Firefox 3 are: firefox.exe.

You may be wondering which versions this Page Address Bar URL Spoofing vulnerability affects. This vulnerability affects Mozilla Firefox version 3.0.11. It is in every users best interest to know that is it possible for other versions to also be affected. In order for a malicious online attacker to exploit this issue successfully, the attacker needs to trick an ignorant user into viewing a manipulated web document. All in all it is better to be aware than to be unaware. I would like to quote in conclusion:"All they need to do is to set up some website somewhere selling some bogus product at twenty percent of the normal market prices and people are going to be tricked into providing their credit card numbers."-Kevin Mitnick

User Comments

Kolia July 30, 2009
not so tricky when the user has low security settings
tttt July 29, 2009
I think this is the most deceptive understanding of the vulnerability I've read today. You first must visit the malicious site, which creates a new tab or window that hosts the spoofed url. Much different than you viewing a site and immediately getting the url spoofed. The person already has to trust the initial page before they trust the child page it creates. Plus, it's only writable by appending information to it from the parent, so it's all client-side information. This would be a tricky phish to pull off.
Name:
Email:
Website:
Comment:
Please type 5-digit security code below:
Captcha image for spam protection

Software Downloads

Free Spyhunter Scanner (Spyware/Trojan Detection). DETECT Spyware, Trojans, Worms, Viruses and malware on your PC absolutely FREE.
Award Winning software, Fixes registry and improves computer performance. Created by a division of Symantec, this tool will scan your registry and find errors that can be later cleaned either individually or all together.
The tool is used to prevent the installation of spyware and other potentially unwanted software. As soon as you download it, you will be able to protect your system.

Latest Comments

March 17, 2010
March 17, 2010
Found this list of godaddy domain name coupons, I got a domain for my dog - ha $6.91 Domain... more..
March 17, 2010
Three guys were having a beer in a bar in London. They were all relative newly-weds and they were talking... more..
more comments..
rss
Home > Computer Security > Don't Let Your Firefox Browser Get Spoofed