Firefox - Gmail Vulnerability Remains Unpatched
Mozilla Firefox and Gmail users need to be careful with an unpatched vulnerability that has been reported in PC World:
A 302 redirect error in Google, discovered by bedford.org's Morgan Lowtech aka tx, creates a domain-wide cross-site scripting attack allowing hackers to gain access and modify Google user accounts including e-mails, contact lists and online presence....
While Mozilla has not issued a solution to the problem, application firewalls and proxy servers can be used to block Windows Universal Resource Identifiers (URIs) that contain the JAR protocol, while Web administrators can use a reverse proxy to prevent malicious content from being uploaded.
There is a NoScript add-on which can block the exploit but at the expense of lost functionality in the browser. Trade-offs between security and functionality? No surprise there.



Email This!
Digg it!
Del.icio.us
Reddit!
Newsvine
