Author Topic: Don't save dose dere passwords on the fiery/volish browser  (Read 3580 times)

Offline W1nTry

  • Administrator
  • Akatsuki
  • *****
  • Posts: 11329
  • Country: tt
  • Chakra 109
  • Referrals: 3
    • View Profile
  • CPU: Intel Core i7 3770
  • GPU: Gigabyte GTX 1070
  • RAM: 2x8GB HyperX DDR3 2166MHz
  • Broadband: FLOW
  • Steam: W1nTry
  • XBL: W1nTry
Don't save dose dere passwords on the fiery/volish browser
« on: November 22, 2006, 08:18:40 AM »
Quote
Firefox gives passwords away

Bugged

By Nick Farrell: Wednesday 22 November 2006, 08:27
THE MOZZARELLA Foundation has issued a security warning on its Firebadger open sauce browser.

Apparently the browser's secure password manager has a nasty habit of telling other people your user name and password.

The problem comes about because Firebadger supplies the username and password stored on one page on a domain to another page on a domain. For example the Username and password input tags on a Myspace user's site will be shared along with the visitor's Myspace.com credentials.

According to Robert Chapin, of Chapin Information Services, who reports the problem on Bugzilla, the flaw means that passwords can be stolen without punters being aware of it.

In the short term, Mozzarella is suggesting avoiding using Password Manager and the Master Password Timeout Firefox extension.

However, an exploit found in the wild mimicked the login.myspace.com site almost perfectly, causing many users to believe they needed to log in.

More here. µ
« Last Edit: November 24, 2006, 08:52:25 AM by W1nTry »

Carigamers

Don't save dose dere passwords on the fiery/volish browser
« on: November 22, 2006, 08:18:40 AM »

Offline Nephilim

  • Sannin
  • *****
  • Posts: 2698
  • Country: 00
  • Chakra 56
  • Referrals: 0
    • View Profile
  • CPU: Q94
  • GPU: 4870
  • RAM: 8GB
  • Broadband: Flow
Re: Don't save dose dere passwords on the fiery browser
« Reply #1 on: November 22, 2006, 08:24:38 AM »
oh lord!!!!!!!!!
and that is ah favorite feature of mine!!!!!!

i see on the report is only saying firefox 2, can it be assumed that 1.5.x.x okay then?

Offline W1nTry

  • Administrator
  • Akatsuki
  • *****
  • Posts: 11329
  • Country: tt
  • Chakra 109
  • Referrals: 3
    • View Profile
  • CPU: Intel Core i7 3770
  • GPU: Gigabyte GTX 1070
  • RAM: 2x8GB HyperX DDR3 2166MHz
  • Broadband: FLOW
  • Steam: W1nTry
  • XBL: W1nTry
Re: Don't save dose dere passwords on the fiery/volish browser
« Reply #2 on: November 24, 2006, 08:52:59 AM »
Not that we expect 'great security' from a MS product.. but all the same a related update:
Quote
Internet Explorer 7 suffers from Firefox bug too

Just less likely to catch it

By Nick Farrell: Friday 24 November 2006, 07:38
IT APPEARS that the latest version of Internet Exploder has the same bug that is, er, bugging the Mozzarella Foundation's Firefox.

Earlier this I said Firefox was victim to a bug that "steals" the login id and passwords of users.

According to Techtree, the geezer who found the Reverse Cross Site Request vulnerability in Firefox, Robert Chapin, has found the same bug in Explorer.

However, the attacks are likely to worry Firefox users more because its Password Manager automatically enters any saved passwords and user-ids into forms, whereas IE can't fill in the saved information automatically.

According to Chapin, Firefox and IE users need to be aware that their information can be stolen in this way when visiting bogs and forum Web sites even at trusted addresses.

Offline BloodWar

  • Kage
  • ****
  • Posts: 1264
  • Chakra -522
    • PS3 and NDS
  • Referrals: 0
    • View Profile
Re: Don't save dose dere passwords on the fiery/volish browser
« Reply #3 on: March 31, 2007, 06:22:00 PM »
WTF I GOIN TO UNSAVE ALL MY PASSWORDS NOW OH LORD MY FINGERS GO DEAD TYPING LOL.
I will live forever..... Until i die

Carigamers

Re: Don't save dose dere passwords on the fiery/volish browser
« Reply #3 on: March 31, 2007, 06:22:00 PM »

 


* ShoutBox

Refresh History
  • Crimson609: yea everything cool how are you?
    August 10, 2022, 07:26:15 AM
  • Pain_Killer: Good day, what's going on with you guys? Is everything Ok?
    February 21, 2021, 05:30:10 PM
  • Crimson609: BOOM covid-19
    August 15, 2020, 01:07:30 PM
  • Shinsoo: bwda 2020 shoutboxing. omg we are in the future and in the past at the same time!
    March 03, 2020, 06:42:47 AM
  • TriniXjin: Watch Black Clover Everyone!
    February 01, 2020, 06:30:00 PM
  • Crimson609: lol
    February 01, 2020, 05:05:53 PM
  • Skitz: So fellas how we go include listing for all dem parts for pc on we profile but doh have any place for motherboard?
    January 24, 2020, 09:11:33 PM
  • Crimson609: :ph34r:
    January 20, 2019, 09:23:28 PM
  • Crimson609: Big up ya whole slef
    January 20, 2019, 09:23:17 PM
  • protomanex: Gyul like Link
    January 20, 2019, 09:23:14 PM
  • protomanex: Man like Kitana
    January 20, 2019, 09:22:39 PM
  • protomanex: Man like Chappy
    January 20, 2019, 09:21:53 PM
  • protomanex: Gyul Like Minato
    January 20, 2019, 09:21:48 PM
  • protomanex: Gyul like XJin
    January 20, 2019, 09:19:53 PM
  • protomanex: Shout out to man like Crimson
    January 20, 2019, 09:19:44 PM
  • Crimson609: shout out to gyal like Corbie Gonta
    January 20, 2019, 09:19:06 PM
  • cold_187: Why allur don't make a discord or something?
    December 03, 2018, 06:17:38 PM
  • Red Paradox: https://www.twitch.tv/flippay1985 everyday from 6:00pm
    May 29, 2018, 09:40:09 AM
  • Red Paradox: anyone play EA Sports UFC 3.. Looking for a challenge. PSN: Flippay1985 :)
    May 09, 2018, 11:00:52 PM
  • cold_187: @TriniXjin not really, I may have something they need (ssd/ram/mb etc.), hence why I also said "trade" ;)
    February 05, 2018, 10:22:14 AM

SimplePortal 2.3.3 © 2008-2010, SimplePortal