By Jennifer LeClaire LinuxInsider Part of the ECT News Network
01/07/05 12:02 PM PT
Could this be the end of the beginning for Firefox? Jupiter analyst Joe Wilcox doesn't think so, but he said it could be a good opportunity for Microsoft to get a little payback for the finger pointing that Mozilla has done about the software giant's security flaws.
Increase Customer Sales with VerticalResponse Email Marketing! Quickly and easily send email newsletters, coupons & sales announcements to your customers – no technical expertise needed. Sign up for your Free Trial today and send 100 emails on us!
A vulnerability in Mozilla's open-source Firefox browser could be exploited, security experts have warned. Despite the hoopla about the superior security of Firefox, Secunia Research reported that the browser could be used by malicious people, know as phishers, to spoof the source URL displayed in the browser's "Download Dialog" box.
"The problem is that long sub-domains and paths aren't displayed correctly, which therefore can be exploited to obfuscate what is being displayed in the source field of the Download Dialog box," said the Secunia advisory.
Secunia rated the flaw "less critical" and has confirmed the vulnerability in Mozilla 1.7.3 for Linux, Mozilla 1.7.5 for Windows, and Mozilla Firefox 1.0. It added that "other versions may also be affected."
"Currently, no solution is available. However, the vendor reports that this vulnerability will be fixed in upcoming versions of the affected products," Secunia stated in its advisory. The company urged users not to follow download links from untrusted sources.
Mozilla's Response
Mozilla officials could not immediately be reached for comment. However, mozillaZine, the Web log that allows its members to post their thoughts and reactions to the company products and news, offers some insight into this hot debate over browser security.
A blogger that calls himself "mlefevre" writes, "Actually there are probably a bunch of security issues that are due to be disclosed, now that Mozilla 1.7.5 and the aviary 1.0s are out."
Meanwhile, "Charles" posted a response to the clamor earlier this morning, writing, "There are always going to be security issues, with all browsers, specifically with Gecko-based browsers, and increasingly so as they become more popular."
Response Time Critical
Jupiter Research analyst Joe Wilcox agreed with the bloggers that security problems with any browser are no surprise. But he told LinuxInsider that the real test is responsiveness.
"Microsoft's argument is that a commercial developer that has sole access to the source code can respond quicker to flaws than open source counterparts," Wilcox said. "The open source community argues that the "all-eyes" approach diminishes the number of exploits and makes responsiveness quicker than commercial vendors. Who can really respond to flaws the quickest? That's the real question."
Wilcox sees no irony in the fact that Firefox has been touted by many as a more secure alternative to Internet Explorer. Secunia released an advisory about multiple "extremely critical" vulnerabilities in Microsoft's (Nasdaq: MSFT) IE 6 earlier today. Those "extremely critical" flaws compare to Secunia's "less critical" rating of the Mozilla flaws. Again, Wilcox said, security flaws will happen. The test is who can respond the fastest.
Chink in Firefox Armor
Microsoft aside, could this be the end of the beginning for Firefox? Wilcox doesn't think so, but he said it could be a good opportunity for Microsoft to get a little pay back for the finger pointing that Mozilla has done about the software giant's security flaws.
"Finger-pointing can be a very effective marketing tool in high-tech," Wilcox said. "Mozilla has used the tactic against Microsoft and it has proved to be very effective. There's no reason why Microsoft shouldn't turn that around here. That could impact Firefox because people have to make a conscious decision to switch browsers and this news could cause them to wait or decide not to migrate."
I am still amazed at the number of people who still don't get it. Microsoft lackeys who still ...
Next Article in Security
New Trojan Attacking Mobile Phones January 07, 2005
Using the Cabir worm, this latest Trojan disables any system application or third-party application that could be used to disinfect the device. It then triggers flashing animation showing the skull logo to indicate the phone has been infected.
Related Stories
Firefox Aims To Convert Masses with New York Times Ad December 16, 2004
Mozilla is already doing damage to mainstream players like Microsoft's Internet Explorer. Over the past month, the U.S. browser usage share of Firefox has grown by more than a third, according to the latest independent study from WebSideStory, a provider of on-demand Web analytics.
Report Shows Uptick in Automated Phishing November 24, 2004
The APWG report indicated that the number of brands used for bogus phishing efforts -- eBay, PayPal, Microsoft and others -- is increasing. The report gave greater focus to the server side of phishing attacks, but indicated more company trademarks are likely to be used as the basis of fraud.
Will Antiphishing Legislation Be Effective? November 13, 2004
James Gildea, director of marketing for e-mail management firm IntelliReach, does not put much faith in such legal proposals. He sees attempts to legislate curbs on phishing attacks as having much the same results as recently enacted antispam laws. "To date, 32 states have enacted antispam laws. These laws haven't done much to stop the flood of spam," he said.
A9.com Launches Toolbar for Mozilla Firefox November 01, 2004
A9.com opened in October 2003 to research and build innovative search technologies. Users generate search results from a variety of information sources including Google, Amazon's "Search Inside the Book," the Internet Movie Database and GuruNet.com.
Mozilla's Firefox, the Next Big Browser? September 15, 2004
Gartner analyst David Smith told LinuxInsider that many of those who switch from dominant browser Internet Explorer do so because of security concerns. "People perceive that there won't be problems with browsers like Firefox or Mozilla." But alternative browser developers will have to do more work to make sure that perception becomes reality in the future.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.