CIS declares Firefox Password Manager unsafe

MySpace details may be compromised in unpatched flaw

CIS declares Firefox Password Manager unsafe. Software, Online, Viruses And Malware, MySpace, Linux 0

29 January 2007 17:34 GMT / By Amber Maitland

CIS is reporting today that efforts by MySpace to fix a flaw that tricks users into entering their login details in to a bogus web page have failed.

CIS said that a Reverse Cross Site Request can still be injected into a MySpace.com email message.

News of the flaw first broke on 23 November, when CIS warned Firefox 2 and IE7 users to be careful of the vulnerability, which allows attackers to get users' login details by showing them a fake login form.

This tricks Firefox Password Manager into filling in the saved details. CIS reviewed the vulnerability on 19 January, after Firefox version 2.0.0.1 was released, but the version didn't contain a fix.

CIS is therefore warning users to disable the Password Manager so that they don't fall prey to a malicious bogus webpage.

Related
Full tags
Software, Online, Viruses And Malware, MySpace, Linux
UK Shopping
Amazon.co.uk, play.com, pixmania.co.uk, Currys.co.uk, Dixons.co.uk, 7dayshop.com, ebay.co.uk
US Shopping
Amazon.com, bestbuy.com, ebay.com

share Subscribe to RSS feeds email story save story print story pdf

Comments

(Will not be published)

  (Next time sign in to bypass captcha)

Latest in Software

Latest on Pocket-lint.com

About Pocket-lint

Pocket-lint is your one stop shop for gadgets, technology and consumer electronics, bringing you the low-down on the latest televisions, cameras, phones, GPS and much more. Whether it's learning about what's hot in the world of Apple, finding out about the latest home cinema kit from Samsung and Sony or merely seeing what not to buy, we have you covered. So check out our reviews, news, comment, hands-on photo galleries and videos. Enjoy.

Pocket-lint.com poll

Q. Do you still buy CDs?

Vote YES Vote NO

» LAST TIME
When asked Do you want the Droid by Motorola? 53% said yes and 47% said no

Top 10 Broadband

Compare 50+
broadband packages

Home Broadband »

Top products

tip us on news

Rss feed

Follow us on Twitter