Recently, two dangerous unpatched Javascript flaws have been found. Furthermore, the unpatched extremely critical security holes and exploit code has already been circulating on the Internet, according to sources.
The exploit, discovered by Paul of Greyhats Security Group and Michael “mikx” Krax, makes use of two separate vulnerabilities. An attacker could create a malicious page using frames and a JavaScript history flaw to make software installations appear to be coming from a “trusted” site. By default, Firefox allows software installations from update.mozilla.org and addons.mozilla.org, but users can add their own sites to this whitelist.
Mozilla Foundation confirmed that users may be vulnerable if they have added other sites to the whitelist. In other words, if you did not add in any site into the software installation whitelist, you are safe from this issue.
Anyway, firefox user can save yourself while waiting for the patch to be released by Mozilla Foundation, by switching off JavaScript in the meantime.
The following are steps to swich off JavaScript:-
1. Go to Tools, then click Options….
2. Select Web Features on the left panel.
3. Deselect the Enable JavaScript box.
[Source]
Blogsphere: TechnoratiFeedsterBloglines
Bookmark: Del.icio.usSpurlFurlSimpyBlinkDigg
RSS feed for comments on this post
Best Deal Ads :
Recent Posts :
New Blog DesignLogitech Going 64Bit Too
iDog
Intel Lost The Dual-Core War ??
Install WinXP x64, PC Warranty Voided?
Google & Yahoo! Compete For Video Searching
LCD Monitor Price Is Going Up
History Of Apple Ipod
Oh, Heart Broken ...
Alienware Released Star Wars PC
Related Posts :
History of Mozilla Firefox
History of Firefox From Phoenix 0.1 - 0.3 then Phoenix 0.4 -...
FireFox 1.0.3 Released !!
Hey guys, Get the latest FireFox 1.0.3 now. You can always check...
Firefox Hit The 90 Million Mark !!
With the help of so many Mozilla Firefox supports, Mozilla...
FireFox 1.0.7 Released
While we are still talking about the free Opera web...
Firefox 1.0.6 Released
As I've just mentioned yesterday, you do not have to...
















Darn it!! My FireFox is having this prob right now. Norton detected Trojan alert. WTF!!
Hopefully new FireFox update will release ASAP!!
Opss… Sorry to hear that.
As long as, you did not add in any other site other than the two Mozzila Original sites, you are not at risk for the JavaScript flaws.
Hope a patch is coming out really soon.