Mozilla releases browser testing tools

By Robert Vamosi, CNET News.com
Friday, August 03, 2007 11:14 AM

At the Blackhat conference, Window Snyder and Mike Shaver of Mozilla released new tools for testing their browser--Firefox--and other popular browsers, such as Microsoft Internet Explorer, Apple Safari and Opera.

The tools include a protocol fuzzer by Michael Eddington and a Javascript fuzzer by Jesse Ruderman. Fuzzing is a method by which researchers randomly simulate common conditions under which most browsers fail.

Preceding the announcement, Mozilla used the opportunity to discuss what are vulnerabilities, how vendors approach fixing them and--more importantly--how quickly they can get the fix into the hands of users. Snyder quoted Brian Krebs of The Washington Post, who said that Microsoft allowed a known vulnerability to exist in the pre-IE7 version of its browser for a total of 284 days, while Mozilla's longest stretch without a patch was a mere 9 days.

In an interview before the presentation, Snyder said that Firefox enjoys a community of users in the millions worldwide. Of these, there are about 10,000 users who regularly download what are called nightly builds. Whenever the Mozilla security team puts out new fixes in the nightly builds, it's these 10,000 users who test the fixes on a wide variety of machines and under a wide variety of circumstances. Thus, Mozilla is able to roll out its security patches faster and with fewer headaches.

Because Mozilla enjoys a very enthusiastic community of users, it decided to put out tools in the hands of its users that'll help make future releases of Firefox even stronger. After thinking about it, it decided the tools could be used on all browsers, not just its own because many similar vulnerabilities affect other browsers as well. In May, Snyder says Mozilla sent the tools to Microsoft and Opera but did not hear back.

This article was originally a blog posted on CNET News.com


WORTHWHILE?

0

0 votes
Blog

Talkback 2 comments

Please get your facts right. Opera did respond. Check out their Desktop Team blog: (web link)
Posted by anonymous on Saturday, August 04 2007 03:37 PM

Try learning to read.

Synder sent the tools to them in May and the only response from either has been a single blog entry posted less than thirty minutes before the article itself.
Posted by Phoneywar on Monday, August 06 2007 04:24 PM

Guest user

Guest user

Level: 
Joined: —
Already a member? Log in »



 

Loading...

Tech Jobs Now!

Secure ASP.NET sites with Membership API

Web Development

Beginning with ASP.NET 2.0, the Membership API was added to simplify adding security to a Web application. Find out how to use the Membership API with a SQL Server backend.


Read more »



  • HPC Applications

    Ever wondered if High Performing Computing systems really matter in our day-to-day world? Let Dr David Scott from Intel take you a for quick tour on developing HPC applications.
    Play video


  • Maximize IT Spend: Business Acceleration

    How do you ensure your IT solutions are well integrated and streamlined across your enterprise? Rajen from Oracle highlights the important considerations ...
    Play video


  • HPC Architecture: Explained

    Why is High Performance Computing increasingly in demand in today's businesses? Find out which is the most widely deployed HPC architecture today.
    Play video

Tags

  1. apple
  2. attacks
  3. botnet
  4. credit
  5. data
  6. details
  7. dns
  8. facebook
  9. fix
  10. flaw
  11. flaws
  12. fraud
  13. google
  14. iphone
  15. issues
  16. microsoft
  17. olympics
  18. oyster
  19. patch
  20. researcher
  21. researchers
  22. security
  23. spam
  24. storm
  25. team
  26. uk
  27. us
  28. users
  29. warns
  30. worm

ZDNet Asia Top Tech 50 to recognize Asia's potential

Blog thumbnail

The ZDNet Asia Top Tech 50 awards are back, and we're once again seeking nominations to identify the industry's best-performing tech companies.

The marketplace is crowded with players clamoring for..... by Eileen Yu

Read more »