IE(7) and Firefox(2) blighted by fake login flaw

By Ashish Mohta

The latest versions of both Firefox and Internet Explorer are vulnerable to an un patched flaw that allows hackers to snaffle users’ login credentials via automated phishing attacks.

The information disclosure bug affects the password manager in Firefox 2.0 and its equivalent in IE7. Firefox’s Password Manager, for example, fails to properly check URLs before filling in saved user credentials into web forms. As a result, hackers might be able to swipe users credentials via malicious forms in the same domain, providing users have already filled out forms on this domain.

Samples of attacks utilizing the flaw have already been reported on MySpace. Firefox 2.0 users might be more at risk from the flaw because IE7 does not automatically fill in saved information. Security notification firm Secunia advises users to disable the “remember passwords for sites” option in their browsers pending the delivery of patches.

This so-called reverse cross-site request flaw was discovered by security researcher Robert Chapin, who explains the issue in greater depth in an advisory here

via John Leyden


Email Print
Vote This Post DownVote This Post Up (No Ratings Yet)
Loading ... Loading ...

About The Author of this article:
Ashish is one of the co-author of this blog and writes on various interesting softwares, PC tips and more. You can read more of his articles here.

Enjoyed this article? Download our Toolbar ( for Free ) and read us more quickly or Free Subscribe to the Full RSS Feed or Get Post like this in your Inbox Free Subscribe via Email


  • Tags: , , , ,
  • Read More Stories from Security

  • No Comments Yet

    You can be the first to comment!

    Leave a comment Share your thoughts with the world

    Scroll Down and Check footer for more details



    • Recent Comments:

      • Anurag: Great Tool… Thnx For thepost….. http://www.pcdrome.com
      • CypherHackz: But, is it secure? Nowadayas I keep thinking about the security of the information transfered from my PC...
      • Greg P.: I read up about DropBox on their website. This looks very promising! I especially like the differential sync...
      • dave: I have heard many good things about dropbox and signed up for beta but did not get an invite. May I get an...
      • drew: i want the engage xp theme please how would i get it!!!
      • brandub: thanks for ths, I was searching for something else but this process helped me a little bit, and is...
      • Gene: This looks great! Do you have any invites left? Thanks!
      • dyjay: helow! how can i play wars of gears after instal dx 10 from alky on xp?i have a error ’send….don`t...
      • Madhur Kapoor: My father will love this.
      • kali: i dont knw john i ve downloaded immediately as chrome was lainched….i didnt experience any of the probs u...

    Technology Blogs - Blog Top Sites