firefox
China's Green Dam and the cyberwar implications
- adobe flash player
- amazon
- arbitrary code execution
- asymmetric warfare
- botnets
- browser crash
- business centers
- ceo
- cisco systems
- cisco systems inc
- commerce industry
- communications capability
- computer security analyst
- computer security experts
- computer specialists
- consumers act
- crime lords
- critical patch
- critical patch
- cyber criminals
- cyberattacks
- demand estimate
- double whammy
- electronic information
- erin andrews
- espn sportscaster
- etisalat
- far cry
- favorite pastimes
- firefox
- firefox browser
- flash software
- foreign ministry
- foundries
- green dam
- insecure version
- korean websites
- linux security
- malicious attackers
- malicious hacker
- messenger users
- metrics
- microsoft office users
- mind control
- modern computing
- netbooks
- north korea
- novell inc
- ones and zeros
- oracle corp
- packet analysis
- pc users
- pc world
- perfect security
- podcast
- private browsing
- richi jennings
- rim blackberry
- said ding
- security business
- security response team
- security response team
- security rules
- security vulnerabilities
- seoul
- seoul officials
- sexy view
- software giant
- software inspector
- south korea
- southern hemisphere
- spam message
- spam messages
- spy software
- swine flu pandemic
- tailspin
- telecommunications company
- united arab emirates
- yxes
Guest editorial by Oliver DayChinese military leaders have always been aware of the military advantage the US has over the People’s Liberation Army. Reading through their published assessments of Sino-US war possibilities confirm our belief that we would dominate them in the air, land and sea. However the PLA was born of asymmetric warfare and [...]
Firefox __defineGetter__ Issues.
I have high hopes for this research done by Gareth Heyes. It looks pretty bad what happens here. It is allowed to spoof different types of window attributes or objects, but also to abuse them cause interesting behaviorism in Firefox. Gareth showed me more, and I think this is going to turn out pretty bad, because it implies that you override almost anything that was set. But, Gareth also told me that he wasn't able to overwrite the document.location object. if that was the issue we could break the same origin policy and that would be one of the biggest vulnerabilities in Firefox so far. read more »
FireFramed.
Yet another nice feature, I only got it working in Firefox. Internet Explorer works also, but only local and not remote. See code below or visit the link to try it out. It might crash Firefox, but that isn't a surprise. Firefox is the crash king.
The Haunted Browser.
FireFox: What a haunted browser it is!Gareth and I, chatted a bit about the Javascript console in FireFox. I knew it can pop up in the strangest places. So we thought: how about popping it up on purpose? And of course we tried it out. I constructed a couple of vectors based on our ideas, try 'em out in BrowserFry if you like. Pretty tricky stuff!Happy Halloween!
Frying FireFox Yet Another Preview.
Okay, I made a better video when I was toying with BrowserFry. The previous video was screwed up by Google, so I uploaded it to a file host instead so you can see how easy it is to launch quick browser tests. This example shows all steps to the latest vulnerability in FireFox, found in exactly 3 minutes due to this new software. Imagine *me* or *you* using this tool all day long, Nah... I don't really want do this all day! So, I have to get back to work on some new projects I have, I hope you can use the tool as well, enjoy the movie and see ya soon!
Even More Sidebar Fun!
Okay, so I woke up this morning thinking it's a cold day today, let's dos Firefox again. This ain't unusual, so I did it. However, there is a slight difference with this one. This is a real denial of service, the exploit below manages to add a bookmark and when the bookmark is set and you click it, Firefox will not respond to ANY uri anymore. Even when you restart Firefox it is impossible to go to Google for instance. See the screenshot below. The reasons I call it a real denial of service is because browser vendors always say that a denial of service is persistent. read more »
Location.href Dossing.
It is also possible to dos Firefox with looping in location.href in Firefox. It tries to change the location to Google but before it gets a chance it loops right back. it bypasses the recursion protection for quite some time. If you do no interact with the page it eventually goes to Google, if you click somewhere inside the page, it probably will crash Firefox.
Copy Paste Illusions.
Don't worry this technique is known, but this time I made a couple of examples to illustrate it's behavior. It utilizes the illusion of selected text. When the selected text is copied or dragged into the URL bar it gets executed because Firefox thinks you have the proper rights to do so. The first example does exactly this and tries to install an Firefox XPI. The seconds one tries to access your local file system, this can only be done by dragging it as a bookmark. Well, this seems an exotic attack, but think again: how many times did you drag hyperlinks and text? read more »
Phish The Master Password In Firefox.
I always felt that security cannot be simplified. It stands in the way of usability because it requires alertness and a clear mind. While I was busy with the previous example I thought about Firefox master password. I tested this feature and I saw that it only asked me a simple Javascript prompt to enter it.Well we can copy this stuff fairly easy by making our own prompt. I think the trick is to time when you want to throw it at a surfer. read more »
FireMaster: Recover Firefox Master Password
When you tell Firefox to remember your user-name and password to a login service, it encrypts the access credentials and stores them in a database file in your profile directory. Yet, anyone can open Firefox’s password manager and view your secure login credentials.In order to keep prying eyes out of your login information, one can [...]




Recent comments
11 weeks 3 days ago
1 year 2 weeks ago
1 year 3 weeks ago
1 year 5 weeks ago
1 year 5 weeks ago
1 year 5 weeks ago
1 year 5 weeks ago
1 year 11 weeks ago
1 year 19 weeks ago
1 year 21 weeks ago