Computerworld
Firefox also vulnerable to Windows cursor exploit
PCs with Firefox 2.0 more vulnerable than those with IE7
Gregg Keizer  04 April, 2007 09:03

Contrary to other reports, Mozilla's Firefox 2.0 is vulnerable to attackers armed with the Windows animated (ANI) cursor exploit, a researcher said Tuesday.

Alexander Sotirov, the vulnerability researcher at Determina who discovered the ANI flaw last December and notified Microsoft of it later that month, yesterday posted a demonstration of an ANI exploit that hijacks a PC when Firefox users are conned into visiting a malicious site.

"It turns out that Firefox uses the same vulnerable Windows component to process .ani files, which can be exploited in a way similar to Internet Explorer," Sotirov said during the demo.

He showed how both IE7 and Firefox 2.0, when run on a Vista-powered PC, can be hijacked by an attack using the ANI exploit he created in December as a vulnerability proof-of-concept, which he also shared with Microsoft's security team. When the attack was run against IE 7, the ANI exploit gave access to all files on the system. "However, we cannot alter any system files" because of IE's protected mode, which is enabled by default in Vista, said Sotirov.

Vista's version of IE7 runs in a low-privilege mode -- dubbed "protected mode" by Microsoft -- that blocks disk write access to all but a temporary files folder.

An identical attack against Firefox 2.0, however, gave Sotirov complete and total access to the PC's drive. "Since Firefox does not have a low-privilege mode, similar to the protected mode in IE, we'll be able to overwrite files as well," he said.

Third-party security vendors have claimed that Firefox 2.0 is not vulnerable. In a threat alert to its DeepSight customers, Symantec flatly stated "Mozilla Firefox is not vulnerable to the vulnerability."

Not so, said Sotirov. "The reason for the confusion over Firefox is that an exploit that works against it has not become public. So in a sense, since there are no attacks in the wild [that work in Firefox], it is safer. But people should also consider that the bad guys will figure out how to exploit Firefox."

Mozilla did not respond to requests for comment about Firefox's risk of exploitation, or confirmation that it is vulnerable.

So far this year, Mozilla has issued 10 Firefox patches.

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Top 10 Ways to Increase IT ROI Without Adding Staff

Today, IT managers are looking for alternative strategies to increase their IT ROI. The first principle is: Simplify operations. Read this white paper for 10 specific strategies for increasing IT ROI.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.