Full Disclosure mailing list archives
Re: Firescrolling [Firefox 1.0]
From: Stan Bubrouski <stan () ccs neu edu>
Date: Fri, 25 Feb 2005 16:33:08 -0500
looked at: http://www.mozilla.org/projects/security/known-vulnerabilities.html
Are you sure its fixed??? -sb Beauford, Jason wrote:
That sucked. Fortunately: http://www.mozilla.org/products/firefox/releases/ jmb -----Original Message-----From: mikx [mailto:mikx () mikx de] Sent: Friday, February 25, 2005 3:11 AMTo: full-disclosure () lists netsys com; bugtraq () securityfocus com; NTBUGTRAQ () LISTSERV NTBUGTRAQ COM Subject: Firescrolling [Firefox 1.0] __SummaryRemember my Internet Explorer "scrollbar exploit" based on http-equiv's "What a Drag"? When will people ever learn that "unusual user interaction" can be hidden by common tasks...Let's combine fireflashing, firetabbing, xul and javascript to runarbitrary code by dragging a scrollbar two times.__Proof-of-Concept http://www.mikx.de/firescrolling/ __Status The exploit is based on multiple vulnerabilities: bugzilla.mozilla.org #280664 (fireflashing) bugzilla.mozilla.org #280056 (firetabbing) bugzilla.mozilla.org #281807 (firescrolling) Upgrade to Firefox 1.0.1 or disable javascript.The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CAN-2005-0527 to this issue.__Affected Software Tested with Firefox 1.0 on Windows and Linux (Fedora Core) __Contact Informations Michael Krax <mikx () mikx de> http://www.mikx.de/?p=11 mikx
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Firescrolling [Firefox 1.0] mikx (Feb 25)
- <Possible follow-ups>
- RE: Firescrolling [Firefox 1.0] Eric McCarty (Feb 25)
- Re: RE: Firescrolling [Firefox 1.0] Niek (Feb 26)
- RE: Firescrolling [Firefox 1.0] Beauford, Jason (Feb 25)
- Re: Firescrolling [Firefox 1.0] Stan Bubrouski (Feb 25)
- Re: Firescrolling [Firefox 1.0] mikx (Feb 26)
- Re: Firescrolling [Firefox 1.0] Stan Bubrouski (Feb 25)
- RE: Firescrolling [Firefox 1.0] Andrade, Leonardo F. Buonsanti de (BR - IT Brazil) (Feb 25)