RE: [Full-Disclosure] Firespoofing [Firefox 1.0]
From: Soderland, Craig (craig.soderland_at_sap.com)
Date: Tue, 11 Jan 2005 15:37:20 +0100 To: "mikx" <firstname.lastname@example.org>, <email@example.com>, <firstname.lastname@example.org>, <NTBUGTRAQ@listserv.ntbugtraq.com>
This does not work if you are using the FireFox 1.0 tabbed browsing
feature, as your pop up window simply opens a new tab, and it then
becomes immediately obvious what you are trying to pull off here.
> -----Original Message-----
> From: email@example.com
> Sent: Monday, January 10, 2005 6:22 PM
> To: firstname.lastname@example.org; email@example.com;
> Subject: [Full-Disclosure] Firespoofing [Firefox 1.0]
> download dialogs by partly covering them with a popup window. This can
> a user to download and automaticly execute a file (if a file extension
> association exists) or to grant a script local data access (if
> principals are enabled).
> __Expected Behavior
> Modal dialogs should always be on top and it should not be possible to
> obfuscate their appearance.
> The PoC is designed for Firefox 1.0 running in a maximized window.
> Part 1 - download dialog spoofing
> Shows how to cover a download dialog and fool the user to execute a
> with a standard windows file association (in this case a .ht file).
> remember the latest .ht buffer overflow...
> Part 2 - security dialog spoofing
> Shows how to cover a security dialog. Make sure codebase principals
> enabled (not default but encouraged by many XUL sites). Creates the
> c:\booom.txt to proof local system access.
> The bug is confirmed but currently unfixed (open for more than 3
> a partial workaround set dom.disable_window_flip to true in
> The vendor failed to respond to multiple status requests which led to
> public disclosure.
> 2004-09-20 Vendor informed (bugzilla.mozilla.org #260560)
> 2004-09-20 Vendor confirmed bug
> 2004-10-20 Status request (open for 1 month - no reply)
> 2005-01-03 Status request (open for 3 months - no reply)
> 2005-01-07 Status request (disclosure warning - no reply)
> 2005-01-11 Public disclosure
> __Affected Software
> Tested with Firefox 1.0, Mozilla 1.7.5 and Netscape 7.1 on Windows XP
> __Contact Informations
> Michael Krax <firstname.lastname@example.org>
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
Full-Disclosure - We believe in it.