<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0" xmlns:osnews="http://osnews.com/rss2#">
	<channel>
		<title>OSNews: </title>
		<link>http://www.osnews.com/story/17376/IE_Firefox_Share_Vulnerability</link>
		<description>Exploring the Future of Computing</description>
		<language>en-us</language>
		<copyright>Copyright 2001-2009, David Adams</copyright>
		<webMaster>adam+nospam@osnews.com</webMaster>
		<lastBuildDate>Tue, 10 Nov 2009 05:01:25 GMT</lastBuildDate>
		<image>
			<url>http://www.osnews.com/images/osnews.gif</url>
			<title>OSNews.com</title>
			<link>http://www.osnews.com</link>
		</image>
		<item>
			<title>This is news?</title>
			<link>http://osnews.com/thread?216944</link>
			<guid isPermaLink="true">http://osnews.com/thread?216944</guid>
			<description>A piece of software has a bug in it.  Software reverse-engineered from the main piece of sofware has the same bug in it.  Film at 11.</description>
			<pubDate>Tue, 27 Feb 2007 18:03:00 GMT</pubDate>
			<author>donotreply@osnews.com (Almafeta)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Didn't work</title>
			<link>http://osnews.com/thread?216945</link>
			<guid isPermaLink="true">http://osnews.com/thread?216945</guid>
			<description>I tried the demonstration at:<br />
<a href="http://lcamtuf.coredump.cx/focusbug/ffversion.html" rel="nofollow">http://lcamtuf.coredump.cx/focusbug/ffversion.html</a> <br />
<br />
And nothing happened. This is Firefox 2.0.0.2 on XP. Perhaps the demonstration is buggy.</description>
			<pubDate>Tue, 27 Feb 2007 18:05:00 GMT</pubDate>
			<author>donotreply@osnews.com (nxsty)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: This is news?</title>
			<link>http://osnews.com/thread?216964</link>
			<guid isPermaLink="true">http://osnews.com/thread?216964</guid>
			<description>Is this FUD?<br />
<br />
So for you Firefox is a reverse engineered version of IE...<br />
<br />
Don't you know that HTML is a markup language universally  known, so you can make yourself your personal rendering engine for html pages.. Would it be a reverse-engineered version of MS Internet Explorer? ....<br />
<br />
....<br />
<br />
-__- my god.</description>
			<pubDate>Tue, 27 Feb 2007 18:37:00 GMT</pubDate>
			<author>donotreply@osnews.com (Tanner)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>mostly a Javascript issue</title>
			<link>http://osnews.com/thread?216973</link>
			<guid isPermaLink="true">http://osnews.com/thread?216973</guid>
			<description>So, it appears that using Javascript, the page is redirecting select input from the user to the file input box - and then uploading the file to the server once complete.<br />
<br />
This doesn't really surprise me - but I wouldn't have thought of it <img src="/images/emo/tongue.gif" alt=";)" /> <br />
<br />
So, mitigating factors appear to be: Have an exploitable browser, have a C:boot.ini (although any file could be used for this), have administrative priveleges (so that accessing boot.ini is possible for the browser in the first place) and have Javascript enabled.<br />
<br />
For the record, it does work on my system... but I have to type very slowly as it's shifting focus around and has a hard time keeping up.Edited 2007-02-27 18:51</description>
			<pubDate>Tue, 27 Feb 2007 18:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Didn't work</title>
			<link>http://osnews.com/thread?216977</link>
			<guid isPermaLink="true">http://osnews.com/thread?216977</guid>
			<description>It worked here.<br />
<br />
Firefox 2.0.0.2, WinXP SP2, running with admin user.</description>
			<pubDate>Tue, 27 Feb 2007 18:54:00 GMT</pubDate>
			<author>donotreply@osnews.com (pandronic)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>linux?</title>
			<link>http://osnews.com/thread?217024</link>
			<guid isPermaLink="true">http://osnews.com/thread?217024</guid>
			<description>how does the test work in linux? my boot drive is hdb1, incidentally i like penguins?</description>
			<pubDate>Tue, 27 Feb 2007 20:36:00 GMT</pubDate>
			<author>donotreply@osnews.com (Dekkard)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: This is news?</title>
			<link>http://osnews.com/thread?217045</link>
			<guid isPermaLink="true">http://osnews.com/thread?217045</guid>
			<description>Don't think that's the way he meant it.<br />
Try it again changing IE for Firefox and vice versa. <img src="/images/emo/smile.gif" alt=";)" /></description>
			<pubDate>Tue, 27 Feb 2007 21:15:00 GMT</pubDate>
			<author>donotreply@osnews.com (Nico57)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Hah.</title>
			<link>http://osnews.com/thread?217047</link>
			<guid isPermaLink="true">http://osnews.com/thread?217047</guid>
			<description>The example won't work on my machine, since my boot.ini is on F: <img src="/images/emo/wink.gif" alt=";)" /> <br />
<br />
Worth noting it doesn't work in Opera either.<br />
<br />
It's an interesting example - the javascript engines in both IE and FF only allow the most recent keypresses to be added to a file input... I think the example is a bit more complex than it needs to be - I'm gonna have to play with this. It should be possible to simply use the return state and CSS layering to do this a LOT simpler than how this example is working.</description>
			<pubDate>Tue, 27 Feb 2007 21:18:00 GMT</pubDate>
			<author>donotreply@osnews.com (deathshadow)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>MS said it doesn't work on Vista...</title>
			<link>http://osnews.com/thread?217048</link>
			<guid isPermaLink="true">http://osnews.com/thread?217048</guid>
			<description>Yeah, sure, since Vista doesn't have a boot.ini it's not affected. <img src="/images/emo/grin.gif" alt=";)" /></description>
			<pubDate>Tue, 27 Feb 2007 21:18:00 GMT</pubDate>
			<author>donotreply@osnews.com (Nico57)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: MS said it doesn't work on Vista...</title>
			<link>http://osnews.com/thread?217050</link>
			<guid isPermaLink="true">http://osnews.com/thread?217050</guid>
			<description>Good point - in fact I believe I read that this problem exists on Firefox on Linux as well - allowing the upload of a file that the user has access to (i.e. /etc/passwd if the user is root) - would be interesting to see the same exploit written for that scenario <img src="/images/emo/grin.gif" alt=";)" /> <br />
<br />
update: oh, someone did<br />
<a href="http://www.thanhngan.org/fflinuxversion.htmlEdited" rel="nofollow">http://www.thanhngan.org/fflinuxversion.htmlEdited</a> 2007-02-27 21:30</description>
			<pubDate>Tue, 27 Feb 2007 21:21:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: Didn't work</title>
			<link>http://osnews.com/thread?217069</link>
			<guid isPermaLink="true">http://osnews.com/thread?217069</guid>
			<description>hey dude, I am running XP SP2 with all the latest patches applied and Firefox 2.0.2 and this exploit NO LONGER WORKS. So next time get your story straight and then post.</description>
			<pubDate>Tue, 27 Feb 2007 22:49:00 GMT</pubDate>
			<author>donotreply@osnews.com (cg0def)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Didn't work</title>
			<link>http://osnews.com/thread?217137</link>
			<guid isPermaLink="true">http://osnews.com/thread?217137</guid>
			<description><i>I am running XP SP2 with all the latest patches applied and Firefox 2.0.2 and this exploit NO LONGER WORKS</i><br />
<br />
Same here, and it works fine.  Damn, must suck when you can't even get a perfectly working exploit to work <img src="/images/emo/wink.gif" alt=";)" /></description>
			<pubDate>Wed, 28 Feb 2007 00:35:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[4]: Didn't work</title>
			<link>http://osnews.com/thread?217156</link>
			<guid isPermaLink="true">http://osnews.com/thread?217156</guid>
			<description>Just to reiterate, yes it does work with Firefox 2.0.0.2 and XP SP2.</description>
			<pubDate>Wed, 28 Feb 2007 01:05:00 GMT</pubDate>
			<author>donotreply@osnews.com (smitty)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: MS said it doesn't work on Vista...</title>
			<link>http://osnews.com/thread?217171</link>
			<guid isPermaLink="true">http://osnews.com/thread?217171</guid>
			<description>&gt;&gt; Yeah, sure, since Vista doesn't have a boot.ini<br />
&gt;&gt; it's not affected. <img src="/images/emo/grin.gif" alt=";)" /> <br />
<br />
The example doesn't work - the technique <i>i</i>tself DOES. Theoretically you could pull a<i>n</i>y <i>f</i>ile, s<i>o</i> long as you were able to get the user to type in ALL the characters in the filename in the order you want them<i>.</i>.. Which is why embedding <i>t</i>his into a blog, forums or any other large te<i>xt</i> entry box could be a easy way to gather information...<br />
<br />
The above paragraph for example, could (in theory) be used to pull info.txt from the current default browser upload directory (notice the bits in italic)<br />
<br />
Would be interesting to see if it could be exploited by making it look like some kind of captcha.Edited 2007-02-28 01:49</description>
			<pubDate>Wed, 28 Feb 2007 01:48:00 GMT</pubDate>
			<author>donotreply@osnews.com (deathshadow)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Ubuntu</title>
			<link>http://osnews.com/thread?217181</link>
			<guid isPermaLink="true">http://osnews.com/thread?217181</guid>
			<description>Running Ubuntu Edgy with Firefox 2.0.0.2 and it does not work.</description>
			<pubDate>Wed, 28 Feb 2007 02:50:00 GMT</pubDate>
			<author>donotreply@osnews.com (lawina)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: MS said it doesn't work on Vista...</title>
			<link>http://osnews.com/thread?217190</link>
			<guid isPermaLink="true">http://osnews.com/thread?217190</guid>
			<description>:D</description>
			<pubDate>Wed, 28 Feb 2007 03:51:00 GMT</pubDate>
			<author>donotreply@osnews.com (Nico57)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[2]: MS said it doesn't work on Vista...</title>
			<link>http://osnews.com/thread?217245</link>
			<guid isPermaLink="true">http://osnews.com/thread?217245</guid>
			<description>Doesn't work too well. One has to write very very slowly for the example to work. But it does illustrate it, though.</description>
			<pubDate>Wed, 28 Feb 2007 13:07:00 GMT</pubDate>
			<author>donotreply@osnews.com (dylansmrjones)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE[3]: Didn't work</title>
			<link>http://osnews.com/thread?217338</link>
			<guid isPermaLink="true">http://osnews.com/thread?217338</guid>
			<description>Are you logged as an admin or a user with 'read' rights to C:boot.ini ?</description>
			<pubDate>Wed, 28 Feb 2007 20:01:00 GMT</pubDate>
			<author>donotreply@osnews.com (Snifflez)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>Konqueror</title>
			<link>http://osnews.com/thread?217413</link>
			<guid isPermaLink="true">http://osnews.com/thread?217413</guid>
			<description>By default, Konqueror asks the user for confirmation when sending a local file. Simple and effective, whatever tricks the webpage may use to set the input to a malicious value.</description>
			<pubDate>Wed, 28 Feb 2007 23:10:00 GMT</pubDate>
			<author>donotreply@osnews.com (moltonel)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>NoScript</title>
			<link>http://osnews.com/thread?217424</link>
			<guid isPermaLink="true">http://osnews.com/thread?217424</guid>
			<description>Everyone should just use NoScript on Firefox. Makes things so much easier, vast majority of the new exploits don't work without javascript.<br />
<br />
NoScript is pretty good at managing javascript permissions.</description>
			<pubDate>Wed, 28 Feb 2007 23:33:00 GMT</pubDate>
			<author>donotreply@osnews.com (Wintermute)</author>
			<category>Comments</category>
		</item>

		<item>
			<title>RE: Konqueror</title>
			<link>http://osnews.com/thread?217477</link>
			<guid isPermaLink="true">http://osnews.com/thread?217477</guid>
			<description><i>Konqueror asks the user for confirmation when sending a local file</i><br />
<br />
And I would hope this is exactly what will be done with Firefox.  That feature along with whitelisting support should be sufficient, and I mean jeez - how often do people upload to a website.  Usually one uses just a few such sites regularly (email, photo sharing...)<br />
<br />
Not sure about IE, Microsoft has a habit of doing stupid things to &quot;fix&quot; exploits.</description>
			<pubDate>Thu, 01 Mar 2007 03:22:00 GMT</pubDate>
			<author>donotreply@osnews.com (umccullough)</author>
			<category>Comments</category>
		</item>
	</channel>
</rss>
