Welcome | Sign In
TechNewsWorld.com
Security

Firefox, IE Vulnerable to Password Theft

Print Version
E-Mail Article
Reprints
Firefox, IE Vulnerable to Password Theft

Frequent visitors to blogs and Internet forums may be particularly at risk of identity theft due to an exploit that prompts the Firefox and Internet Explorer password managers to give away their protected information. Both Mozilla and Microsoft have acknowledged the problem and are working on fixes.


A software security researcher has warned that the password manager features of Mozilla's open source Firefox 2.0 and Microsoft's (Nasdaq: MSFT) Internet Explorer (IE) Web browsers could be exploited, placing unsuspecting users at risk.

Users of Firefox or Explorer, both of which may be vulnerable to the attack known as "Reverse Cross Site Request" (RCSR), are not fooled directly by the password theft exploit. Instead, it provides a fake login site that fools a browser's saved password feature into automatically providing the information, Robert Chapin, president of Chapin Information Services, reported.

Neither the latest Firefox 2.0 nor Explorer 7 browser were designed to check the destination of form data before submission, thus making them vulnerable to the weakness.

Because the exploit is actually conducted at a trusted Web site, the user sees a trusted address in the browser bar, according to Chapin.

"Users of both Firefox and Internet Explorer need to be aware that their information can be stolen in this way when visiting blog and forum Web sites at trusted addresses," Chapin wrote for his security site Chapin Information Services (CIS).

Don't Remember My Password

Both Microsoft and Mozilla acknowledged the issue, with the former referring to an investigation, and the latter, which has a bug report on the issue, advising users to turn off the password manager in Firefox until it is fixed.

The password managers in browsers help millions of Internet users log onto blogging, social networking, Web mail, portal and an array of other sites, and the RCSR vulnerability was reportedly exploited on the popular site MySpace, Chapin said.

The RCSR attack could also be combined with a bogus phishing site to target the attack for more valuable passwords and information, such as online banking, IT-Harvest Chief Research Analyst Richard Stiennon told TechNewsWorld.

"From here on out, best practice is going to be to stop using [password managers]," he said.

Bigger Hole for Firefox

The vast majority of Internet attacks and scams are aimed at Windows users, and while Firefox typically enjoys a security advantage because of its separation from the operating system and faster response to issues, the RCSR is one instance in which the open source browser may be more risky than IE, according to Chapin. He said he reported the issue to Mozilla earlier this month.

While neither browser bolsters password protection for the RCSR scheme, Firefox automatically fills in saved user names and passwords when presented with bogus sign-in forms, Chapin warned.

"This behavior does not occur in Internet Explorer unless the RCSR form appears on the same page as a legitimate login form," he pointed out.

Mozilla, which has displayed the speed and transparency advantages of its open source development for security before, is reportedly working on a fix.

Hidden Danger

The password manager vulnerability is made worse by the fact that the fake sign-in forms can be completely hidden from view, Chapin reported, thus allowing a saved password to be transmitted to another site unwittingly by clicking an invisible image link.

Chapin recommended changes for both Firefox and Explorer, adding that Webmasters should review server code for the possibility of RCSR and cross-site scripting (XSS) injections, particularly for encrypted sites.

Attacks leveraging the password manager weaknesses could work against firewalled, local network servers and HTTPS addresses that would not otherwise be available, because no direct access or client-side scripting is needed, Chapin said.


Print Version E-Mail Article Reprints More by Jay Lyman


More by Jay Lyman

Open Source Developer Dumps Novell Over Microsoft Deal
December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux
December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0
December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network