Firefox leaks info useful to attackers

Some browser add-ons let hackers do preattack reconnaissance

Mozilla's head of security Tuesday confirmed a bug in Firefox that could be used by attackers to scout out a system prior to mounting a more thorough assault.

The flaw, said Window Snyder, Mozilla's chief security officer, is in the browser's chrome protocol -- "chrome" is the Firefox term for its user interface -- as she responded to reports of the vulnerability and the public posting of a proof-of-concept exploit.

Access to a user's machine would be through one of many Firefox extensions packaged in a flat file structure, rather than collected into a single Java archive, or .jar file, said Snyder. Several popular extensions, including Download Statusbar and Greasemonkey, use a flat file structure. "Users are only at risk if they have one of the 'flat' packaged add-ons installed," Snyder said on the Mozilla security blog.

By leading users to a tricked-out Web page, criminals could sniff for information that might be useful in more aggressive attacks, Snyder acknowledged. "A visited attacking page is able to load images, scripts or style sheets from known locations on the disk," she said. "Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed. This information may be used to profile the system for a different kind of attack."

Firefox developers are working on a patch, according to a thread on Bugzilla, Mozilla's bug-tracking and management site, but a fix has not yet been coded.

In the meantime, the authors of the two extensions that Snyder called out -- Download Statusbar and Greasemonkey -- have updated their works so that they cannot be exploited. "I just released a JARred version of Download Statusbar 0.9.5.3," said Devon Johnson on Bugzilla.

Firefox users can also deploy another add-on, the popular NoScript, to block exploits, no matter which extensions have been installed, updated or not. "[NoScript] block[s] chrome JavaScript load attempts," reported Giorgio Maone, NoScript's maker, on the same Bugzilla thread.

Although Snyder downplayed the threat posed by the bug, Gerry Eisenhauer, the researcher who uncovered the vulnerability, said there might be more to it. "This looks very interesting and may have bigger potential," he said Saturday in his original write-up. "But for now, it's just another information disclosure."

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Gregg Keizer

Computerworld
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?