Search Perform an advanced search query SOFTPEDIA
 
SOFTPEDIA
Updated one minute ago
HomeSubmit a program for being reviewedAdvertise on our websiteGet help on surfing our websitesSend us your feedbackGet information about our XML/RSS backend and how to use itBrowse the news archiveVisit our discussion forumVizitati forumul in limba romana



KLIP
  1. HOME
  2. SCIENCE
  3. TECHNOLOGY
  4. WEBMASTER
  5. SECURITY
  6. MICROSOFT
  7. LINUX
  8. APPLE
  9. GAMES
  10. TELECOMS
  11. REVIEWS
  12. LIFE & STYLE
  13. EDITORIALS
  14. INTERVIEWS
  15. RSS
Welcome!
Hello, Guest

Login if you have a Softpedia.com account.

Otherwise, register for one.

DATA LEAKS

FireFox 2.0.0.11 and Opera 9.50 Information Leak!

- BMPs to blame

By: Vlad Constandes, SEO News Editor

There’s nothing to kick your morning into gear like finding out that your browser can be the means of losing personal information. I’m talking about the people who actually care and did not go with the stock Windows Internet Explorer, known to be flawed and continually
exploited. Choosing the safer version for surfing the web, like Mozilla’s Firefox or Opera, might prove, until this is fixed, to be a pretty big error.

The problem is concerning the way the two browsers mentioned above handle a .BMP file, as Gynvael Coldwind posted on Vexillium.org.

Breaking it down to the basics, a simple scanner/ harvester site, created by the cyber criminal, can copy the leaked data from Firefox and Opera memory onto a remote server. It does not select and sort what it copies, but rather takes it all in a bundle, but as it sometimes happens, some personal important information is available on your screen. Picture your Internet banking account being copied as a whole. The longer you stay on a site, the more data is leaked to the third, remote site.

Depending on the capacity of the scanner and the rate it has been set to refresh, it will gather a set amount of information per each refresh. Coldwind demonstrated it with heaps of 7650 bytes and using a visible scanner, but if placed in a hidden iframe, it’s almost impossible to find it.

The vulnerability is caused by the BITMAPINFOHEADER field contained in the BMP format named biClrUsed, indicating how many colors the palette has. 0 = 256, any other number is its equivalent. According to Gynvael, both Firefox and Opera allocate to just the ‘right’ amount of memory or forget to nil the allocated palette. Translated into English, if there’s nothing there, it will be a BMP that copies exactly what the screen displays at the moment.

"If the attacker creates a BMP file with biClrUser = 0, and fills it with gradient, from 0 to 255: 00 01 02 03 04 05 ... and so on, the displayed BMP will in fact copy the palette to the screen, which of
course means that it copies the data lying on the heap to the screen," Coldwind says..

My advice would be to roll back to the versions you upgraded to this from, that seems to solve the problem.

MORE RELATED ARTICLES: Malware: Two Is a Company, Three Means Listen! Almost Flawless DNS Scams From Hackers with Love Hackers Fraud Online Scammers Illegal Downloaders Facing Ban Some Kissing Leaked on YouTube Attracts Lawsuit Is the Google Ship Leaking?
 
Comments | Link here | Subscribe
Print | Send to friend
Today's News | Yesterday's News

Search:


19th February 2008, 20:51 GMT | Copyright (c) 2008 Softpedia | Contact:
Read by 1,230 user(s) | Rating: | 8 vote(s) so far | Cast your vote:
FireFox 2.0.0.11 and Opera 9.50 Information Leak! - USER OPINIONS




We are sorry, there are no opinions available for this article.






SHARE YOUR OPINION ABOUT FireFox 2.0.0.11 and Opera 9.50 Information Leak!

Since you are not logged on, your comments will have to be approved before being displayed.
Click here to login, or register.
Your Name:
Your Email:
Type in the result:
Your Opinion:
 


DO YOU WANT TO CONTACT US?  

If you have some comments or you want to send us some information you can send us an email directly to .
You can use the form below for the same purpose.
Your full name: (at least 3 characters)
Your email address: (at least 5 characters)
Message subject: (at least 5 characters)
Message text:
(at least 10 characters)
Type in the result:
 
 



© 2001 - 2008 Softpedia. All rights reserved.
Softpedia™ and Softpedia™ logo are registered trademarks of SoftNews NET SRL.
Copyright Information | Privacy Policy | Terms of Use | Contact Softpedia | Update your software | Archive