Re: [Full-Disclosure] Is Mozilla's "patch" enough?

From: Barry Fitzgerald (bkfsec_at_sdf.lonestar.org)
Date: 07/12/04

  • Next message: Andrew Poodle: "RE: [Full-Disclosure] Firefox 0.92 DoS via TinyBMP"
    To: Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
    Date: Mon, 12 Jul 2004 11:20:23 -0400
    
    

    Pavel Kankovsky wrote:

    >
    >The user has already lost. Game over.
    >
    >An attacker can exploit the ability to modify the user's configuration in
    >many different ways. E.g. redirect the browser to a proxy under the
    >attacker's control, make Mozilla use a trojanized Chrome or a trojanized
    >Java plugin, etc.
    >
    >
    >

    My thought about this is that if someone can gain access to the system
    in order to change the contents of prefs.js, then why would they want to
    be able to run even more code via shell: ?

    At that point they already have the ability to run code on the box
    because they have to be able to do that to modify the config files.

    And yes, I firmly believe that whitelisting the "safe" protocols is
    better than maintaining a blacklist.

              -Barry

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Andrew Poodle: "RE: [Full-Disclosure] Firefox 0.92 DoS via TinyBMP"

    Relevant Pages

    • RE: Share AppSettings configuration between a service Web and an asp.net web application
      ... the IIS root site and modify the AppSettings section in it, ... Here is a test function which open & modify web.config file in IIS site ... Microsoft MSDN Online Support Lead ... Share AppSettings configuration between a service Web and an ...
      (microsoft.public.dotnet.framework.aspnet)
    • Client Lockdown
      ... I was hoping that someone could shed some light on a configuration issue I am ... Deny their ability to install their own programs ... I purchased the SBS Premium to get the ISA server 2000. ...
      (microsoft.public.windows.server.sbs)
    • RE: IE: cant change home page from MSN.com
      ... On the System configuration window click on StartUp Tab and uncheck the ... Click on it and select Modify and in the Data: http://www.bbc.co.uk for Ex ... click Ok and Exit the Registry Editor change the home page on the IE ... Properties also and Reboot and see if the issue resolved. ...
      (microsoft.public.windowsxp.general)
    • Re: Automatic Memory Sizing - CEPC/CE 4.2
      ... Since you already have built images for 256 and 128 MB configuration, ... believe you do know how to modify the OEMAddressTable. ... For memory Auto Sizing, the codes are already available in i486 CSP codes. ...
      (microsoft.public.windowsce.platbuilder)
    • Re: Using any network interface whatsoever (solution?)
      ... have to duplicate or modify your ifconfig lines in /etc/rc.conf, ... device name to the slot number, you can swap different ... It wouldn't be too difficult to extend the configuration to allow entries like this: ... address the sole interface in a system without knowing it's name in ...
      (freebsd-hackers)