| SillyDog701 Forums |
| Author |
Message |
Antony


Joined: 18 Jun 2002 Posts: 11869
|
05 Jul, 2004 3:44 am "Frame Injection" vuln affects all browsers |
[sdp=37377] |
|
According to Secunia , an old vulnerability was discovered in many modern browsers, allowing malicious people to spoof the content of websites. The affected browsers include Safari , Konqueror, Opera, MSIE, and all Mozilla (Gecko-based) browsers.
| Quote: | The problem is that the browsers don't check if a target frame belongs to a website containing a malicious link, which therefore doesn't prevent one browser window from loading content in a named frame in another window. |
You can test your browser with this detailed instructions .
> More information: Multiple Browsers Frame Injection Vulnerability
Internet Explorer Frame Injection Vulnerability
I do not know if there's any fixes available, however, you can safeguard yourself by checking the Page Info from context menu or View menu and check the child-window (frame)'s actual URL.
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.8
|
|
| Back to top |
|
 |
DJGM


Joined: 19 Jun 2002 Posts: 4338 Location: Manchester, England, UK
|
05 Jul, 2004 5:14 am |
[sdp=37379] |
|
I've just tested that vuln using the instructions in Secunia's advisory. The browser I'm using at the
moment (Mozilla 1.7 on SUSE Linux) does not appear to be affected. No content from Secunia
appeared in any frames on the MSDN website that opened in the second browser window.
EDIT 1:
Having now just tested this in Netscape 7.1, the vuln is apparent in this browser.
EDIT 2:
Konqueror 3.2 on Linux also appears to be vulnerable to this bug.
EDIT 3:
Mozilla Firefox 0.9.1 is not affected.
UserAgent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7) Gecko/20040618
Mozilla = Swiss Army Knife: It's versatile, reliable, and contains useful tools.
Microsoft Internet Explorer = Old Swiss Cheese: Full of holes, and it stinks! |
|
| Back to top |
|
 |
Edward


Joined: 01 Dec 2002 Posts: 3100
|
05 Jul, 2004 6:14 am |
[sdp=37381] |
|
Opera 7.51 for Linux is affected by this.
UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; X11; Linux i586) Opera 7.51 [en]
SillyDog701 Moderator
User of SeaMonkey under Mandriva Linux. |
|
| Back to top |
|
 |
Antony


Joined: 18 Jun 2002 Posts: 11869
|
05 Jul, 2004 7:20 am |
[sdp=37383] |
|
| DJGM wrote: | The browser I'm using at the
moment (Mozilla 1.7 on SUSE Linux) does not appear to be affected. No content from Secunia
appeared in any frames on the MSDN website that opened in the second browser window.
...
EDIT 3:
Mozilla Firefox 0.9.1 is not affected. |
Thanks, DJGM,
Is the Mozilla Firefox 0.91 the Windows version or Mac version?
According to the Secunia,
the vulnerability has been confirmed in the following browsers:
- Opera 7.51 for Windows
- Opera 7.50 for Linux
- Mozilla 1.6 for Windows
- Mozilla 1.6 for Linux
- Mozilla Firebird 0.7 for Linux
- Mozilla Firefox 0.8 for Windows
- Netscape 7.1 for Windows
- Internet Explorer for Mac 5.2.3
- Safari 1.2.2
- Konqueror 3.1-15redhat
- Internet Explorer 5.01, 5.5, 6 for Windows.
However, that's not the whole list.
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.8
|
|
| Back to top |
|
 |
DJGM


Joined: 19 Jun 2002 Posts: 4338 Location: Manchester, England, UK
|
|
| Back to top |
|
 |
marcoos

 Marek Stepien Joined: 21 Mar 2003 Posts: 36 Location: Poland
|
05 Jul, 2004 7:57 am |
[sdp=37387] |
|
Browsers based on Gecko 1.7 (for all operating systems), such as Mozilla suite 1.7 and Firefox 0.9.1 are immune to this attack (Secunia's report says this, too).
UserAgent: Mozilla/5.0 (X11; U; Linux i686; pl-PL; rv:1.7) Gecko/20040626 Firefox/0.9.1
|
|
| Back to top |
|
 |
Mandrake


Joined: 13 Sep 2002 Posts: 3628
|
05 Jul, 2004 8:05 am |
[sdp=37388] |
|
It's good to see that Mozilla and Firefox are not effected by this latest flaw. This is certainly a good reason to upgrade to FireFox 0.9.1 or Mozilla 1.7.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616
Antec 900 Case | Core 2 Duo E8200 | Gigabyte X48-DS4 | 4GB G-Skill/Kingston DDR2-800 | HIS Radeon 4870 Xfire | Zalman 850W PSU | Auzen X-Fi Prelude | Logitech Z-2300 Speakers | Sony 1080P 40" HDTV | MS Natural MultiMedia Keyboard | MS Habu Gaming Mouse |
|
| Back to top |
|
 |
Wellander


Joined: 21 Oct 2002 Posts: 2576
|
05 Jul, 2004 10:32 am |
[sdp=37394] |
|
Hi,
How about Netscape 4.x and lower?
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.8a1) Gecko/20040520 |
|
| Back to top |
|
 |
Wellander


Joined: 21 Oct 2002 Posts: 2576
|
05 Jul, 2004 10:38 am |
[sdp=37395] |
|
Hi,
I can not find it in 1.7 and 1.8a1.
I think that these browsers are safe.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.8a1) Gecko/20040520 |
|
| Back to top |
|
 |
Edward


Joined: 01 Dec 2002 Posts: 3100
|
05 Jul, 2004 10:43 am |
[sdp=37396] |
|
Also affects Konqueror 3.2.1 under Linux.
UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; X11; Linux i586) Opera 7.51 [en]
SillyDog701 Moderator
User of SeaMonkey under Mandriva Linux. |
|
| Back to top |
|
 |
Phoenix21692


Joined: 23 Jun 2003 Posts: 234 Location: US
|
05 Jul, 2004 1:31 pm |
[sdp=37405] |
|
I just tested the bug on Netscape Communicator 4.8 and it doesn't appear to be vulnerable. And yes, it doesn't affect Mozilla 1.7 either. Also, I tested the bug on the Release Candiates 1, 2, and 3 of Mozilla 1.7 and these were affected by the bug. Not only that, the flaw also affects Mozilla 1.3.1 and 1.4.2. I'm sure it would affect many of the older builds. So, that means most of the Mozilla builds, up to version 1.7 RC 3 are vulnerable.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616 |
|
| Back to top |
|
 |
DJGM


Joined: 19 Jun 2002 Posts: 4338 Location: Manchester, England, UK
|
|
| Back to top |
|
 |
Don_HH2K


Joined: 09 May 2004 Posts: 4508
|
05 Jul, 2004 2:31 pm |
[sdp=37415] |
|
Great.. Any suggestions on what to do with my old PCs running NS6.1? K-Meleon appears to also be vulnerable, Mozilla won't work in versions above 0.9.4, and Firefox is just as slow for me as 0.9.5+ is...
If NS7.2 isn't released soon, I'll probably switch to Mozilla and possibly stay there. In that case, I hope I'll find a way to get AIM to integrate into Moz1.7..
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax) |
|
| Back to top |
|
 |
akbash


Joined: 09 Feb 2004 Posts: 363
|
05 Jul, 2004 3:07 pm |
[sdp=37419] |
|
Of all the security and crash fixes made since Netscape 6, this is a relatively minor one.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8a2) Gecko/20040704 Firefox/0.8.0+ |
|
| Back to top |
|
 |
Fulvio


Joined: 19 Jun 2002 Posts: 10475
|
05 Jul, 2004 4:51 pm |
[sdp=37427] |
|
| dluchini30 wrote: | Great.. Any suggestions on what to do with my old PCs running NS6.1? K-Meleon appears to also be vulnerable, Mozilla won't work in versions above 0.9.4, and Firefox is just as slow for me as 0.9.5+ is...
If NS7.2 isn't released soon, I'll probably switch to Mozilla and possibly stay there. In that case, I hope I'll find a way to get AIM to integrate into Moz1.7.. |
1. The probability that anything so dangerous will happen to you, is, IMHO, unlikely.
2. Do not store sensitive information on your computer.
3. Give up.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616
"I've got a very poor sense of direction. I keep forgetting which way is forwards."
WinXP, SP2, FF2.0.0.16, FF3.0.1, TB2.0.0.14, IE7.0, Opera9.5, SM1.1.11, Safari3.1.2, Sygate5.6; AVG8.01, JRE1.6_05 |
|
| Back to top |
|
 |
|