HardwareHeaven.com

HardwareHeaven.com

Looking for the skin chooser?
 
 
  • Home

  • Hardware reviews

  • Articles

  • News

  • Tools

  • Gaming at HardwareHeaven

  • Forums

 

Go Back   HardwareHeaven.com > Forums > News > Other Tech News


Other Tech News The latest community based technology news from across the globe. (If you aren't a community newsposter then use the "Submit News" section.)

Reply
 
Thread Tools
Old Oct 1, 2006, 02:18 PM   #1
DriverHeaven Extreme Member
 
Iria's Avatar
 
Join Date: Apr 2004
Posts: 7,275
Rep Power: 89
Iria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seenIria has a divinity and aura the likes we have never seen

Hackers claim zero-day flaw in Firefox

Source: News.com
______
SAN DIEGO, Calif.--The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon.

An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said.
Iria is offline   Reply With Quote


Old Oct 1, 2006, 04:12 PM   #2
DriverHeaven Senior Member
 
TheBlackCat's Avatar
 
Join Date: Jul 2006
Location: Searching for the Candle in the Dark
Posts: 567
Rep Power: 0
TheBlackCat is an unknown quantity at this point

Looks like it is finally time to install scriptblock.

These guys are serious evil people, though. Laughing in the face of someone asking you merely not hurt other people, instead telling him that is precisely your plan and there is nothing he can do to stop you. Just evil, there is no other way to describe it.
__________________
[color=#000000]There is always an easy solution to every human problem—neat, plausible and wrong.[/color]
-H. L. Mencken


TheBlackCat is offline   Reply With Quote
Old Oct 1, 2006, 05:16 PM   #3
Mostly lurking lately....
 
Rayder's Avatar
 
Join Date: Jun 2002
Location: U.S.A.
Posts: 2,161
Rep Power: 73
Rayder is just super!Rayder is just super!Rayder is just super!Rayder is just super!Rayder is just super!Rayder is just super!Rayder is just super!

It seems to me that the authorities should storm these "hacker conventions" and bust them all.

Treat them as world terrorists. I'm sure not ALL of them are evil, but if they know something, they should be FORCED to disclose that info or risk some jail time.

Maybe I'm just not understanding something that allows those people to hold conventions for hacking.....
Rayder is offline   Reply With Quote
Old Oct 2, 2006, 01:05 AM   #4
Apple Fanboy?
 
dj_stick's Avatar
 
Join Date: Jun 2003
Location: Basement of the first floor
Posts: 17,485
Rep Power: 190
dj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his statusdj_stick is godlike in his status
System Specs

it's better they find the flaws and let us + the companies know rather than releasing exploits…
__________________
Chris - The Aussie Super Mod
Hardwareheaven Rules - Sig Request Thread

How you can help HardwareHeaven by using Digg!

Hardwareheaven Super-Moderator

Quote:
Originally Posted by OmegaRED View Post
You know, there's "off topic" and then there's so freakin' off topic it you gotta wear a straitjacket to join the conversation.
dj_stick is offline   Reply With Quote
Old Oct 2, 2006, 01:44 AM   #5
DriverHeaven Senior Member
 
TheBlackCat's Avatar
 
Join Date: Jul 2006
Location: Searching for the Candle in the Dark
Posts: 567
Rep Power: 0
TheBlackCat is an unknown quantity at this point

That's the point. They want to release exploits because they want to hackers to attack people. They are not doing this in spite of the fact that it might be used by hackers, they are doing it with the express purpose of getting hackers to use it for malicious purposes.
__________________
[color=#000000]There is always an easy solution to every human problem—neat, plausible and wrong.[/color]
-H. L. Mencken


TheBlackCat is offline   Reply With Quote
Old Oct 2, 2006, 12:28 PM   #6
Anti-Piracy Poster Boy
 
YAYitsAndrew's Avatar
 
Join Date: Oct 2004
Location: NJ
Posts: 2,605
Rep Power: 79
YAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seen
System Specs

One thing that's nice about this is that it will shut up those firefox diehards that think their browser is any safer than IE. The exploits go where the marketshare is going.

If you want to use the most secure browser right now, then that is Opera. Secunia's advisory reports from the last two years will tell you this and those are hard facts.

You can use firefox for the plugins, or because all your friends are using it and you think it makes you cool, but you can't use it and make fun of IE for being insecure. Not when you aren't using the most secure web browser to date.

www.opera.com
__________________
"It is because the resistance to paying for copyrighted material, although often characterized as arising from a supposed technical burden or principled concern for the public interest, arises rather from exactly the same segment of the brain that is dominant in shoplifters."
- Mark Helprin, Digital Barbarism

In other words, it's never okay to steal even if you think you have a good reason!

www.yayitsandrew.com
YAYitsAndrew is offline   Reply With Quote
Old Oct 2, 2006, 05:54 PM   #7
Get off my lawn!
 
Erroneus's Avatar
 
Join Date: Aug 2002
Location: Denmark
Posts: 13,417
Rep Power: 119
Erroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seenErroneus has a divinity and aura the likes we have never seen
System Specs

Quote:
Originally Posted by YAYitsAndrew View Post
One thing that's nice about this is that it will shut up those firefox diehards that think their browser is any safer than IE.
Ehm no it will not shut us up and you want to know why? Because MS is about avg. 10 days to fix a critically flaw, while Mozilla does it in 1 day (Opera two days). There will always be flaws in Firefox, and since it's open source, hackers can easly scope for flaws, but at the same time it also means that bugs can be fixed fast.

I agree though Opera is more secure, to bad it doesn't have the same extension possibilities as Firefox.
__________________
Erroneus is offline   Reply With Quote
Old Oct 2, 2006, 06:42 PM   #8
HH's Nokia shareholder!
 
Join Date: Dec 2004
Location: Vantaa, Finland
Posts: 7,841
Rep Power: 147
temeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refutetemeteus82 has a reputation beyond refute
System Specs

Hmm... this might bee the reason that I get po-ups in firefox that some programs want to use my dial-up link to go online :P
__________________
Quote:
Originally Posted by dj_stick View Post
no, stupidity is a WMD in itself
temeteus82 is online now   Reply With Quote
Old Oct 2, 2006, 08:43 PM   #9
DriverHeaven Senior Member
 
Join Date: Mar 2003
Posts: 332
Rep Power: 0
ChrisW is on a distinguished road

exclamation

These people are not finding an existing flaw in the software. They are devising a new way to exploit the software. They are not trying to help us by exposing a flaw to be fixed. The fact of the matter is there is an infinite number of ways to exploit the software, no matter how well written. The problem is not that holes exist...the problem is the fact that there are people looking for new ways to exploit the software. The hackers are the problem, not the solution.
ChrisW is offline   Reply With Quote
Old Oct 2, 2006, 11:14 PM   #10
Anti-Piracy Poster Boy
 
YAYitsAndrew's Avatar
 
Join Date: Oct 2004
Location: NJ
Posts: 2,605
Rep Power: 79
YAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seenYAYitsAndrew has a divinity and aura the likes we have never seen
System Specs

Quote:
Originally Posted by Erroneus View Post
Ehm no it will not shut us up and you want to know why? Because MS is about avg. 10 days to fix a critically flaw, while Mozilla does it in 1 day (Opera two days). There will always be flaws in Firefox, and since it's open source, hackers can easly scope for flaws, but at the same time it also means that bugs can be fixed fast.
Your numbers seem a little off from secunia's reports. Opera tends to fix the highest risk vulnerabilities faster than firefox despite being closed source.
http://www.webdevout.net/security_summary.php

Like I said in another thread about this though, the numbers for firefox and opera are too close to really mean anything. The only conclusion I can come to is that when it comes to security, open source and closed source make very little difference with the right team. (I suppose IE has the wrong team)
__________________
"It is because the resistance to paying for copyrighted material, although often characterized as arising from a supposed technical burden or principled concern for the public interest, arises rather from exactly the same segment of the brain that is dominant in shoplifters."
- Mark Helprin, Digital Barbarism

In other words, it's never okay to steal even if you think you have a good reason!

www.yayitsandrew.com
YAYitsAndrew is offline   Reply With Quote
Reply

Thread Tools