Welcome Guest ( Log In | Register)



 
Reply to this topicStart new topic
> Hackers Focus Efforts On Firefox, Safari, And Office
Saint_Michael
post Apr 26 2008, 06:08 AM
Post #1


$p4m 0n j00 $h4m3 m3 0nc3 $p4m 0n m3 $h4m3 m3 7\/\/1c3
*********************

Group: [HOSTED]
Posts: 6,059
Joined: 21-September 04
From: 9r33|\| 399$ 4|\|D 5P4/\/\
Member No.: 1,218
T17 GFX Crew



QUOTE
Many people are switching from Internet Explorer to alternative browsers such as Firefox and Safari. Though that might make them feel more secure, the shift has also opened new doors for bad guys.

Case in point: We have no IE bugs to report this month, but both Firefox and Safari have been hit hard.

So forget the idea that just because you've switched to a new browser, you're magically safer. You may be for a time, but to stay safe with any software, you need to keep current with fixes.
Firefox Holes

In a somewhat dubious recognition of Firefox's growing popularity, hackers have focused their attention on it, leading to a rash of newly discovered holes. The folks at Mozilla recently released two Firefox updates in less than six weeks, fixing a total of five critical security vulnerabilities. All five can be exploited by planting a poisoned JavaScript file in a Web site and waiting for you to stumble across it.

In an actual attack--neither the Safari nor the Firefox bugs have elicited one so far--a bad guy could take over your PC or steal your navigation history.

The latest versions of Firefox--2.0.0.13 on--will stop all five bugs. Mozilla's Thunderbird and SeaMonkey are also at risk (if you have JavaScript enabled), so download updated versions.
Safari in the Wild

Safari 3.1 patches 13 holes affecting Mac OS X, Windows XP, and Windows Vista.

Think you're safe because you don't have Safari? You may have it without realizing it. Apple now distributes its browser with iTunes updates. Forget to uncheck a box in one of these updates, and it's there.

The Safari holes could allow an attacker to trick you into thinking that a fake site is really your bank site, or to take over your PC via a poisoned page. Download Safari 3.1.
Office Bugged Again

Microsoft recently released four patches that fix a dozen dangerous holes in Office. I warned you about one of those holes--a zero-day attack on Excel--in April. Be sure to apply the patches, if your system doesn't install them automatically. Get the four new Office patches and more info. (You are not affected if Microsoft Office 2007 is the version you use.)

No sooner had Microsoft shipped those patches than the company acknowledged the existence of yet another bad Office bug that needs patching. And this one is urgent because some users have already been attacked.

Luckily, Windows Vista, Windows Vista SP1, and the beta version of Windows XP SP3 are not at risk because they ship with a newer version of the affected "Jet" database. But earlier versions of Windows are vulnerable, as are all supported versions of Office, including Office 2007.

Becoming a victim of the bug involves saving two files to your PC's hard drive--one a mail-merge file that uses the database engine. There was no patch at press time. For more information, read Microsoft's advisory.


Well no wonder we had those two new Firefox versions so quickly, but I wonder if that will push back Firefox 3's release date at all because of those big security holes that have been found. Well I figured it would just be a matter of time before Firefox started to have its underground hackers go after it and so I would assume that Firefox 3 will be receiving a lot of updates once the final version is release. Of course, I can't talk about this without mentioning the other side that the mozilla team has spent about two years and some change on this version of the browser, but to do an 180 once again, they mostly focus on the memory issues that I am aware of so there could be some security holes they they might have missed.

As with safari I am not surprise just because they lack a lot of the security features needed to have a secured browser, but I guess after these attacks Apple will be thinking about adding some security stuff to safari in later editions. The same with Office as that software has always had security holes in them, reminds me though that I should update office 2003 on my vista computer just to make sure about that.


This post has been edited by Saint_Michael: May 4 2008, 11:07 PM
Go to the top of the page
 
+Quote Post
bluedragon
post Apr 26 2008, 06:36 PM
Post #2


Newbie [Level 3]
***

Group: Members
Posts: 46
Joined: 24-April 08
Member No.: 61,260



Thanks for the info m8. biggrin.gif

But I am going to stick with Mozilla.. I think My IE is somehow corrupted.. (I was experimenting with something when it just sort of ate my IE)



I think its not much of a deal if you are careful with what you are downloading and running on the internet wink.gif. but then Ofcourse most of us just press Yes/Okay to almost every alert that we see.. laugh.gif


I've listed two articles for ppl interested to see how the Vulnerabilities work ..


1.)http://sunbeltblog.blogspot.com/2006/04/ps...exploit-in.html

2.)http://www.theregister.co.uk/2005/05/09/fi...x_0day_exploit/

This post has been edited by bluedragon: Apr 26 2008, 06:45 PM
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

Collapse

> Similar Topics

Topics Topics
  1. Phpbb Hackers(21)
  2. Status Bar Spoofing In Firefox(10)
  3. Another Firefox Security Update(6)
  4. ? Doesn't G-mail Notifier Work Wit Firefox?(15)
  5. Critical Firefox Exploits(16)
  6. Firefox Has A Big Time Security Flaw(3)
  7. Firefox 1.0.7(14)
  8. Firefox 1.5 Flaws(22)
  9. Firefox Exploit(0)
  10. Zero-day Firefox Exploit(5)
  11. Windows Crashing. Can't Use Opera Or Firefox(3)
  12. Myspace Has A Team Of Hackers(7)
  13. Spammers, Hackers Seize On Virginia Tech Shootings(3)
  14. Microsoft Update Program Being Used By Hackers(6)
  15. Interesting New Ie - Firefox Bug ( A Must Read Asap)(3)
  1. Firefox Flaws Galore(7)
  2. Is There An Exploit In Vista Home Premium To Make Firefox Permanant Default Browser?(4)
  3. Opera, Firefox Bug Could Reveal Web Travels(0)
  4. Mozilla: Firefox Plugin Shipped With Malicious Code(2)


 



- Lo-Fi Version Time is now: 12th May 2008 - 10:29 PM