ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Firefox phishing vulnerability discovered

Ingrid Marson ZDNet.co.uk

Published: 05 Jan 2005 15:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A vulnerability in Firefox could make users of the open source browser more likely to fall for phishing scams.

The flaw in Mozilla Firefox 1.0, details of which were published by Secunia on Tuesday, allows malicious hackers to spoof the URL in the download dialog box which pops up when a Firefox user tries to download an item from a Web site. This flaw is caused by the dialog box incorrectly displaying long sub-domains and paths, which can be exploited to conceal the actual source of the download.

Mikko Hyppönen, director of antivirus research at F-Secure, said this bug could make Firefox users vulnerable to cybercriminals. "The most likely way we could see this exploited would be in phishing scams," said Hyppönen.

To fall victim to such a scam, a Firefox user would have to click on a link in an email that pointed to a spoofed Web site and then download malware from the site, which would appear to be downloaded from a legitimate site.

This flaw was given a severity rating of two out of a possible five by Secunia.

David Emm, a senior technology consultant at antivirus company Kaspersky Labs, said it is unlikely that phishers will take advantage of this exploit in Firefox because Microsoft's Internet Explorer still dominates the browser market.

"I think it's unlikely that we'll see hackers rush to exploit this vulnerability," said Emm. "After all, Firefox has a much, much smaller install base than IE and it's likely that hackers will continue to pay more attention to [IE] instead."

This may change in the future as Firefox has attracted a lot of interest in the past few months. A survey at the end of November found that Mozilla-based browsers, including Firefox, accounted for 7.4 percent of browsers in November 2004, up 5 percent from May.

The download vulnerability has been confirmed in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. No solution is available at present, but Mozilla developers plan to fix this bug in an upcoming version of the product.

The Secunia advisory and Mozilla bug report are available online.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
101 out of 166 people found this useful


Full Talkback thread

26 comments

  1. A security vulnerability..??? this is a ridicul... Pete Molina
  2. This article by Ingrid Marson and the opinion... Abe
  3. Ooooh.. I'm frightened!! I guess I'll switch... Ossama Khayat
  4. All I Have To Say Is Firefox Is The Best... Jason
  5. I agree, Pete, that the vulnerability in Fire... Graeme Wearden
  6. Firefox without a doubt, is the best and... Webx
  7. USE FIREFOX ITS MILES AND MILES AHE... robd
  8. Microsoft is waiting for one person to be caught i... The Way
  9. Big deal! This is only one problem compared to the... Anonymous
  10. If this vulnerability had been identified in IE, t... Anonymous
  11. Ouch! 'Users are smart enough to choose their... philbert
  12. Lets face it, not everyone out there is a Web... B B
  13. I think it's important to put things in conte... Anonymous
  14. The simple solution is often the best,JU... Voodoodoctor
  15. There is no reason to believe that Firefox is actu... Anonymous
  16. Critical mass FUD is the typical reaction of... Arthur B.
  17. Firefox will always be more secure than Inter... john_t
  18. It doesn't matter at all if only a couple of... Sebastián Benítez
  19. Ok, had a quick read of some of these replies... fieldyweb
  20. I have to reply to the above comment, be... Webx
  21. can't believe it! But where's the PoC? :) Anonymous
  22. Firefox is undoubtedly a better and more secu... Seb
  23. I've used Firefox since the Phoenix days. Noone e... Killian
  24. I use both Firefox and IE, and while IE is pl... Camper
  25. Ok so there is a flaw. So what? How many flaws h... Simon Buckner
  26. Nice to see an area in IT where Microsoft doesn't... Bill

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

C# ASP.NET Developer Required URGENTLY!!!!!!

Are you an experienced developer using C# ASP.NET? Have you completed numerous contracts in web site development using these technologies? If so, ...

Fidessa Bluebox Algorithmic Fidessa Bluebox Developer

Key words: Fidessa, Bluebox, Blue Box, Java Fidessa Bluebox A Fidessa Bluebox developer is required by my Investment Banking client in London for a ...

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment