Author Topic: Exploit for Mozilla/Firefox/Thunderbird on Windows  (Read 1156 times)

0 Members and 1 Guest are viewing this topic.

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Exploit for Mozilla/Firefox/Thunderbird on Windows
The listed Mozilla.org software uses the shell: protocol handler for its browser, apparently this passes stuff off to Windows APIs. Looks like the Windows APIs were bugged (and it was exploited), and Mozilla.org has released a fix to work around it.

The bug makes it possible for arbitrary execution of code via the software.

Note that non-Windows users of the software don't have to do anything.

http://www.mozilla.org/security/shell.html
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 

Offline SA22C

  • 26
Exploit for Mozilla/Firefox/Thunderbird on Windows
Thanks for the heads up.

 

Offline Taristin

  • Snipes
  • 213
  • BlueScalie
    • Skelkwank Shipyards
Exploit for Mozilla/Firefox/Thunderbird on Windows
Yeah. I'll have to patch that up when I get the modem back.
Freelance Modeler | Amateur Artist

 
Exploit for Mozilla/Firefox/Thunderbird on Windows
I got the patch when I booted up mo today. I'll update my laptop when I get it back.
just another newbie without any modding, FREDding or real programming experience

you haven't learned masochism until you've tried to read a Microsoft help file.  -- Goober5000
I've got 2 drug-addict syblings and one alcoholic whore. And I'm a ****ing sociopath --an0n
You cannot defeat Windows through strength alone. Only patience, a lot of good luck, and a sledgehammer will do the job. --StratComm

 

Offline vyper

  • 210
  • The Sexy Scotsman
Exploit for Mozilla/Firefox/Thunderbird on Windows
Good man, Kam. I updated the minute I saw this thread, you quite possibly saved a lot of ppl's browsers around here. :)
"But you live, you learn.  Unless you die.  Then you're ****ed." - aldo14

 

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Exploit for Mozilla/Firefox/Thunderbird on Windows
I love the fact that even when there is a mozilla exploit the underlying cause is still MS :D
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]

 

Offline IceFire

  • GTVI Section 3
  • 212
    • http://www.3dap.com/hlp/hosted/ce
Exploit for Mozilla/Firefox/Thunderbird on Windows
Quote
Originally posted by karajorma
I love the fact that even when there is a mozilla exploit the underlying cause is still MS :D

I KNOW...its so funny and disturbing at the same time :D

Thanks for letting us know.  Updated and patched.
- IceFire
BlackWater Ops, Cold Element
"Burn the land, boil the sea, you can't take the sky from me..."

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Exploit for Mozilla/Firefox/Thunderbird on Windows
It was also much easier to fix than it would be using IE...didn't even have to restart.
-C

 

Offline Sandwich

  • Got Screen?
  • 213
    • Skype
    • Steam
    • Twitter
    • Brainzipper
Exploit for Mozilla/Firefox/Thunderbird on Windows
I wish I could upgrade my Mozilla beyond 1.5. Danged screwiness.
SERIOUSLY...! | {The Sandvich Bar} - Rhino-FS2 Tutorial | CapShip Turret Upgrade | The Complete FS2 Ship List | System Background Package

"...The quintessential quality of our age is that of dreams coming true. Just think of it. For centuries we have dreamt of flying; recently we made that come true: we have always hankered for speed; now we have speeds greater than we can stand: we wanted to speak to far parts of the Earth; we can: we wanted to explore the sea bottom; we have: and so  on, and so on: and, too, we wanted the power to smash our enemies utterly; we have it. If we had truly wanted peace, we should have had that as well. But true peace has never been one of the genuine dreams - we have got little further than preaching against war in order to appease our consciences. The truly wishful dreams, the many-minded dreams are now irresistible - they become facts." - 'The Outward Urge' by John Wyndham

"The very essence of tolerance rests on the fact that we have to be intolerant of intolerance. Stretching right back to Kant, through the Frankfurt School and up to today, liberalism means that we can do anything we like as long as we don't hurt others. This means that if we are tolerant of others' intolerance - especially when that intolerance is a call for genocide - then all we are doing is allowing that intolerance to flourish, and allowing the violence that will spring from that intolerance to continue unabated." - Bren Carlill

 

Offline IceFire

  • GTVI Section 3
  • 212
    • http://www.3dap.com/hlp/hosted/ce
Exploit for Mozilla/Firefox/Thunderbird on Windows
Quote
Originally posted by Sandwich
I wish I could upgrade my Mozilla beyond 1.5. Danged screwiness.

Wha?

And why not use Firefox? :)
- IceFire
BlackWater Ops, Cold Element
"Burn the land, boil the sea, you can't take the sky from me..."

 

Offline Sandwich

  • Got Screen?
  • 213
    • Skype
    • Steam
    • Twitter
    • Brainzipper
Exploit for Mozilla/Firefox/Thunderbird on Windows
I do use Firefox from time to time, but it's still too buggy for me to step over the 50/50 line from Mozilla. I'm a very heavy power user, and I demand a lot from my software.
SERIOUSLY...! | {The Sandvich Bar} - Rhino-FS2 Tutorial | CapShip Turret Upgrade | The Complete FS2 Ship List | System Background Package

"...The quintessential quality of our age is that of dreams coming true. Just think of it. For centuries we have dreamt of flying; recently we made that come true: we have always hankered for speed; now we have speeds greater than we can stand: we wanted to speak to far parts of the Earth; we can: we wanted to explore the sea bottom; we have: and so  on, and so on: and, too, we wanted the power to smash our enemies utterly; we have it. If we had truly wanted peace, we should have had that as well. But true peace has never been one of the genuine dreams - we have got little further than preaching against war in order to appease our consciences. The truly wishful dreams, the many-minded dreams are now irresistible - they become facts." - 'The Outward Urge' by John Wyndham

"The very essence of tolerance rests on the fact that we have to be intolerant of intolerance. Stretching right back to Kant, through the Frankfurt School and up to today, liberalism means that we can do anything we like as long as we don't hurt others. This means that if we are tolerant of others' intolerance - especially when that intolerance is a call for genocide - then all we are doing is allowing that intolerance to flourish, and allowing the violence that will spring from that intolerance to continue unabated." - Bren Carlill

 

Offline Setekh

  • Jar of Clay
  • 215
    • Hard Light Productions
Exploit for Mozilla/Firefox/Thunderbird on Windows
Hey, cheers. I'll go let my brother know, he swears by Firefox. ;)
- Eddie Kent Woo, Setekh, Steak (of Steaks), AWACS. Seriously, just pick one.
HARD LIGHT PRODUCTIONS, now V3.0. Bringing Modders Together since January 2001.
THE HARD LIGHT ARRAY. Always makes you say wow.

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Exploit for Mozilla/Firefox/Thunderbird on Windows
Sorry to bump this everyone, but an interesting related article came up.

http://www.infoworld.com/article/04/07/12/HNmicromozilla_1.html

To sum it up, the shell: exploit may affect Winword and MSN messenger.

Alternatives to Winword:
http://www.openoffice.org/
http://www.abisource.com/

Alternative to MSN messenger:
http://gaim.sourceforge.net/
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Exploit for Mozilla/Firefox/Thunderbird on Windows
Though my opinion has soured due to the lack of updates for the basic version,

http://www.trillian.cc
-C

 

Offline Lonestar

  • Fred Zone Guru
  • 27
    • United Gamers Coalition
Exploit for Mozilla/Firefox/Thunderbird on Windows
Quote
Originally posted by WMCoolmon
It was also much easier to fix than it would be using IE...didn't even have to restart.


You dont have to restart every time you update IE. Alot of times you dont have to restart windows XP at all. By the same token, ive never had to worry about 3rd party software being buggy or exploitable.
Why do people replace perfectly good working Windows programs with buggy 3rd party software?

I could understand if you used a non-windows OS, but on a windows system? Doesnt make much sense considering how easy it is to use IE and how stable it is.

Stop being a corporate guinea pig and just accept the good things we have! :D

 

Offline Kamikaze

  • A Complacent Wind
  • 29
    • http://www.nodewar.com
Exploit for Mozilla/Firefox/Thunderbird on Windows
Wait a second, you're calling Firefox/Mozilla users corporate guinea pigs? When you're advocating corporate products (from a monopoly too) in a thread about how this particular corporation has fscked up APIs?
Science alone of all the subjects contains within itself the lesson of the danger of belief in the infallibility of the greatest teachers in the preceding generation . . .Learn from science that you must doubt the experts. As a matter of fact, I can also define science another way: Science is the belief in the ignorance of experts. - Richard Feynman

 

Offline WMCoolmon

  • Purveyor of space crack
  • 213
Exploit for Mozilla/Firefox/Thunderbird on Windows
IE has no tabs, and Firefox just seems a lot more stable than it.

Plus it means if I ever use a non-Windows system, I already know a good browser that I can use.
-C

  

Offline karajorma

  • King Louie - Jungle VIP
  • Administrator
  • 214
    • Karajorma's Freespace FAQ
Exploit for Mozilla/Firefox/Thunderbird on Windows
Quote
Originally posted by Lonestar
Stop being a corporate guinea pig and just accept the good things we have! :D


I've already said (admittedly on the other mozilla thread) that I use Mozilla because it has features I like that IE doesn't have. It is also more secure. It is also more stable.

When I used IE I would find that it would lock up causing me to have to kill it from the task manager every few days.

With Mozilla I've had to do that twice in the last few months.

And yet you still claim that using IE would be a better choice?

What the **** are you on Lonestar? If new features aren't damn good reasons for using a different piece of software I don't know what is.  Tell me this, do you use WordPad for all your word procesing needs cause it too comes with the OS?
« Last Edit: July 13, 2004, 08:39:37 am by 340 »
Karajorma's Freespace FAQ. It's almost like asking me yourself.

[ Diaspora ] - [ Seeds Of Rebellion ] - [ Mind Games ]