NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Security / Advisories

Advisories


Firefox Security Flaw Affecting Gmail's Users

The Firefox JAR vulnerability still there

By Bogdan Popa, Security and Search Engines Editor

12th of November 2007, 08:08 GMT

Adjust text size:


Mozilla Firefox
Enlarge picture
Last week, security companies around the world spotted a new vulnerability in Mozilla Firefox which could allow the attackers to use a malicious JAR file to harm users' computers. The security flaw is still there and moreover, it seems it affects most websites on the Internet including the super search giant Google.
GnuCitizien wrote that Michal Zalewski from Google (you know, that famous hacker who joined Googleplex) required additional information about a potential exploitation over the company's technologies. In addition, beford.org discovered a way to steal the Gmail contact list using a malicious JAR file especially created to take advantage of the Firefox vulnerability.

I'm not going to offer you more details about it but I'll give you a tip on how to remain protected against attacks. You can always install the NoScript extension which was already updated to provide protection for this exploit. In case you never tried it, NoScript is an add-on designed to work with Mozilla Firefox which is supposed to disable the webscripts included on the websites you choose.

Obviously, you can always choose another browser to visit the Internet pages which will surely keep you away from the Firefox JAR attacks. But in case you're a Firefox-addicted user, I think you can try signing out of your account but I'm not sure this would be 100 percent efficient. However, stay away from dangerous websites and unknown links which could attempt to steal your private Google information.

Now, since the flaw affects both Google and Firefox, I'm pretty curious to see which will be the first company to patch it. "Who's fault? Both, Google for having open redirect issues and not fixing them, and Mozilla Corporation for failing to address this problem," beford wrote.

You can download the latest version of Firefox straight from Softpedia.

TAGS:

firefox | google | flaw | security | jar
Read by 1,960 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Good (3.2/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


Firefox 3.0 to Support Offline Applications

How to Get The Best of Google

Firefox 3.0 To Bundle Google's Security Tools

Google Toolbar for Firefox Updated!

Google Gets More Firefox Support

Google Is God

User opinions:

No user comments yet.
Be the first to express your opinion using the form below!

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM