[Full-Disclosure] Re: Firescrolling [Firefox 1.0]

From: Stan Bubrouski (stan_at_ccs.neu.edu)
Date: 02/25/05

  • Next message: pingywon: "[Full-Disclosure] More T-Mobile fall out..."
    Date: Fri, 25 Feb 2005 16:33:08 -0500
    To: "Beauford, Jason" <jbeauford@EightInOnePet.com>
    
    

    looked at:
    http://www.mozilla.org/projects/security/known-vulnerabilities.html

    Are you sure its fixed???

    -sb

    Beauford, Jason wrote:
    > That sucked.
    >
    > Fortunately: http://www.mozilla.org/products/firefox/releases/
    >
    > jmb
    >
    > -----Original Message-----
    > From: mikx [mailto:mikx@mikx.de]
    > Sent: Friday, February 25, 2005 3:11 AM
    > To: full-disclosure@lists.netsys.com; bugtraq@securityfocus.com;
    > NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    > Subject: Firescrolling [Firefox 1.0]
    >
    >
    > __Summary
    >
    > Remember my Internet Explorer "scrollbar exploit" based on http-equiv's
    > "What a Drag"? When will people ever learn that "unusual user
    > interaction"
    > can be hidden by common tasks...
    >
    > Let's combine fireflashing, firetabbing, xul and javascript to run
    > arbitrary
    > code by dragging a scrollbar two times.
    >
    > __Proof-of-Concept
    >
    > http://www.mikx.de/firescrolling/
    >
    > __Status
    >
    > The exploit is based on multiple vulnerabilities:
    >
    > bugzilla.mozilla.org #280664 (fireflashing) bugzilla.mozilla.org #280056
    > (firetabbing) bugzilla.mozilla.org #281807 (firescrolling)
    >
    > Upgrade to Firefox 1.0.1 or disable javascript.
    >
    > The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    > assigned the name CAN-2005-0527 to this issue.
    >
    > __Affected Software
    >
    > Tested with Firefox 1.0 on Windows and Linux (Fedora Core)
    >
    > __Contact Informations
    >
    > Michael Krax <mikx@mikx.de>
    > http://www.mikx.de/?p=11
    >
    > mikx
    >
    >
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: pingywon: "[Full-Disclosure] More T-Mobile fall out..."

    Relevant Pages

    • Re: Firescrolling [Firefox 1.0]
      ... > can be hidden by common tasks... ... > The exploit is based on multiple vulnerabilities: ... > Upgrade to Firefox 1.0.1 or disable javascript. ...
      (Bugtraq)
    • Re: Firescrolling [Firefox 1.0]
      ... > can be hidden by common tasks... ... > The exploit is based on multiple vulnerabilities: ... > Upgrade to Firefox 1.0.1 or disable javascript. ...
      (Full-Disclosure)
    • Firescrolling [Firefox 1.0]
      ... Remember my Internet Explorer "scrollbar exploit" based on http-equiv's ... The exploit is based on multiple vulnerabilities: ... The Common Vulnerabilities and Exposures project has ... Tested with Firefox 1.0 on Windows and Linux ...
      (NT-Bugtraq)
    • Firescrolling [Firefox 1.0]
      ... Remember my Internet Explorer "scrollbar exploit" based on http-equiv's ... The exploit is based on multiple vulnerabilities: ... The Common Vulnerabilities and Exposures project has ... Tested with Firefox 1.0 on Windows and Linux ...
      (Bugtraq)
    • [Full-Disclosure] Firescrolling [Firefox 1.0]
      ... Remember my Internet Explorer "scrollbar exploit" based on http-equiv's ... The exploit is based on multiple vulnerabilities: ... The Common Vulnerabilities and Exposures project has ... Tested with Firefox 1.0 on Windows and Linux ...
      (Full-Disclosure)