Webmaster Forum

Webmaster Forum Home Webmaster Tools Classified Ads

Go Back   Webmaster Forum > Search Engines & Directories > Search Engines > All Other Search Engines

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 11-15-2008, 04:24 AM
sagar.best's Avatar
Senior
 
Join Date: Oct 2008
Gender: Male
Location: kanpur
Posts: 623
iTrader: (0)
Thanks: 3
Thanked 13 Times in 12 Posts
sagar.best will become famous soon enough
Send a message via MSN to sagar.best Send a message via Yahoo to sagar.best
Default Firefox 3.0.4 is out fixing some 'neat' flaws

As I noted last week Firefox 3.0.4 is out now (technically late yesterday) fixing at least 9 security fixes four of which are labeled as "critical".

There are (as usual) some flawa that I consider to be really interesting - in that they are attack vectors that I just haven't heard off or seen before. One of them is a Cross Site Scripting (XSS) and JavaScript privilege escalation via a Firefox browser

I love the Session Restore feature as I'm the kind of user that always has 10+ tabs open all the time. To think that it could be used as a vehicle to exploit me is "interesting" to say the least. According to Mozilla, as a result of that flaw potentially, "any otherwise unexploitable crash can be used to force the user into the session restore state."

Mozilla also provides a fix for a flaw that could have enabled an attacker to steal user information from local shortcut files. Shortcut files?! Really? Mozilla only labels this flaw as "moderate" since they view it as being a little complex to execute. The way the attack would work is that .url shortcut files could potentially be used to read local cache information if the user downloaded both an HTML file and a .url shortcut.

As part of the update Mozilla is also updating Firefox 2.x to 2.0.0.19 though it's clear that the Firefox 2.x's days are numbered. With Firefox 3.1 around the corner (the Beta 2 release is likely next week now with a test day scheduled for Friday), it will soon be time for Firefox 3.x users to upgrade too.
Reply With Quote
  #2 (permalink)  
Old 11-15-2008, 11:00 AM
Amirmullick3's Avatar
Master
 
Join Date: Apr 2008
Gender: Male
Location: USA, New York -- Born in India
Posts: 4,807
iTrader: (4)
Thanks: 510
Thanked 198 Times in 158 Posts
Amirmullick3 is a name known to allAmirmullick3 is a name known to allAmirmullick3 is a name known to allAmirmullick3 is a name known to allAmirmullick3 is a name known to allAmirmullick3 is a name known to all
Send a message via AIM to Amirmullick3 Send a message via MSN to Amirmullick3 Send a message via Yahoo to Amirmullick3
Default

Hmm, thats really good of them. This is what makes people feel so much safer and at ease on the net.
__________________
Amir Mullick, SEO and Internet Marketer.
Wanna learn more about SEO? Visit my SEO Blog and Gadgets Blog
Reply With Quote
  #3 (permalink)  
Old 11-19-2008, 05:59 AM
sagar.best's Avatar
Senior
 
Join Date: Oct 2008
Gender: Male
Location: kanpur
Posts: 623
iTrader: (0)
Thanks: 3
Thanked 13 Times in 12 Posts
sagar.best will become famous soon enough
Send a message via MSN to sagar.best Send a message via Yahoo to sagar.best
Default

Quote:
Originally Posted by Amirmullick3 View Post
Hmm, thats really good of them. This is what makes people feel so much safer and at ease on the net.
yea firefox rockssss....!!!
Reply With Quote
Reply

Bookmarks

Tags
firefox, fixing, flaws, neat

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla tricks - Latest 7 mozilla firefox tricks sagar.best All Other Search Engines 0 11-20-2008 03:28 AM


 
 
- Advertise here

All times are GMT -4. The time now is 10:01 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.2.0
Ad Management plugin by RedTyger