[pchelpers] News:Phishers Lurk For Firefox 2.0 Password Manager
- From: John Durham <john.modec@xxxxxxxxxx>
- To: PC-Helpers <pchelpers@xxxxxxxxxxxxx>
- Date: Thu, 23 Nov 2006 07:36:34 +1300
November 22, 2006
By Sean Michael Kerner
Using Mozilla Firefox's built-in Password Manager to keep track of your
browser's passwords? It makes site logins faster but it also could help
malicious sites steal your passwords.
The bug, which has been known to Mozilla for at least 10 days, remains
unpatched and exploits as well as a proof of concept exist in the wild.
"I was shocked today to find an in-the-wild phish that uses nothing more
than cross-site forms, and also extracts information from the Password
Manger!" Security Researcher Robert Chapin wrote in a November 12tth
e-mail posted in the bugzilla bug tracking system.
"The underlying method was so obvious that it should have raised
multiple warnings," Chapin continued. "There were none at all."
More here:
http://www.internetnews.com/security/article.php/3645396
--
Regards, John Durham <http://modecideas.com/contact.html?sig>
ICQ number 112663246
Fax/Phone 64 4 5286786
Award winning web site at http://modecideas.com?sig
Order my latest e-book at http://modecideas.com/dmaxhits.htm?sig
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Good advice is like good paint- it only works if applied.
--
-------list-services-below-----------
Regards, John Durham (list moderator) <http://modecideas.com/contact.html?sig>
Freelists login at http://www.freelists.org/cgi-bin/lsg2.cgi
List archives at http://www.freelists.org/archives/pchelpers
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Latest news live feeds at http://modecideas.com/indexhomenews.htm?sig
Good advice is like good paint- it only works if applied.
Other related posts:
- » [pchelpers] News:Phishers Lurk For Firefox 2.0 Password Manager