CIS declares Firefox Password Manager unsafe
MySpace details may be compromised in unpatched flaw
29 January 2007 17:34 GMT / By Amber Maitland
CIS is reporting today that efforts by MySpace to fix a flaw that tricks users into entering their login details in to a bogus web page have failed.
CIS said that a Reverse Cross Site Request can still be injected into a MySpace.com email message.
News of the flaw first broke on 23 November, when CIS warned Firefox 2 and IE7 users to be careful of the vulnerability, which allows attackers to get users' login details by showing them a fake login form.
This tricks Firefox Password Manager into filling in the saved details. CIS reviewed the vulnerability on 19 January, after Firefox version 2.0.0.1 was released, but the version didn't contain a fix.
CIS is therefore warning users to disable the Password Manager so that they don't fall prey to a malicious bogus webpage.
Latest in Software
Latest on Pocket-lint.com
-
SOFTWARE
Google Apps Getting Wave Interface?
-
SOFTWARE
Firefox keeps crashing? Here's How To Fix It
-
AUDIO
Pocket-lint Is Hiring
PHONES
HTC HD2 mobile phone Does Windows Mobile finally make Sense?
HARDWARE
Dell Adamo XPS laptop - First Look Have corners been cut to get it this thin?
HOME CINEMA
Sainsbury's now offering free glasses for Channel 4's 3D week 10 million pairs of glasses across 500 stores




Comments