Password vulnerability in Firefox 2
The vulnerability is caused due to the Password Manager not properly checking the URL before automatically filling in saved user credentials into forms. This may be exploited to steal user credentials via malicious forms in the same domain.
According to security company Netcraft, which discovered the exploit being used on MySpace, a fraudulent login page was hosted on the company's own servers.
Solution:
Disable the "Remember passwords for sites" option in the preferences.
http://news.com.com/2100-1002_3-6137844.html?part=rss&tag=2547-1_3-0-20&subj=news
http://secunia.com/advisories/23046/
According to security company Netcraft, which discovered the exploit being used on MySpace, a fraudulent login page was hosted on the company's own servers.
Solution:
Disable the "Remember passwords for sites" option in the preferences.
http://news.com.com/2100-1002_3-6137844.html?part=rss&tag=2547-1_3-0-20&subj=news
http://secunia.com/advisories/23046/
0 Comments:
Post a Comment
<< Home