[pchelpers] News:Phishers Lurk For Firefox 2.0 Password Manager

  November 22, 2006
By Sean Michael Kerner
Using Mozilla Firefox's built-in Password Manager to keep track of your 
browser's passwords? It makes site logins faster but it also could help 
malicious sites steal your passwords.

The bug, which has been known to Mozilla for at least 10 days, remains 
unpatched and exploits as well as a proof of concept exist in the wild.

"I was shocked today to find an in-the-wild phish that uses nothing more 
than cross-site forms, and also extracts information from the Password 
Manger!" Security Researcher Robert Chapin wrote in a November 12tth 
e-mail posted in the bugzilla bug tracking system.

"The underlying method was so obvious that it should have raised 
multiple warnings," Chapin continued. "There were none at all."

More here:
http://www.internetnews.com/security/article.php/3645396
-- 
Regards, John Durham <http://modecideas.com/contact.html?sig>
ICQ number 112663246
Fax/Phone 64 4 5286786
Award winning web site at http://modecideas.com?sig
Order my latest e-book at http://modecideas.com/dmaxhits.htm?sig
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Good advice is like good paint- it only works if applied.



-- 
-------list-services-below-----------
Regards, John Durham (list moderator) <http://modecideas.com/contact.html?sig>
Freelists login at http://www.freelists.org/cgi-bin/lsg2.cgi
List archives at http://www.freelists.org/archives/pchelpers
PC-HELPERS list subscribe/unsub at http://modecideas.com/discuss.htm?sig
Latest news live feeds at http://modecideas.com/indexhomenews.htm?sig
Good advice is like good paint- it only works if applied.

Other related posts: