Thought you where safe with Opera/Firefox/Mozilla/Konqueror?

GEC: Discuss gaming, computers and electronics and venture into the bizarre world of STGODs.

Moderator: Thanas

User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Thought you where safe with Opera/Firefox/Mozilla/Konqueror?

Post by Faram »

Forget it ALL major browsers are at risk from this new vulnerability.
Introduction

Secunia Research has reported a vulnerability, which affects most browsers. The vulnerability can be exploited by a malicious web site to "hi-jack" a named browser window, regardless of which web site is the true "owner" of the window.

Please use the test below, to see an example of how this vulnerability can be exploited, and also to determine whether or not your browser is vulnerable.
Demo

This is one fucked up vulnerability, one of the worst I have seen EVER!
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Dalton
For Those About to Rock We Salute You
For Those About to Rock We Salute You
Posts: 22639
Joined: 2002-07-03 06:16pm
Location: New York, the Fuck You State
Contact:

Post by Dalton »

BUMP

Thank you Faram!
Image
Image
To Absent Friends
Dalton | Admin Smash | Knight of the Order of SDN

"y = mx + bro" - Surlethe
"You try THAT shit again, kid, and I will mod you. I will
mod you so hard, you'll wish I were Dalton." - Lagmonster

May the way of the Hero lead to the Triforce.
User avatar
White Cat
Padawan Learner
Posts: 212
Joined: 2002-08-29 03:48pm
Location: A thousand km from the centre of the universe
Contact:

Post by White Cat »

I'm using Firefox 0.9.2, and according to that test, I'm not vulnerable.
LISTEN TO MY LOUSY ANIME SONG
Pcm979
Rabid Monkey
Posts: 4092
Joined: 2002-10-26 12:45am

Post by Pcm979 »

Well, I'm safe. Firefox rox.
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Pcm979 wrote:Well, I'm safe. Firefox rox.
NO YOU ARE NOT SAFE!!!!

Follow the link.

Left Click the first link named "Test Now - With Pop-up Blocker - Left Click On This Link"

On the new page click the Consumer Alert picture

This is the danger with this one!

All large browsers are unsafe from this ALL!

Image
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Sir Sirius
Sith Devotee
Posts: 2975
Joined: 2002-12-09 12:15pm
Location: 6 hr 45 min R.A. and -16 degrees 43 minutes declination

Post by Sir Sirius »

I'm running Firefox 1.0, tried both of the links, did just as the instructions said and got a pop-up titled Learn About Spoofs on both occasions, not the Secunia pop-up Faram posted a picture of.
The pop-up wrote:Every Internet user should know about spoof (a.k.a. phishing or hoax) e-mails that appear to be from a well-known company but can put you at risk.
Ok, I just tried four more times and got the same results... maybe it's broken or something.
Image
User avatar
Sir Sirius
Sith Devotee
Posts: 2975
Joined: 2002-12-09 12:15pm
Location: 6 hr 45 min R.A. and -16 degrees 43 minutes declination

Post by Sir Sirius »

Now I can't access the Secunia website at all. Considering that and the fact that this is supposed to work on Firefox, which it didn't do for me, I am starting to think that there really is something wrong with the Secunia site.

A "safe" result might not mean that you are safe after all.

EDIT: I just got the Secunia page to work again and tried once more... and got the Secunia pop-up Faram posted a picture of :( , even though it didn't work on previous attempts.
Image
User avatar
SecondStorm
Jedi Knight
Posts: 562
Joined: 2002-09-20 08:06pm
Location: Denmark

Post by SecondStorm »

I use Mozilla Firefox 1.0 and I got no pop-up. It appears Im safe after all.
User avatar
Sir Sirius
Sith Devotee
Posts: 2975
Joined: 2002-12-09 12:15pm
Location: 6 hr 45 min R.A. and -16 degrees 43 minutes declination

Post by Sir Sirius »

SecondStorm wrote:I use Mozilla Firefox 1.0 and I got no pop-up. It appears Im safe after all.
Try it again a few times with both links and with out opening the links in a new tab, just click them regulary. Thats how I got it to work.
Image
User avatar
Darth Wong
Sith Lord
Sith Lord
Posts: 70028
Joined: 2002-07-03 12:25am
Location: Toronto, Canada
Contact:

Post by Darth Wong »

I've tested this on Firefox 1.0. It works.
Image
"It's not evil for God to do it. Or for someone to do it at God's command."- Jonathan Boyd on baby-killing

"you guys are fascinated with the use of those "rules of logic" to the extent that you don't really want to discussus anything."- GC

"I do not believe Russian Roulette is a stupid act" - Embracer of Darkness

"Viagra commercials appear to save lives" - tharkûn on US health care.

http://www.stardestroyer.net/Mike/RantMode/Blurbs.html
User avatar
2000AD
Emperor's Hand
Posts: 6666
Joined: 2002-07-03 06:32pm
Location: Leeds, wishing i was still in Newcastle

Post by 2000AD »

No pop up. i'm safe apparently
Ph34r teh eyebrow!!11!Writers Guild Sluggite Pawn of Chaos WYGIWYGAINGW so now i have to put ACPATHNTDWATGODW in my sig EBC-Honorary Geordie
Hammerman! Hammer!
User avatar
Sharp-kun
Sith Devotee
Posts: 2993
Joined: 2003-09-10 05:12am
Location: Glasgow, Scotland

Post by Sharp-kun »

I'm using Firefox 1.0 and got the problem.
User avatar
Vohu Manah
Jedi Knight
Posts: 775
Joined: 2004-03-28 07:38am
Location: Harford County, Maryland
Contact:

Post by Vohu Manah »

The latest Safari didn't bring up the Secunia pop-up, but the latest Camino (a Mozilla-variant) did.
There are two kinds of people in the world: the kind who think it’s perfectly reasonable to strip-search a 13-year-old girl suspected of bringing ibuprofen to school, and the kind who think those people should be kept as far away from children as possible … Sometimes it’s hard to tell the difference between drug warriors and child molesters.” - Jacob Sullum[/size][/align]
User avatar
Terr Fangbite
Padawan Learner
Posts: 363
Joined: 2004-07-08 12:21am

Post by Terr Fangbite »

tested on latest mozilla, I got nothing for both links.
Beware Windows. Linux Comes.
http://ammtb.keenspace.com
Pcm979
Rabid Monkey
Posts: 4092
Joined: 2002-10-26 12:45am

Post by Pcm979 »

Faram wrote:NO YOU ARE NOT SAFE!!!!
Yes I am!11!! I did the fucking test!1!!
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Pcm979 wrote:
Faram wrote:NO YOU ARE NOT SAFE!!!!
Yes I am!11!! I did the fucking test!1!!
Well what Firefox are you running?

And have you appplied any patch for this?
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Enigma
is a laughing fool.
Posts: 7777
Joined: 2003-04-30 10:24pm
Location: c nnyhjdyt yr 45

Post by Enigma »

With the pop up blocker I get the Secunia window. Without the pop up blocker I get the citibank window.
ASVS('97)/SDN('03)

"Whilst human alchemists refer to the combustion triangle, some of their orcish counterparts see it as more of a hexagon: heat, fuel, air, laughter, screaming, fun." Dawn of the Dragons

ASSCRAVATS!
User avatar
Soontir C'boath
SG-14: Fuck the Medic!
Posts: 6860
Joined: 2002-07-06 12:15am
Location: Queens, NYC I DON'T FUCKING CARE IF MANHATTEN IS CONSIDERED NYC!! I'M IN IT ASSHOLE!!!
Contact:

Post by Soontir C'boath »

The first two times it showed the Secunia pop-up but after that, it showed the regular pop-up from Citi-bank.
Edit: and back again. Anyway, I got the spoof-stick to show where the site is coming from.
I have almost reached the regrettable conclusion that the Negro's great stumbling block in his stride toward freedom is not the White Citizen's Counciler or the Ku Klux Klanner, but the white moderate, who is more devoted to "order" than to justice; who constantly says: "I agree with you in the goal you seek, but I cannot agree with your methods of direct action"; who paternalistically believes he can set the timetable for another man's freedom; who lives by a mythical concept of time and who constantly advises the Negro to wait for a "more convenient season."
Pcm979
Rabid Monkey
Posts: 4092
Joined: 2002-10-26 12:45am

Post by Pcm979 »

Faram wrote:
Pcm979 wrote:
Faram wrote:NO YOU ARE NOT SAFE!!!!
Yes I am!11!! I did the fucking test!1!!
Well what Firefox are you running?

And have you appplied any patch for this?
Version 1.0, with pop-up blockers. Yes, I did the test for people with pop-up blockers.
Asst. Asst. Lt. Cmdr. Smi
What Kind of Username is That?
Posts: 9254
Joined: 2002-07-10 08:53pm
Location: Back in PA

Post by Asst. Asst. Lt. Cmdr. Smi »

I'm using IE right now, and after trying with and without pop-up blocker, my computer is apparently safe.
BotM: Just another monkey|HAB
User avatar
Faram
Bastard Operator from Hell
Posts: 5271
Joined: 2002-07-04 07:39am
Location: Fighting Polarbears

Post by Faram »

Pcm979 wrote:Version 1.0, with pop-up blockers. Yes, I did the test for people with pop-up blockers.
Then you are vulnerable.

Image

There might be somthing in the network or some other setting in you computer that is affecting this but Firefox 1.0 is not safe from this attack.
[img=right]http://hem.bredband.net/b217293/warsaban.gif[/img]

"Either God wants to abolish evil, and cannot; or he can, but does not want to. ... If he wants to, but cannot, he is impotent. If he can, but does not want to, he is wicked. ... If, as they say, God can abolish evil, and God really wants to do it, why is there evil in the world?" -Epicurus


Fear is the mother of all gods.

Nature does all things spontaneously, by herself, without the meddling of the gods. -Lucretius
User avatar
Beowulf
The Patrician
Posts: 10621
Joined: 2002-07-04 01:18am
Location: 32ULV

Post by Beowulf »

If there is more than one tab open in a window, it doesn't work in Firefox. Try it. Click the link to open the citibank website in a new window. Hit Ctrl+T. Then click the image. The citi-bank window shows up properly.

At least, I think that's how it's working...
"preemptive killing of cops might not be such a bad idea from a personal saftey[sic] standpoint..." --Keevan Colton
"There's a word for bias you can't see: Yours." -- William Saletan
Pcm979
Rabid Monkey
Posts: 4092
Joined: 2002-10-26 12:45am

Post by Pcm979 »

Faram wrote:
Pcm979 wrote:Version 1.0, with pop-up blockers. Yes, I did the test for people with pop-up blockers.
Then you are vulnerable.
How many fucking times do I have to tell you? I did the test. I'm safe.
User avatar
Mad
Jedi Council Member
Posts: 1923
Joined: 2002-07-04 01:32am
Location: North Carolina, USA
Contact:

Post by Mad »

Pcm979 wrote:
Faram wrote:
Pcm979 wrote:Version 1.0, with pop-up blockers. Yes, I did the test for people with pop-up blockers.
Then you are vulnerable.
How many fucking times do I have to tell you? I did the test. I'm safe.
Did you click on the spoofing thing? I'm using Firefox 1.0 and when I clicked on the Citibank web site. Then, on the Citibank web site, I clicked on the consumer alert graphic, and I got the Secunia warning. Firefox 1.0 is not safe from the security hole.
Later...
Pcm979
Rabid Monkey
Posts: 4092
Joined: 2002-10-26 12:45am

Post by Pcm979 »

Argh! I am not stupid! I DID THE TEST! 3 TIMES! I AM SAFE!
Post Reply