Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!
Uniqs:
1231
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
NIS 2008 on 64 Bit Vista »
« Security Software Updates - 06 Feb 2008  

yes_sir

@net.mx

Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

Firefox seems to have trouble with defining the proper hostname when
requesting a ssl connection. I was able to trick Firefox in thinking
the hostname behind the at-sign is legit and the same as the URI that
requested an ssl connection, and this without a warning.

PoC:
You can add as much garbage between .com and the @ sign.

So what else can we do?

PoC:
ah heck we don't need that at all:
works fine also :)

jansson_mark
Markus Jansson
Premium
join:2001-08-05
Finland

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

Dude, the version is still 2.0.0.11.

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

said by jansson_mark See Profile :

Dude, the version is still 2.0.0.11.
»Firefox 2.0.12 VS IE7

»wiki.mozilla.org/Releases/Firefox_2.0.0.12

»ftp.eu.mozilla.org/pub/mozilla.o···?C=M;O=D
--
10,504 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

said by La Luna See Profile :

said by jansson_mark See Profile :

Dude, the version is still 2.0.0.11.
»Firefox 2.0.12 VS IE7

»wiki.mozilla.org/Releases/Firefox_2.0.0.12

»ftp.eu.mozilla.org/pub/mozilla.o···?C=M;O=D
Soon. Should be any day assuming no release blockers.
--
Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer

chachazz
Premium
join:2003-12-14

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

Name: Firefox 2.0.0.12
Scheduled Release Date : February 7
Release Schedule
--
Gladiator Security Forum: www.gladiator-antivirus.com/

antdude
A Ninja Ant
Premium,VIP
join:2001-03-25

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

said by chachazz See Profile :

Name: Firefox 2.0.0.12
Scheduled Release Date : February 7
Release Schedule
Ooh. Hmmph, no suite product SeaMonkey?
--
Ant @ »antfarm.ma.cx and »aqfl.net. Please do not IM/e-mail me for technical support. Use the forum! Disclaimer: The views expressed in this posting are mine, and do not necessarily reflect the views of my employer
pepperxn

join:2001-02-21

Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing flaws!

said by antdude See Profile :

said by chachazz See Profile :

Name: Firefox 2.0.0.12
Scheduled Release Date : February 7
Release Schedule
Ooh. Hmmph, no suite product SeaMonkey?
SeaMonkey 1.1.8 is coming soon.

»home.kairo.at/blog/2008-02/weekl···w05_2008

Notice this sentence: "I created and uploaded (two sets of) candidate builds for SeaMonkey 1.1.8 this week, which is our upcoming security release for the stable 1.1.x series. We target a release nearly in sync with Firefox 2.0.0.12 this Thursday or Friday."

WeenieBoy

join:2003-06-25
Pasadena, MD
Besides the wrong version with this "problem" What are you saying ? When I did it I got the certificate from the rogue host so how the heck is that wrong ? What does "legit" mean ?

I am confused about your post

Epyon9283
Premium
join:2001-12-26
Dayton, NJ
What the heck are you talking about?

What comes after the @ is the host name that firefox is going to connect to. If that host has a valid, trusted SSL cert you're not going to see a warning message. What are you spoofing?

Grail Knight
Who Dares Wins
Premium
join:2003-05-31
·Verizon Online DSL

So are you testing the beta in hopes of informing Mozilla Foundation that they need to work on the beta?

The beta is 2.0.0.12pre.

The release is 2.0.0.11
--
"We must look for consistency. Where there is a want of it we must suspect deception." - Sherlock Holmes
pepperxn

join:2001-02-21

2 flaws here.

»www.0x000000.com/?i=509

and

»www.0x000000.com/index.php?i=511
»https://bugzilla.mozilla.org/show_bug.cgi?id=415034

Haven't found the bug # for the first one yet. 2nd one has a patch, and will be fixed in 1.8.1.13 (Firefox 2.0.0.13).
Forums » Up and Running » Security » SecurityNIS 2008 on 64 Bit Vista »
« Security Software Updates - 06 Feb 2008  


Sunday, 29-Nov 19:31:06 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [124] Time Warner Cable Fires Broadside At Broadcasters
· [112] New AT&T Ad Campaign Hits Back At Verizon
· [96] Apple Joins AT&T Verizon Snark Fest
· [87] New Bill Takes Aim At Higher Verizon ETFs
· [80] TiVo Sees Record Customer Losses
· [80] Weekend Open Thread
· [79] Verizon CEO: Hulu Will Be Dead Soon
· [69] In-Flight Internet Headed For Bumpy Landing?
· [63] Thanksgiving Open Thread
· [41] ICANN Slams DNS Redirection
Most people now reading
· Grey Cup on the Web? [Canadian Chat]
· Are GPS's better today? [General Questions]
· Is Easynews down? [Filesharing Software]
· [Newsgroups] Newzleech down? [Filesharing Software]
· Windows 7 boot manager editing questions [Microsoft Help]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Surfers beware !!! [TekSavvy]
· Enhancement Shaman + Heirlooms, what to pick? [World of Warcraft]