Follow Us

Firefox vulnerable to password-stealing

Browser doesn't check who is asking for the information.

A flaw in Firefox allows you to steal user information on websites where users create their own pages, such as MySpace.

The flaw in the browser's Password Manager software can be tricked into sending password information to a different website, said Robert Chapin, president of Chapin Information Services. But for it to work, attackers need to be able to create HTML forms on the site - something not allowed on blogging and social networking sites.

The attack was used in a MySpace phishing attack last month where a fake log-in page was use to exploit the flaw. The page then sent MySpace username and password information to another site, and MySpace users who visited the page using Firefox could have easily had their information compromised, said Chapin. Firefox developers rate the bug critical.

Related Articles on Techworld

Password Manager currently does not check if password information is being sent to the server that requested it, Chapin said. "From a programming point of view, this is almost like a typo," he said. "Ironically I think that's why it hasn't been discovered until now. It was just way too obvious."

Internet Explorer is also susceptible to the attack but is less likely to be tricked because it does a more thorough job in checking to see where a log-in form is coming from before it automatically submits password and user information.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *