Hackers work to exploit latest Firefox flaw

By Joris Evers, CNET News.com
Wednesday, September 14, 2005 09:20 AM

Security researchers claim to have found ways to exploit a serious bug in Firefox and Mozilla Web browsers, a sign that attacks could be on the way.

The vulnerability, which could let attackers secretly run malicious software on PCs, was disclosed last week by security researcher Tom Ferris. The Mozilla Foundation, which distributes and coordinates the development of the Firefox and Mozilla browsers, responded swiftly and released a temporary fix on Friday.

The problem also affects the latest Netscape Web browser, according to security experts. Netscape, a division of Time Warner's America Online subsidiary, is investigating the issue, a company representative said Tuesday.

Disclosure of a flaw typically starts a race in the security community to exploit it. In the past few days, at least two security researchers have posted messages to popular security mailing lists claiming they have found ways attackers could take advantage of the vulnerability.

The postings said that exploits that work on Windows and Linux operating systems had been found. At the time the flaw details were disclosed, there were no known exploits for the vulnerability, beyond the one Ferris claimed to have for Windows.

"It took only about 3 hours and 30 minutes to develop the exploit, so I might not be the only one able to write it," Berend-Jan Wever, a computer science student in the Netherlands, wrote in a posting to the Full Disclosure mailing list during the weekend. Wever said he had found an exploit that works on Windows XP and Windows Server 2003.

Wever and Ferris have kept their exploit code private, and no attacks that take advantage of this flaw have been reported. However, criminal hackers are likely not far behind the researchers in working out a mode of attack, experts said.

"We did not see any public exploit for the vulnerability. However, security researchers and hackers are actively working on this issue," a representative of the French Security Incident Response Team, or FrSIRT, said in an e-mail interview. The FrSIRT tags the issue as "critical," its most serious rating.

Ferris agreed that miscreants are looking to write or even buy code that can use the vulnerability to attack people's machines. "I have been e-mailed a couple of times by people asking for an exploit," he said. "This tells me the Trojan writers are out there looking for something."

Name game
The problem in Firefox, Mozilla and Netscape has to do with the way the browsers handle International Domain Names. IDNs are domain names that use local language characters. Experts advise Firefox and Mozilla users to apply the temporary fix provided by the Mozilla Foundation, which disables the IDN feature.

"I would certainly recommend that users implement the vendor workarounds until a patch is made available," said Michael Sutton, director of security intelligence company iDefense Labs. "We feel that exploit code can and will be created."

The security vulnerability in question is a buffer overflow flaw. An attacker could host a Web site containing malicious code to exploit the vulnerability. Mozilla has posted an advisory on its Web site that includes the patch and instructions to manually disable IDN.

Mozilla has said that it is working to fix the actual vulnerability in an upcoming version of Firefox and that it will re-enable the IDN feature in that version. Switching off IDN support impacts Firefox and Mozilla customers who actually use such special domain names.

Firefox has risen in popularity in recent years as a viable alternative to Microsoft's Internet Explorer. Though its market share slipped slightly recently, researchers estimate that between 8 and 9 percent of the Internet population use the open-source Web browser.

Security has been a main selling point for Firefox over Internet Explorer. However, Firefox has had its own security woes. Numerous serious holes in the browser have been plugged since its official release, and experts have said that safe Web browsers don't exist.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web