Security flaw that affects pretty much all browsers

For system help, all hardware / software topics NOTE: use Coders Corner for all coders topics.

Moderators: Krom, Grendel

Post Reply
MD-2389
Defender of the Night
Defender of the Night
Posts: 13477
Joined: Thu Nov 05, 1998 12:01 pm
Location: Olathe, KS
Contact:

Security flaw that affects pretty much all browsers

Post by MD-2389 »

Introduction

Secunia Research has reported a vulnerability, which affects most browsers. The vulnerability can be exploited by a malicious web site to "hi-jack" a named browser window, regardless of which web site is the true "owner" of the window.

Please use the test below, to see an example of how this vulnerability can be exploited, and also to determine whether or not your browser is vulnerable.

The test

Run this test multiple times to be sure. Sometimes it will give false negatives.
User avatar
Jeff250
DBB Master
DBB Master
Posts: 6514
Joined: Sun Sep 05, 1999 2:01 am
Location: ❄️❄️❄️

Post by Jeff250 »

No problems with Lynx here.
User avatar
Duper
DBB Master
DBB Master
Posts: 9214
Joined: Thu Nov 22, 2001 3:01 am
Location: Beaverton, Oregon USA

Post by Duper »

popup bloacker on my FW pretty much cures that. ;)

IE, does not.
User avatar
Fusion
DBB Ace
DBB Ace
Posts: 379
Joined: Sun Sep 07, 2003 2:01 am
Location: Valdez System, Underverse; 7 Stars, Azeroth

Post by Fusion »

Netscape on Mac, NP :D
Fus
User avatar
BUBBALOU
DBB Benefactor
DBB Benefactor
Posts: 4198
Joined: Tue Aug 24, 1999 2:01 am
Location: Dallas Texas USA
Contact:

Post by BUBBALOU »

hahaha

you click the test link and you popup blocker alert sounds like an alarm clock. funny but...

Ghey

maybe you should post this link over at planetdescent they will all get hammered by it...
Plebeian
DBB Alumni
DBB Alumni
Posts: 1055
Joined: Wed Dec 22, 1999 3:01 am
Location: Austin, TX, USA
Contact:

Post by Plebeian »

Heh, they say Firefox is vulnerable, but I tested it five times, and mine didn't show symptoms. ;)
User avatar
CDN_Merlin
DBB_Master
DBB_Master
Posts: 9750
Joined: Thu Nov 05, 1998 12:01 pm
Location: Capital Of Canada

Post by CDN_Merlin »

Using IE at work with Google toolbar and I wasn't affected. Did stop about 500 pop ups though.
User avatar
Mobius
DBB_Master
DBB_Master
Posts: 7940
Joined: Sun Jun 03, 2001 2:01 am
Location: Christchurch, New Zealand
Contact:

Post by Mobius »

OH NO!

I am so scared!

My Browser has a hole!

WHO'D HAVE EVER BELIEVED *THAT*????!!111
User avatar
Top Wop
DBB Master
DBB Master
Posts: 5104
Joined: Wed Mar 01, 2000 3:01 am
Location: Far from you.
Contact:

Post by Top Wop »

Shut up you idiot.
User avatar
suicide eddie
DBB Ace
DBB Ace
Posts: 381
Joined: Mon Sep 09, 2002 2:01 am

Post by suicide eddie »

just a con to get usa today more veiws
User avatar
DCrazy
DBB Alumni
DBB Alumni
Posts: 8826
Joined: Wed Mar 15, 2000 3:01 am
Location: Seattle

Post by DCrazy »

I don't see a "today in pictures" link...
User avatar
Mobius
DBB_Master
DBB_Master
Posts: 7940
Joined: Sun Jun 03, 2001 2:01 am
Location: Christchurch, New Zealand
Contact:

Post by Mobius »

Top Wop - get a sense of humour.

But please, wait until AFTER you boil your head for 20 minutes. A "high simmer" would probably do the trick too.
User avatar
Top Gun
DBB Master
DBB Master
Posts: 8020
Joined: Wed Nov 13, 2002 3:01 am

Post by Top Gun »

Plebeian wrote:Heh, they say Firefox is vulnerable, but I tested it five times, and mine didn't show symptoms. ;)
Weird...I'm also using Firefox, and I saw the window.
User avatar
roid
DBB Master
DBB Master
Posts: 9990
Joined: Sun Dec 09, 2001 3:01 am
Location: Brisbane, Australia
Contact:

Post by roid »

firefox here. i seem to be safe, it was not able to open the window.

when i clicked the "no popup blocker" link, firefox sure enough STOPPED the popup from opening. (i guess this popup was supposed to grab control of the other window yes?). all clicking the link did was open the usatoday website in a new tab (with a typical firefox notice at the top that firefox had stopped it opening a popup window).

so i clicked the "i have a popup blocker" link, and it told me that i didn't have a popup blocker - and refused to run the test.

so i guess i win :)

perhaps it's because i use the tabbrowser preferences extention for firefox, NOTHING can open a new window, everything opens in a new TAB instead. i only ever have 1 firefox window open.
User avatar
Top Gun
DBB Master
DBB Master
Posts: 8020
Joined: Wed Nov 13, 2002 3:01 am

Post by Top Gun »

I have it configured to open in new tabs as well; I simply assumed that opening the tab was enough, by their definition, to fail the test.
User avatar
roid
DBB Master
DBB Master
Posts: 9990
Joined: Sun Dec 09, 2001 3:01 am
Location: Brisbane, Australia
Contact:

Post by roid »

to have failed the test i think it has to open a new SECUNIA window, instead of a USATODAY window. or the USATODAY window turns into a SECUNIA window, or something to that effect.

all i saw was the USATODAY tab, since that's what the link had written on it: i kinda expected that ;)
User avatar
SSX-Thunderbird
DBB Admiral
DBB Admiral
Posts: 1275
Joined: Sun Jun 03, 2001 2:01 am
Location: Washington (the state, not the city)

Post by SSX-Thunderbird »

You fail if the new window opened by the Day In Pictures link ends up as a Secunia window instead of a USA Today window.
User avatar
roid
DBB Master
DBB Master
Posts: 9990
Joined: Sun Dec 09, 2001 3:01 am
Location: Brisbane, Australia
Contact:

Post by roid »

ah ok.
*tries*

i am still a winnar.
User avatar
fliptw
DBB DemiGod
DBB DemiGod
Posts: 6458
Joined: Sat Oct 24, 1998 2:01 am
Location: Calgary Alberta Canada

Post by fliptw »

secunia found an exploit that works this week. IE only.

im wrong. Firefox is vunerable to the first exploit., if, I need to test this, you either uninstall Adaware or TBE.

Its TBE. funny.
User avatar
Vindicator
DBB Benefactor
DBB Benefactor
Posts: 3166
Joined: Mon Dec 16, 2002 3:01 am
Location: southern IL, USA
Contact:

Post by Vindicator »

roid wrote:perhaps it's because i use the tabbrowser preferences extention for firefox, NOTHING can open a new window, everything opens in a new TAB instead. i only ever have 1 firefox window open.
I'm pretty sure thats what did it, since my Firefox was vulnerable before I installed the tabbrowser extension but now it isnt.
User avatar
Boo
DBB Ace
DBB Ace
Posts: 413
Joined: Mon Feb 09, 2004 3:01 am

Post by Boo »

Using firefox here and failed
User avatar
substratus
DBB Cadet
DBB Cadet
Posts: 8
Joined: Tue Nov 23, 2004 4:30 am

Post by substratus »

They also say Opera is vulnerable but it doesn't work right, instead of the site taking over the pop-up window the pop-up window loads on top of the site.
User avatar
Testiculese
DBB Material Defender
DBB Material Defender
Posts: 4688
Joined: Sun Nov 11, 2001 3:01 am

Post by Testiculese »

It snagged the pop up that opened in Firefox. It wasn'[t an unintended pop-up, Firefox does open new windows if you *click* a link that is set to open a new window. That in itself is not a vulnerability or a problem.

I dont' see how this will affect any other than the dumbest people. You first have to be on an untrusted site for it to work anyway. Who clicks on the link to their bank account from hackerz.com anyway?
User avatar
Tyranny
DBB Defender
DBB Defender
Posts: 3399
Joined: Sun Nov 10, 2002 3:01 am
Location: Phoenix, Arizona

Post by Tyranny »

Ace? ;)
Post Reply