HZRN.COM
welcome to my space
X
Welcome to:hzrn.com
Causes and Organizations | Home Improvement | Writing | Desserts | Computer Games | Fashion | Cars | Recruitment | Related articles
Article search:  
NAVIGATION - HOME

Mozilla Flaw Springs Privacy Leak

Published by: admin 2008-09-06
Researchers have found a flaw in Mozilla-based browsers that springs data on the Web surfing movements of users.

Head researcher at Neopoly Sven Neuhaus said the bug, first discovered in May, is a serious privacy issue.

In a demonstration of the flaw, Neuhaus says it exposes the URL of the page a user is viewing to the Web server of the site visited last, allowing a Web site to track where a viewer goes next regardless of whether the URL is entered manually or via a bookmark.

"This bug is still present in the Mozilla 1.1 release... It's been three months," Neuhaus said in a plea for a fix on Bugzilla, the site used to track vulnerabilities in Mozilla releases.

It affects Mozilla browser versions 0.9x, 1.0, 1.0.1, 1.1 and 1.2 alpha; Netscape 6.x and 7; Galeon 1.2.x and Chimera 0.5.

Mozilla users are urged to disable JavaScript as a temporary workaround until a fix is issued. The flaw exists in the "onunload" handler which loads an image from the referring server about a user's surfing movements.

In addition to disabling JavaScript, users can avoid the bug by creating a file "user.js" in the profile folder (the one with the pref.js file) and put the following line in the file:

Critical Security Vulnerability with GreaseMonkey (Firefox Extension)::
The flaw allows any website which matches at least one user script (even Security: How Internet Explorer 6 Fares Against Mozilla Firefox?
http://blog.taragana.com/index.php/archive/critical-security-vulnnkey-firefox-extension/ru
HOME
user_pref("capability.policy.default.Window.onunload", "noAccess"); This stops the "onunload" handler from being activated.

Mozilla.org, the open source browser project backed by AOL Time Warner , just released the 1.1 upgrade to provide increased support for Linux and Mac platforms but the privacy flaw remains in the upgrade, Neuhaus said.


Pre-Article:RosettaNet: The Strong Link in the Supply Chain
Next-Article:Handhelds Get Boost on Windows CE

You are looking at:hzrn.com's Mozilla Flaw Springs Privacy Leak, click hzrn.com to home
#If you have any other info about this subject , Please add it free.#
Your name:
E-mail:
Telphone:

Your comments:


If you have any other info aboutMozilla Flaw Springs Privacy Leak, Please add it free.

About us |Contact us |Advertisement |Site map |Exchange links
Copyright© 2008hzrn.com All Rights Reserved