Our Community is 940,000 Strong. Join Us.


Warning major vulnerabily in all browsers!!!


Neutrino
12-08-2004, 11:38 PM
its called a Window Injection Vulnerability

test your browser here. It will very likelly fail no matter what you have.


http://secunia.com/multiple_browsers_window_injection_vulnerability_t est/

their advice so far is:
Solution:
Do not browse untrusted sites while browsing trusted sites.

pre98zetec
12-09-2004, 03:08 AM
Man your not going to beleive this, But when I did the test on Avant I didn't get the pop up, I did on Firefox though. :lol2:

Neutrino
12-09-2004, 10:50 AM
Man your not going to beleive this, But when I did the test on Avant I didn't get the pop up, I did on Firefox though. :lol2:


did you get any pop up at all?

pre98zetec
12-09-2004, 12:10 PM
on firefox I did, Avant I didn't.

Neutrino
12-09-2004, 12:11 PM
on firefox I did, Avant I didn't.


that is not good either, because what you should've got was a pop up from citibank.

pre98zetec
12-09-2004, 12:15 PM
I got one from citibank but I also got another pop up showing text from that Secunia site, Avant I just got the CitiBank site when I clicked the second link. No pop up at all.


And now I redo the test on Firefox and get no pop up, just the citibank site :sly:

Neutrino
12-09-2004, 12:42 PM
well firefox has a pop up blocker built in so you should test it only with the first link. Same goes for advant if it has a pop up blocker.


Also to do the test properly you should refresh the secunia test page between tests.

Phieta
12-09-2004, 10:47 PM
Just tested with Firefox 1.0... wasn't vulnerable, though according to the site, it should have been. Weird.

Neutrino
12-09-2004, 11:09 PM
Just tested with Firefox 1.0... wasn't vulnerable, though according to the site, it should have been. Weird.


did you click on this link?:
Test Now - With Pop-up Blocker

because firefox has a popup blocker and clicking on the other link(Test Now - Without Pop-up Blocker) will render the test invalid


I have firefox 1.0 too and it was vulnerable. It seems to be the only firefox vulnerabily without a pach so far. I'm sure they are working on it though

Phieta
12-10-2004, 07:17 PM
did you click on this link?:
Test Now - With Pop-up Blocker

Aye. Though, I did it a second time right afterward and it was vulnerable.

Add your comment to this topic!