"Frame Injection" vuln affects all browsers

Firefox, Thunderbird, SeaMonkey, Camino, Mozilla, Netscape 6/7/8/9, and all Gecko-based browsers discussion and support forum.
(MozInfo701, Netscape Browser Archive)

Moderators: Antony, Edward, profman, Ramona

Postby Edward » Mon 05 Jul, 2004 5:56 pm

People really have to be VERY AWARE of where they browse on the web today.

Just the other evening, I was watching one of the business shows on cable, and they reported the top three items sold online.

Books was # 1, and the second-highest (both by dollar amount) is not acceptable to mention in this forum.
UserAgent: Opera/7.51 (X11; Linux i586; U) [en]
SillyDog701 Moderator
debian 6 - iceape - iceweasel - icedove - seamonkey
User avatar
Edward
Moderator
Moderator
 
Posts: 3584
Joined: Sun 01 Dec, 2002 7:15 pm

Postby akbash » Mon 05 Jul, 2004 7:43 pm

#3 is garden gnomes, isn't it? Yeah, I'm gonna make a killing.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8a2) Gecko/20040704 Firefox/0.8.0+
akbash
silver member
silver member
 
Posts: 364
Joined: Mon 09 Feb, 2004 9:13 pm

Postby Fulvio » Mon 05 Jul, 2004 8:03 pm

I don't think that this is surprising, nor of much interest here, but Compuserve7.0, which is based on Mozilla0.9.4, and AOL9.0, both the original, and a later build are vulnerable.
May be someone at AOL does know what's going on( i.e. NS7.2)
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040626 Weblemur/0.9.1
A minority may be right, and a majority is always wrong
~ Henrik Ibsen
WinXP, SP3, 512 MB, SM2.9.1, FF12, TB12.0.1, IE8.0, Google Chrome18, Ghostwall , Avast 7.x, JRE1.7_04. Testing FF13b4
User avatar
Fulvio
Moderator
Moderator
 
Posts: 11916
Joined: Wed 19 Jun, 2002 10:08 am

Postby Fulvio » Mon 05 Jul, 2004 9:15 pm

Internet Explorer6 vulnerability can be defeated by disabling in the Internet Security settings(custom): "Navigate sub frames across domains.
This was brought up at Ramona's windows BBS forum. I fiddle with all setting in Netscape7.1, with no success, so far.
Of course, all IE-based programs, including AOL9.0 are also protected, since they use the IE settings.
Now what?
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616
A minority may be right, and a majority is always wrong
~ Henrik Ibsen
WinXP, SP3, 512 MB, SM2.9.1, FF12, TB12.0.1, IE8.0, Google Chrome18, Ghostwall , Avast 7.x, JRE1.7_04. Testing FF13b4
User avatar
Fulvio
Moderator
Moderator
 
Posts: 11916
Joined: Wed 19 Jun, 2002 10:08 am

Postby Edward » Mon 05 Jul, 2004 9:24 pm

Some members of the My Opera Community have reported seeing Opera 7.52 UserAgent strings in some of the newsgroup messages, so Opera might be working on it.
UserAgent: Opera/7.51 (X11; Linux i586; U) [en]
SillyDog701 Moderator
debian 6 - iceape - iceweasel - icedove - seamonkey
User avatar
Edward
Moderator
Moderator
 
Posts: 3584
Joined: Sun 01 Dec, 2002 7:15 pm

Postby Fulvio » Tue 06 Jul, 2004 8:47 pm

A security friend of mine said that the protection of IE and AOL is legit, but also that not many websites use sub-frames, so the test is misleading. His feeling is to stay away from Active X as much as possible.
He loves Firefox0.9.1.
UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; BCD2000)
A minority may be right, and a majority is always wrong
~ Henrik Ibsen
WinXP, SP3, 512 MB, SM2.9.1, FF12, TB12.0.1, IE8.0, Google Chrome18, Ghostwall , Avast 7.x, JRE1.7_04. Testing FF13b4
User avatar
Fulvio
Moderator
Moderator
 
Posts: 11916
Joined: Wed 19 Jun, 2002 10:08 am

Postby Jeffredo » Tue 06 Jul, 2004 8:57 pm

Opera 7.52 is on the Opera FTP server, but not yet on their website download. I installed it, ran the test at Secunia and it passed. Typical Opera (quick to fix)! :)
UserAgent: Opera/7.52 (Windows NT 5.1; U) [en]
Jeff
User avatar
Jeffredo
super member
super member
 
Posts: 169
Joined: Tue 09 Mar, 2004 11:40 pm
Location: Monterey, California

Postby Mandrake » Tue 06 Jul, 2004 9:05 pm

I prefer already being protected against this :wink:
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616
Core i7 920 | ASUS P6T Deluxe v2 | 3TB+ HDD | 12GB Corsair DDR3 | Radeon 4890 Xfire | X-Fi Titanium Fatal1ty | Logitech Z-5500 Speakers | Dell 3008WFP | Seven RC1
User avatar
Mandrake
Moderator
Moderator
 
Posts: 4193
Joined: Fri 13 Sep, 2002 6:35 am

Postby Don_HH2K » Tue 06 Jul, 2004 9:28 pm

Mandrake wrote:I prefer already being protected against this :wink:


It seems we have little time that we will have to wait for a NS7.2, judging by the new test site.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Don_HH2K » Wed 07 Jul, 2004 5:04 pm

Just an idea if this might be a workaround for NS7.1 and other Mozilla releases prior to 1.7

In my c:\Program Files\Common Files\Mozilla.org, I have two folders: One for 1.4 final and one for 1.7 beta (I used that for awhile). Lets say that I was to move the files from the 1.7beta folder to the 1.4 final folder. Would that work at all, or would I get large crash problems?

EDIT- No, it doesn't work...
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
User avatar
Don_HH2K
Moderator
Moderator
 
Posts: 5112
Joined: Sun 09 May, 2004 3:59 pm

Postby Fulvio » Wed 07 Jul, 2004 8:51 pm

Edward wrote:People really have to be VERY AWARE of where they browse on the web today.

Just the other evening, I was watching one of the business shows on cable, and they reported the top three items sold online.

Books was # 1, and the second-highest (both by dollar amount) is not acceptable to mention in this forum.


I doubt that the people involved got trapped into buying the unmentionable items. I also read of the large percentage of people who are indignant at receiving any amount of spam, and I agree 100%. But the same survey said that 20% will order Spam stuff. That's why we keep getting the ugly stuff.
It is good to use software which will not allow any stranger in, but if they set their mind to it, anything can become unsafe. But, who needs to work hard if we use Windows, so good for you.
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7) Gecko/20040616
A minority may be right, and a majority is always wrong
~ Henrik Ibsen
WinXP, SP3, 512 MB, SM2.9.1, FF12, TB12.0.1, IE8.0, Google Chrome18, Ghostwall , Avast 7.x, JRE1.7_04. Testing FF13b4
User avatar
Fulvio
Moderator
Moderator
 
Posts: 11916
Joined: Wed 19 Jun, 2002 10:08 am

Previous

Return to Firefox, SeaMonkey and Netscape

Who is online

Registered users: Google [Bot], Google Feedfetcher