| 

Browser Updates

  • Post author: Omid Farhang
  • Post published: September 8, 2010
  • Reading Time: 2 min
  • Word Count: 316 words

The Mozilla foundation just released the popular web browser Firefox in version 3.6.9. The new version fixes overall 14 security vulnerabilities of which 10 are rated critical by the developers. Additionally, they added a new feature called ā€œX-FRAME-OPTIONSā€œ-header which shall help mitigating clickjacking attacks as web site owners can ensure with this header that their content isnā€™t inserted into other sites via frames. The update is available through the automatic update mechanism ( via the ā€œHelpā€ ā€“ ā€œSearch for updatesā€ menu). ...

Continue Reading Browser Updates

Malicious warez site offers Firefox 4.0 beta download scam

  • Post author: Omid Farhang
  • Post published: August 29, 2010
  • Reading Time: 1 min
  • Word Count: 176 words

Like a lot of seedy stuff, this started with a Twitter post:. The current working version of Mozillaā€™s Firefox browser is 3.6.8. Version 4 is in beta testing. You get them FREE from Mozilla.. Why would you need a crack (program with its password broken) or a keygen (application that generates a password for a password-protected program) for something that is FREE? Well, thereā€™s a sucker born every minute and the folks at this warez (pirated software) site are betting there are a lot of them using Twitter. ...

Continue Reading Malicious warez site offers Firefox 4.0 beta download scam

Mozilla turns up the fire, Firefox 4 betas to begin in June

  • Post author: Omid Farhang
  • Post published: May 11, 2010
  • Reading Time: 6 min
  • Word Count: 1187 words

With competition in the Web browser field having transitioned from cold to boiling in less than a yearā€™s time, Mozilla suddenly finds itself playing catch-up against not only Apple and Google, but Microsoft as well. In March, the organization realized it needed to completely make over Firefox 4 if it wanted to remain feature competitive against a fast-rising Google Chrome. In a live presentation yesterday, Mozilla Firefox director Mike Beltzner admitted that his groupā€™s March roadmap, which involved an interim release of Firefox 3.7, had too many steps. Now the group has decided to straighten out its path by grafting version 3.7ā€™s main additions onto a point release Firefox 3.6.4, and shifting gears to focus on version 4.0. ...

Continue Reading Mozilla turns up the fire, Firefox 4 betas to begin in June

Exploit for zero-day vuln in Firefox is for sale

  • Post author: Omid Farhang
  • Post published: February 21, 2010
  • Reading Time: 1 min
  • Word Count: 179 words

Evgeny Legerov, founder of Intevydis in Moscow, has created an exploit that hits a previously unknown heap-corruption vulnerability in the Firefox browser. The code isnā€™t readily available though, since heā€™s put it in a module to the automated exploitation system he sells (reportedly at a considerable price.) Legerov has not provided information on the vulnerability to Mozilla. The Intevydis site says: ā€œExploitation frameworks are not new on the market, but only we may offer you hundreds of CANVAS modules for unpatched and unknown vulnerabilities in highly popular software products.ā€ ...

Continue Reading Exploit for zero-day vuln in Firefox is for sale

Trojan code sneaks into two Mozilla add-ons

  • Post author: Omid Farhang
  • Post published: February 5, 2010
  • Reading Time: 1 min
  • Word Count: 159 words

Mozilla yesterday posted a notice on its AMO blog (thatā€™s an acronym for their add-on site addons.mozilla.org) that two add-ons have been found infected with Trojan code: Sothink Web Video Downloader v. 4.0 and all versions of Master Filer. Version 4.0 of Sothink Web Video Downloader contained Win32.LdPinch.gen and Master Filer contained Win32.Bifrose. According to the blog, Masterfiler was downloaded 600 times before it was removed from the site Jan. 25 and Sothink was downloaded more than 4,000 times before it was removed Feb. 2. ...

Continue Reading Trojan code sneaks into two Mozilla add-ons