'How to attack Firefox' code appears on the net

Exploits freshly patched security flaw...

By Joris Evers, 26 September 2005 08:15

NEWS Computer code that could be used to attack Firefox, Mozilla Suite and Netscape users has been released on the internet.

The release of the attack code comes days after Mozilla released an updated version of Firefox to fix several security flaws, including the bug exploited by the code.

A fixed version of the Mozilla Suite is also available but Firefox-based Netscape has yet to be updated. The Netscape browser is a product of Netscape, which is a division of Time Warner's AOL subsidiary. An AOL spokesman had no comment on Thursday.

The attack code exploits a vulnerability that was disclosed two weeks ago. The flaw lies in the way the browsers handle International Domain Names, which are web addresses that use international characters. Hackers had been working to exploit the flaw and had said the code would be released after fixes were available.

The exploit could let attackers run code remotely on vulnerable computers and works on Firefox, Mozilla and, in some cases, Netscape, according to security researcher Berend-Jan Wever, who published the code. Mozilla has urged users to upgrade to the latest versions of its products.

Joris Evers writes for CNET News.com

Comments

There is 1 comment. Join the discussion

  1. 1. Tony Whitty

    funny but i thought the latest version of firefox (1.07) fixed this problem

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ