NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home / News / Microsoft

Microsoft


Mozilla Needs to Start Copying Internet Explorer 7

The sooner, the better

By Marius Oiaga, Technology News Editor

5th of April 2007, 14:24 GMT

Adjust text size:



Enlarge picture
The recent critical vulnerability in Windows Animated Cursor Handling has brought the heat down on Mozilla. The reason for this is the fact that Firefox 2.0 can be used as an attack vector to exploit
the .ANI file vulnerability in Windows Vista, just as much as Internet Explorer 7. Yesterday you have been able to watch a video demonstration of a successful .ANI exploit on Windows Vista via both Firefox and IE7 authored by Alexander Sotirov, the Determina security researcher that discovered the Windows Animated Cursor Handling vulnerability back in December 2006.

The video of the exploit indicates that there is a major difference between IE7 and Firefox 2.0 running on Windows Vista. Both the Microsoft and the open source browser access the same vulnerable Windows components to process the malformed .ani files, which makes them both valid attack vectors.

However, the major difference between the two browsers is Protect Mode. IE7 running in Protect Mode has very low privileges. In this context, although an attacker would be permitted access to system files, alteration would not be allowed. The same is not the case with Firefox 2.0. As a matter of fact, via Firefox 2.0, an attacker would share the privileges of the logged-on user. This is one instance where IE7 does a better job in protecting your machine than Firefox 2.0.

Mozilla promised to release an update that would address the Firefox issue in the upcoming security patch release. However, the point here is that Mozilla should implement a Protect Mode in Firefox similar to the one in IE7 that would work in conjunction with the User Account Control in Windows Vista.

Prior to the release of Windows Vista, Firefox developers were invited to Microsoft to touch up support details. No doubt discussions also covered Protect Mode for Firefox. But until this time, Mozilla has not hinted in the least that it plans to integrate Protect Mode into Firefox.

TAGS:

Internet Explorer 7 | Firefox 2.0 | Mozilla
Read by 1,831 user(s) | Add comment | Link to this article TWEET THIS


Article rating:
Fair (2.8/5) 8 vote(s)    

Subscribe to news | Print article | Send to friend

© Copyright 2001-2009 Softpedia
Contact:

 

 

SEARCH THE NEWS ARCHIVE :




Today's News
| Yesterday's News | News Archive


MORE RELATED ARTICLES:


IE7, Firefox, Opera - The Browser War Is On! Vote Now!

Internet Explorer 7 Is Eating Away at... Internet Explorer

Mozilla Firefox 3.0 Drops This Spring

Firefox 2.0 and IE7 Are Equally Matched in Security

Firefox 2.0 Can't Breathe with All the IE7 Saturation

Internet Explorer Goes Down! Down! Down!

Internet Explorer Security Will Ultimately Fail Miserably

Internet Explorer 7 vs. Internet Explorer 6 SP1 - No Kill

Firefox 2.0 and IE7 - Attack Vectors for Windows Vista

User opinions:


Comment #1 by: Lost Angel on 06 Apr 2007, 06:41 GMT reply to this comment

"Determina security researcher that discovered the Windows Animated Cursor Handling vulnerability back in December 2007." - for xrist's sake - December of 2007 hasn't even come yet - bloody read your own articles before you publish them... This is just so lame.

About the content of article - that MS OS has a security hole is not really caused by Firefox - no use ranting about it. I am sure it would take Firefox developers less than a year to fix, unlike Microsoft guys.

Share your opinion:

Your Name:
Your Email Address:
(will not be used for commercial purposes)
Solve this to prove you're not a bot: =
Your review/opinion:

 




Windows tabGames tabDrivers tabMac tabLinux tabScripts tabMobile tabHandheld tabGadgets tabNews tab

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   ENTER NEWS SITE   |   ENGLISH BOARD   |   ROMANIAN FORUM