Go Back   PCMech Forums > Help & Discussion > Software Discussion & Support

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 10-03-2006, 09:40 AM   #1
Member (9 bit)
 
Join Date: Aug 2004
Location: San Francisco
Posts: 324
Firefox Javascript full of exploitable holes-and hackers aren't sharing

http://arstechnica.com/news.ars/post/20061002-7885.html
antgross@pacbell.net is offline   Reply With Quote
Old 10-03-2006, 09:48 AM   #2
Professional gadfly
 
doctorgonzo's Avatar
 
Join Date: Jan 2002
Location: Minneapolis, MN
Posts: 6,364
Send a message via MSN to doctorgonzo
It is rather lame for the people who claim to know the details of these exploits to not share them with the Mozilla development team. If you find a security hole, I think you have the ethical duty to take steps that will get it fixed.
doctorgonzo is offline   Reply With Quote
Old 10-03-2006, 01:35 PM   #3
Computing Professor
Staff
Premium Member
 
Join Date: Jun 2001
Posts: 11,718
I'm giving these guys the benefit of the doubt but it's beginning to look like they haven't been entirely truthful.
__________________
Asus M4A77D, 64 X2 6000+, 4 GB Corsair DDR2 800 ram, Radeon 5770.
pam123 is offline   Reply With Quote
Old 10-03-2006, 02:03 PM   #4
Computing Professor
Staff
Premium Member
 
Join Date: Jun 2001
Posts: 11,718
Another Hoax...

OK, here's the story linked to from Digg :

Claimed security hole in Firefox "just a joke"

The allegedly critical hole reported yesterday in Firefox's JavaScript implementation has turned out, not surprisingly, to be a hoax. Mischa Spiegelmock, who made the claim at the Toorcon hacker conference, told Mozilla's security chief Window Snyder, "The main purpose of our talk was to be humorous."

While it is possible to create a stack overflow, the only result he has been able to produce is a browser crash. Neither he, nor anyone else, has managed to execute code via this hole. Spiegelmock claims to know nothing about the other 30 holes reported in the media. The Mozilla team nevertheless plans to look into the matter in order to detect and remedy any flaws.

http://www.heise-security.co.uk/news/78970
pam123 is offline   Reply With Quote
Old 10-03-2006, 02:05 PM   #5
Professional gadfly
 
doctorgonzo's Avatar
 
Join Date: Jan 2002
Location: Minneapolis, MN
Posts: 6,364
Send a message via MSN to doctorgonzo
Ha ha, what a funny joke.
doctorgonzo is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 09:27 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 PL2