CIS declares Firefox Password Manager unsafe

MySpace details may be compromised in unpatched flaw


29 January 2007 17:34 GMT / By Amber Maitland

CIS is reporting today that efforts by MySpace to fix a flaw that tricks users into entering their login details in to a bogus web page have failed.

CIS said that a Reverse Cross Site Request can still be injected into a MySpace.com email message.

News of the flaw first broke on 23 November, when CIS warned Firefox 2 and IE7 users to be careful of the vulnerability, which allows attackers to get users' login details by showing them a fake login form.

This tricks Firefox Password Manager into filling in the saved details. CIS reviewed the vulnerability on 19 January, after Firefox version 2.0.0.1 was released, but the version didn't contain a fix.

CIS is therefore warning users to disable the Password Manager so that they don't fall prey to a malicious bogus webpage.
Related
Full tags
Software, Online, Viruses And Malware, MySpace, Linux

share print story pdf email story

Recommended articles


Search

Loading

Follow


Best iPad 2 apps

We detail the best iPad 2 and iPad apps in the app store Which iPad app should you download?

Windows 8

All the features and details of the new Microsoft operating system explained What's new in Windows 8?

iPad 3 rumours

What comes next? We look at the possible features, leaks, images, specs and more

Pocket-lint poll

Q. Will you be buying a PS Vita?

Vote YES Vote NO

» LAST TIME
When asked Will Samsung be making a mistake if the Galaxy S III isn't shown at Mobile World Congress in February? 51% said yes and 49% said no