Password flaw hits Firefox and Safari

JavaScript and password manager make disastrous combination

Written by Ian Williams

The latest versions of Firefox and Safari contain a password management security flaw that could allow certain websites to access stored usernames and passwords.

A message on the Full Disclosure mailing list warned that users who have either browser configured to remember passwords, and have JavaScript enabled, are at risk.

Mozilla fixed a similar reverse cross-site scripting flaw in Firefox last November, but this was a lot more serious as it did not require JavaScript to be enabled.

Heise Security has a demonstration of the vulnerability on its website to allow users to determine whether they are vulnerable to the attack. 

However, some developers and commentators have questioned whether this constitutes a vulnerability in the browser, as it requires the attacker to place malicious code on the web server.

If an attacker can place script code on a server, they would be able to manipulate the pages anyway, and would have other ways to steal user access data.

Until a fix is released, users are urged to disable JavaScript in their browser or avoid the use of the password manager on sites where users are allowed to post JavaScript pages.

Tags:

Further reading

Firefox attack uses Internet Explorer

Microsoft browser can pass on attack to rival   More...

Cross-browser Firefox/IE flaw worsens

IM app used to launch attack   More...

Mozilla patches cross-browser Firefox flaw

Fix does not cover Internet Explorer problem   More...

Four more fixes for Windows Safari

Security updates pile up for Apple browser   More...

Related articles

iPhone update thwarts hacks

New firmware disables SIM-hacked phones   More...

QuickTime flaw adds to Apple's woes

Exploit especially dangerous for Firefox users   More...

Mozilla patches cross-browser Firefox flaw

Fix does not cover Internet Explorer problem   More...

Mozilla issues 'critical' Firefox fixes

Update addresses a number of security issues   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement