My Photo
Name:
Location: Blue Ridge, Va., United States

Wednesday, November 22, 2006

Password vulnerability in Firefox 2

The vulnerability is caused due to the Password Manager not properly checking the URL before automatically filling in saved user credentials into forms. This may be exploited to steal user credentials via malicious forms in the same domain.

According to security company Netcraft, which discovered the exploit being used on MySpace, a fraudulent login page was hosted on the company's own servers.

Solution:

Disable the "Remember passwords for sites" option in the preferences.

http://news.com.com/2100-1002_3-6137844.html?part=rss&tag=2547-1_3-0-20&subj=news

http://secunia.com/advisories/23046/

0 Comments:

Post a Comment

<< Home