Australian IT JOBS : Sydney IT jobs, UNIX jobs, Linux jobs, Java jobs, ASP jobs Linux.conf.au Linux.conf.au
Technology news and Jobs arrow Information Technology News arrow Firefox authentication spoofing vulnerability
Firefox authentication spoofing vulnerability PDF Print E-mail
Written by Stephen Withers   
Monday, 07 January 2008
A researcher has identified a vulnerability in Firefox's basic authentication dialog that may help phishers fool users into false feelings of security.

The problem is that is is possible to craft a WWW-Authenticate header in such a way that Firefox will display an authentication dialog that at first glance resembles that of the real site.

Aviv Raff, who brought the problem to light, says possible exploits include links to "trusted website" such as banks, PayPal or webmail services, coupled with scripting to redirect the newly opened window to the attacker's server.

Other browsers, such as Internet Explorer and Opera display the data in a format that makes it more obvious that the information came from a site other than the one from which it purports to originate.

"Until Mozilla fixes this vulnerability, I recommend not to provide username and password to web sites which show this dialog," says Raff.

According to the Mozilla Security Blog, "Mozilla is currently investigating this issue and has assigned it an initial security severity rating of low."



Get stories like this delivered daily - FREE - subscribe now
When you subscribe get a 12 months license for LiveProject
Valued at $99 USD


LiveWire - Desktop alerts Download the FREE iTWire desktop alert widget LiveWire - Desktop alerts


Del.icio.us!
 
Next >

Latest jobs

Contact , Register , Advertise with iTWire , Links , Register , About iTWire , Feedback , Post your jobs , Events , iTWire site map , Start Blogging
Industry Releases , Submit your release now , Start submitting to iTWire , How to post video