Hard Light Productions Forums

Off-Topic Discussion => General Discussion => Topic started by: Kamikaze on July 08, 2004, 08:28:26 pm

Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Kamikaze on July 08, 2004, 08:28:26 pm
The listed Mozilla.org software uses the shell: protocol handler for its browser, apparently this passes stuff off to Windows APIs. Looks like the Windows APIs were bugged (and it was exploited), and Mozilla.org has released a fix to work around it.

The bug makes it possible for arbitrary execution of code via the software.

Note that non-Windows users of the software don't have to do anything.

http://www.mozilla.org/security/shell.html
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: SA22C on July 08, 2004, 08:38:31 pm
Thanks for the heads up.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Taristin on July 08, 2004, 09:10:21 pm
Yeah. I'll have to patch that up when I get the modem back.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: kasperl on July 09, 2004, 04:55:07 am
I got the patch when I booted up mo today. I'll update my laptop when I get it back.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: vyper on July 09, 2004, 06:21:00 am
Good man, Kam. I updated the minute I saw this thread, you quite possibly saved a lot of ppl's browsers around here. :)
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: karajorma on July 09, 2004, 07:15:26 am
I love the fact that even when there is a mozilla exploit the underlying cause is still MS :D
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: IceFire on July 09, 2004, 07:42:37 am
Quote
Originally posted by karajorma
I love the fact that even when there is a mozilla exploit the underlying cause is still MS :D

I KNOW...its so funny and disturbing at the same time :D

Thanks for letting us know.  Updated and patched.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: WMCoolmon on July 09, 2004, 02:12:19 pm
It was also much easier to fix than it would be using IE...didn't even have to restart.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Sandwich on July 09, 2004, 04:26:27 pm
I wish I could upgrade my Mozilla beyond 1.5. Danged screwiness.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: IceFire on July 09, 2004, 05:32:45 pm
Quote
Originally posted by Sandwich
I wish I could upgrade my Mozilla beyond 1.5. Danged screwiness.

Wha?

And why not use Firefox? :)
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Sandwich on July 09, 2004, 08:33:45 pm
I do use Firefox from time to time, but it's still too buggy for me to step over the 50/50 line from Mozilla. I'm a very heavy power user, and I demand a lot from my software.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Setekh on July 09, 2004, 11:59:22 pm
Hey, cheers. I'll go let my brother know, he swears by Firefox. ;)
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Kamikaze on July 12, 2004, 08:43:37 pm
Sorry to bump this everyone, but an interesting related article came up.

http://www.infoworld.com/article/04/07/12/HNmicromozilla_1.html

To sum it up, the shell: exploit may affect Winword and MSN messenger.

Alternatives to Winword:
http://www.openoffice.org/
http://www.abisource.com/

Alternative to MSN messenger:
http://gaim.sourceforge.net/
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: WMCoolmon on July 12, 2004, 09:01:40 pm
Though my opinion has soured due to the lack of updates for the basic version,

http://www.trillian.cc
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Lonestar on July 12, 2004, 10:20:21 pm
Quote
Originally posted by WMCoolmon
It was also much easier to fix than it would be using IE...didn't even have to restart.


You dont have to restart every time you update IE. Alot of times you dont have to restart windows XP at all. By the same token, ive never had to worry about 3rd party software being buggy or exploitable.
Why do people replace perfectly good working Windows programs with buggy 3rd party software?

I could understand if you used a non-windows OS, but on a windows system? Doesnt make much sense considering how easy it is to use IE and how stable it is.

Stop being a corporate guinea pig and just accept the good things we have! :D
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: Kamikaze on July 12, 2004, 10:25:20 pm
Wait a second, you're calling Firefox/Mozilla users corporate guinea pigs? When you're advocating corporate products (from a monopoly too) in a thread about how this particular corporation has fscked up APIs?
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: WMCoolmon on July 12, 2004, 10:33:03 pm
IE has no tabs, and Firefox just seems a lot more stable than it.

Plus it means if I ever use a non-Windows system, I already know a good browser that I can use.
Title: Exploit for Mozilla/Firefox/Thunderbird on Windows
Post by: karajorma on July 13, 2004, 05:32:47 am
Quote
Originally posted by Lonestar
Stop being a corporate guinea pig and just accept the good things we have! :D


I've already said (admittedly on the other mozilla thread) that I use Mozilla because it has features I like that IE doesn't have. It is also more secure. It is also more stable.

When I used IE I would find that it would lock up causing me to have to kill it from the task manager every few days.

With Mozilla I've had to do that twice in the last few months.

And yet you still claim that using IE would be a better choice?

What the **** are you on Lonestar? If new features aren't damn good reasons for using a different piece of software I don't know what is.  Tell me this, do you use WordPad for all your word procesing needs cause it too comes with the OS?