CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Vulnerabilities: Mozilla and Netscape race condition image
Security Hole
Secunia - Advisory
Reported by Liu Die Yu

Mozilla, Netscape and possibly other browsers derived from Mozilla have been found vulnerable to a race condition, which allows malicious sites to bypass the security zone.

The problem is that Mozilla does not eliminate any active scripts, when a user clicks on a link and a new page is being loaded. This allows the previous site to launch a JavaScript, which is able to steal cookie information from the new site and return it to the previous site.

This has only been confirmed on Microsoft Windows systems (Windows Server 2003, Windows XP Pro and Windows 2000 Professional). Initial tests indicate that Linux systems are not vulnerable.

Specific versions proved vulnerable are Netscape 7.0, Mozilla 1.3 and Mozilla 1.4a.

To test you browser Liu Die Yu has made a live example/exploit - see the "Other References" section.

Solution:
There is no immidiate solution.

We recommend that you do not follow links from untrusted sites to sites that you exchange sensitive information with. Use a different browser window to access trusted sites or simply use another browser.

Reported by / credits:
Liu Die Yu

Original Advisory:
http://liudieyuinchina.vip.sina.com/EdgeLink/EdgeLink-Content.txt

Other References:
Here is an example of how to exploit this:
http://liudieyuinchina.vip.sina.com/EdgeLink/EdgeLink-MyPage.htm
Source of advisory:  Secunia
Posted on Thursday, 17 April 2003 @ 07:46:01 UTC by cj (1253 reads)
[ Trackback ]
image

"Vulnerabilities: Mozilla and Netscape race condition" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register
 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· Linux.com
· Microsoft
· Microsoft
· HotScripts
· W3 Consortium
· Mozilla
· Netscape
· More about Security Hole
· News by cj


Most read story about Security Hole:
Windows Media Player, Spyware and Trojan

block bottom
Article Rating
spacer
Average Score: 0
Votes: 0

Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer