By Jay Lyman LinuxInsider Part of the ECT News Network
11/24/06 4:00 AM PT
Frequent visitors to blogs and Internet forums may be particularly at risk of identity theft due to an exploit that prompts the Firefox and Internet Explorer password managers to give away their protected information. Both Mozilla and Microsoft have acknowledged the problem and are working on fixes.
A software security researcher has warned that the password manager features
of Mozilla'sopen source Firefox 2.0 and Microsoft's (Nasdaq: MSFT) Internet
Explorer (IE) Web browsers could be exploited, placing unsuspecting users at risk.
Users of Firefox or Explorer, both of which may be
vulnerable to the attack known as "Reverse Cross Site Request" (RCSR), are not fooled directly by the password theft exploit. Instead, it provides a fake login site that fools a browser's saved password feature into automatically providing the information, Robert Chapin, president of Chapin Information Services, reported.
Neither the latest Firefox 2.0 nor Explorer 7 browser were designed to check the destination of form data before submission, thus making them vulnerable to the weakness.
Because the exploit is actually conducted at a trusted Web site, the
user sees a trusted address in the browser bar, according to Chapin.
"Users of both Firefox and Internet Explorer need to be aware that
their information can be stolen in this way when visiting blog and forum
Web sites at trusted addresses," Chapin wrote for his security site
Chapin Information Services (CIS).
Don't Remember My Password
Both Microsoft and Mozilla acknowledged the issue, with the former
referring to an investigation, and the latter, which has a bug report on
the issue, advising users to turn off the password manager in Firefox
until it is fixed.
The password managers in browsers help millions of Internet users log
onto blogging, social networking, Web mail, portal and an array of other
sites, and the RCSR vulnerability was reportedly exploited on the
popular site MySpace, Chapin said.
The RCSR attack could also be combined with a bogus phishing site to
target the attack for more valuable passwords and information, such as
online banking, IT-Harvest Chief Research Analyst Richard Stiennon told
TechNewsWorld.
"From here on out, best practice is going to be to stop using
[password managers]," he said.
Bigger Hole for Firefox
The vast majority of Internet attacks and scams are aimed at Windows
users, and while Firefox typically enjoys a security advantage because
of its separation from the operating system and faster response to
issues, the RCSR is one instance in which the open source browser may be more risky than IE, according to Chapin. He said he reported the issue to Mozilla earlier this month.
While neither browser bolsters password protection for the RCSR scheme, Firefox automatically fills in saved user names and passwords when presented with bogus sign-in forms, Chapin warned.
"This behavior does not occur in Internet Explorer unless the RCSR
form appears on the same page as a legitimate login form," he pointed out.
Mozilla, which has displayed the speed and transparency advantages of
its open source development for security before, is reportedly working
on a fix.
Hidden Danger
The password manager vulnerability is made worse by the
fact that the fake sign-in forms can be completely hidden from view, Chapin reported, thus allowing a saved password to be transmitted to another site
unwittingly by clicking an invisible image link.
Chapin recommended changes for both Firefox and Explorer, adding that
Webmasters should review server code for the possibility of RCSR and
cross-site scripting (XSS) injections, particularly for encrypted sites.
Attacks leveraging the password manager weaknesses could work against
firewalled, local network servers and HTTPS addresses that would not
otherwise be available, because no direct access or client-side scripting
is needed, Chapin said.
The Risky Business of Online Stock Trading November 16, 2006
Online traders can become too aggressive, and it can be very easy to lose one's shirt. It is not uncommon for avid traders to roll over their 401k funds or other investments -- only to lose everything in the stock market. It's "a double-edged sword," said Kenneth Prather, owner of Prather Investment Management.
Related Stories
IBM Targets SMBs With Identity Management Tools November 21, 2006
Using Federated Identity Manager Business Gateway, an SMB's users can log on to a company's Web site and have that site confirm their identity when they connect to applications on related Web sites without having to log in again. The new single sign-on tools can help systems administrators control access to multiple services.
New Research Center to Combat Identity Theft June 28, 2006
The Center "is a huge step in the right direction," said Ron O'Brien, senior security consultant at Sophos, who applauds the cooperation among the private, public and academic sectors.
Lessons for the Private Sector From Data Theft at the VA June 20, 2006
Procedures need to be put in place to segregate and physically control access to confidential information. Most importantly, everyone in an organization needs to take personal responsibility for protecting confidential information. It was this lack of personal responsibility that stands out as one of the biggest failures of the chain of command at the VA.
Related News Alerts
More by Jay Lyman
Open Source Developer Dumps Novell Over Microsoft Deal December 26, 2006
A key open source developer, Jeremy Allison, who cofounded the Samba project, has resigned from Novell in protest over the company's recent agreement to enter a collaborative arrangement with Microsoft. The deal has created an uproar in the open source community because it does not treat all recipients of the GPL equally and thus violates the spirit of the license, critics say.
Financial Firms Tap Microsoft for Linux December 22, 2006
Three major financial institutions are among the first companies to go to Microsoft for Linux services, provided through an agreement the software giant struck with Novell. Although a recent survey showed customer approval of the collaboration, many members of the open source community view Novell's move as sleeping with the devil.
Mozilla Beefs Up Security in Firefox 2.0 December 21, 2006
Mozilla's latest update to its open source Firefox browser includes security measures targeting phishers. Phishing scams that use social engineering techniques to dupe Web surfers into revealing personal financial information have become an effective way for cybercriminals to conduct their nefarious activities on the Internet.