Follow iTWire on Twitter

About iTWire

iTWire is all about technology news, information, jobs and community for the IT and telecommunications industry professional. Subscribe to our free ICT daily newsletter
Firefox authentication spoofing vulnerability E-mail
by Stephen Withers   
Monday, 07 January 2008
A researcher has identified a vulnerability in Firefox's basic authentication dialog that may help phishers fool users into false feelings of security.

Register now to win a Canon EOS 500D Cannon EOS 500D Digiral SLR

The problem is that is is possible to craft a WWW-Authenticate header in such a way that Firefox will display an authentication dialog that at first glance resembles that of the real site.

Aviv Raff, who brought the problem to light, says possible exploits include links to "trusted website" such as banks, PayPal or webmail services, coupled with scripting to redirect the newly opened window to the attacker's server.

Other browsers, such as Internet Explorer and Opera display the data in a format that makes it more obvious that the information came from a site other than the one from which it purports to originate.

"Until Mozilla fixes this vulnerability, I recommend not to provide username and password to web sites which show this dialog," says Raff.

According to the Mozilla Security Blog, "Mozilla is currently investigating this issue and has assigned it an initial security severity rating of low."

Please enable JavaScript in your browser to post your comment!

Tags See All Tags Add New Tag...

Please Enter New Tags Separated By Comma's
  Or Close

Browsers  Security  Software  Stephen Withers  Web 
Powered By Joomla Tags

 
< Next story in category   Previous story in the category >
iTWire user statistics Visitors last 30 days
665,005
Subscribers 14,517
#1 independent technology news advertise here
  •   *  
  • Search
  • AdvSeach
  • Login
  • Events
  • FreeStuff

Register now to win a Canon EOS 500D Canon EOS 500D Digital SLR
1