<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; firefox exploit</title> <atom:link href="http://www.ghacks.net/tag/firefox-exploit/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Fri, 10 Feb 2012 20:51:26 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>0-Day Firefox 3.6 Vulnerability Emerges</title><link>http://www.ghacks.net/2010/10/27/0-day-firefox-3-6-vulnerability-emerges/</link> <comments>http://www.ghacks.net/2010/10/27/0-day-firefox-3-6-vulnerability-emerges/#comments</comments> <pubDate>Wed, 27 Oct 2010 16:05:08 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[firefox exploit]]></category> <category><![CDATA[firefox security]]></category> <category><![CDATA[firefox vulnerability]]></category> <category><![CDATA[symantec.exe]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=36288</guid> <description><![CDATA[The official Nobel Prize website was hacked yesterday, and for some time ran an exploit targeting a new 0-day vulnerability in the Firefox browser. According to our information, the exploit was used to install a backdoor on the user&#8217;s computer system without notifications or warning messages. The backdoor tries to retrieve the path of the [...]]]></description> <content:encoded><![CDATA[<p>The official Nobel Prize website was hacked yesterday, and for some time ran an exploit targeting a new 0-day vulnerability in the Firefox browser. According to our information, the exploit was used to install a backdoor on the user&#8217;s computer system without notifications or warning messages.</p><p>The backdoor tries to retrieve the path of the Windows directory to copy the file symantec.exe to %WINDIR%\temp\symantec.exe. Once the file is created there, autostart keys are added to the Windows Registry to load the file on system startup. The keys are added both to the user and local machine parts of the Registry, and the reg command is used to add them.</p><p>The program then tries to create two connections to Internet servers, namely to nobel.<host>.mooo.com and update.microsoft.com. After these initial connections it tries to connect to two additional servers, both of which appear to be offline currently. If they are offline, the malware stops executing and exits.</p><p>On a successful connection, the malware opens a shell and the attacker can access the local computer with the same rights the malware was executed with.</p><p>Mozilla appears to be aware of the vulnerability and is developing a patch to protect the browser from the vulnerability. (<a
href="http://techblog.avira.com/2010/10/27/new-firefox-exploit-in-the-wild/en/">via</a>)</p><p>Update: Office Mozilla <a
href="http://blog.mozilla.com/security/2010/10/26/critical-vulnerability-in-firefox-3-5-and-firefox-3-6/">Response</a> Up, suggest to disable JavaScript to protect the browser from the vulnerability.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/10/27/0-day-firefox-3-6-vulnerability-emerges/feed/</wfw:commentRss> <slash:comments>11</slash:comments> </item> <item><title>Critical Security Vulnerability In Firefox 3.5</title><link>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/</link> <comments>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/#comments</comments> <pubDate>Wed, 15 Jul 2009 12:01:02 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[firefox exploit]]></category> <category><![CDATA[firefox patch]]></category> <category><![CDATA[firefox vulnerability]]></category> <category><![CDATA[mozilla-firefox]]></category> <category><![CDATA[security patch]]></category> <category><![CDATA[web browser]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=14412</guid> <description><![CDATA[A critical security vulnerability affecting Firefox 3.5 has been discovered and published on the security portal Milw0rm entitled Firefox 3.5 Heap Spray Vulnerability. A proof of concept exploit has been provided. In short, the vulnerability can lead to remote code execution. The good news is that a security patch has already been published by Mozilla [...]]]></description> <content:encoded><![CDATA[<p><img
src="http://www.ghacks.net/wp-content/uploads/2009/06/firefox.png" alt="firefox" title="firefox" width="128" height="128" class="alignleft size-full wp-image-13848" />A critical security vulnerability affecting Firefox 3.5 has been discovered and published on the security portal Milw0rm entitled Firefox 3.5 Heap Spray Vulnerability. A proof of concept exploit has been provided. In short, the vulnerability can lead to remote code execution. The good news is that a security patch has already been published by <a
href="http://mozillalinks.org/wp/2009/07/mozilla-confirms-critical-security-flaw-in-firefox-3-5/">Mozilla Links</a>.</p><p>The security vulnerability can be fixed the following way. Type in about:config in the Firefox address bar and hit enter. Now filter for the term <strong>javascript.options.jit.content</strong> and double-click it afterwards to set it to false which disables the Tracemonkey JavaScript engine. This in turn could (and most likely will) reduce the JavaScript performance of the Firefox 3.5 web browser until an official security patch is provided by the Mozilla Firefox team.</p><p><span
id="more-14412"></span>The security patch is expected to be released soon by the Firefox development team. Stay tuned, we keep you updated.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/07/15/critical-security-vulnerability-in-firefox-3-5/feed/</wfw:commentRss> <slash:comments>10</slash:comments> </item> <item><title>Latest Firefox Web Browser Vulnerable to 0-Day Exploit</title><link>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/</link> <comments>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/#comments</comments> <pubDate>Thu, 26 Mar 2009 14:32:58 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Browsing]]></category> <category><![CDATA[Firefox]]></category> <category><![CDATA[firefox 3]]></category> <category><![CDATA[firefox bu]]></category> <category><![CDATA[firefox exploit]]></category> <category><![CDATA[firefox security]]></category> <category><![CDATA[firefox vulnerability]]></category> <category><![CDATA[mozilla-firefox]]></category> <category><![CDATA[web browser]]></category> <guid
isPermaLink="false">http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/</guid> <description><![CDATA[Dante send me a tip about a 0-day exploit that is affecting the latest versions of the popular Firefox web browser. The exploit is described as a remote memory-corruption vulnerability that is affecting Firefox running on all supported operating systems. A proof of concept has been published by the security researcher and the Mozilla team [...]]]></description> <content:encoded><![CDATA[<p>Dante send me a tip about a 0-day exploit that is affecting the latest versions of the popular Firefox web browser. The exploit is described as a remote memory-corruption vulnerability that is affecting Firefox running on all supported operating systems. A proof of concept has been published by the security researcher and the Mozilla team has acknowledged the existence and announced plans to rush a Firefox 3.0.8 update at the beginning of next week.</p><p>The Firefox exploit could be used to add software to the target system without the knowledge of the users. There is currently no solution to block this attack from being executed other than being very careful about the visited websites. The safest would be to switch to another web browser at least for the time until the Mozilla developers have published the update that fixes the vulnerability in the web browser or a hot fix becomes known.</p><p>The issue has already been fixed <a
href="https://bugzilla.mozilla.org/show_bug.cgi?id=485217">according</a> to the bug report that was filed at the Mozilla website and is now awaiting verification.</p><p><span
id="more-11482"></span></p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2009/03/26/latest-firefox-web-browser-vulnerable-to-0-day-exploit/feed/</wfw:commentRss> <slash:comments>4</slash:comments> </item> </channel> </rss>
