|
|||||||||||
|
Minimo .2 and more Firefox 2.0.0.6 Password Manager Vulnerabilites
From: Seth Fogie <seth(at)airscanner.com>
Date: Thu Aug 02 2007 - 13:52:26 EDT
Airscanner Mobile Security Advisory #07080102: Minimo <=.2 and Firefox
2.0.0.6 Product:
http://airscanner.com/security/07080103_minimo.2.htm
Platform:
Requirements:
Credits:
Risk Level:
Program Summary:
Minimo uses Mozilla Technologies to produce a highly usable web browser
for advanced mobile devices. Features include:
Vulnerability Details:
Note: The Password Manager bug is often misunderstood for how it work. The reason is that there are numerous subtle variations on how the username and password show up. The following highlights some of these:
Similar Firefox bugs has been known about since mid-2006; however, https://bugzilla.mozilla.org/show_bug.cgi?id=360493#c44 indicates these are supposedly resolved. The details and vulnerable status of Minimo .2 and below is new. Proof of Concept The following webpage provides a link to two pages. The login.php page is just a sample form that you can enter a user/pass into. Enter and save some sample info and then click on the second poc.htm link. This will open a page with a script inside that dynamically creates a framed environment, one of which is essentially hidden (note: using style:hidden will not work). In the hidden frame, the login.php page is loaded, the action is changed, and the user/pass are tickled into the form fields. You should see two popups - one with the changed form action, and the other with the stored user & pass variables. http://www.airscanner.com/tests/minimo.htm
Workaround:
Vendor Response:
Copyright (c) 2007 Airscanner Corp. Permission is granted for the redistribution of this alert electronically. It may not be edited in any way without the express written consent of Airscanner Corp. If you wish to reprint the whole or any part of this alert in any other medium other than electronically, please contact Airscanner Corp. for permission. Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently available information. Use of the information constitutes acceptance for use on an AS IS condition. There are no warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information. Received on Thu Aug 2 14:53:51 2007 This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:10:44 EDT |
||||||||||
|
|||||||||||