bugtraq
[Top] [All Lists]

Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerabilit

To: "pdp (architect)" <pdp.gnucitizen@googlemail.com>
Subject: Re: [Full-disclosure] Firefox bookmark cross-domain surfing vulnerability
From: Daniel Veditz <dveditz@cruzio.com>
Date: Thu, 22 Feb 2007 17:23:13 -0800
Cc: Michal Zalewski <lcamtuf@dione.ids.pl>, security@mozilla.org, bugtraq@securityfocus.com, full-disclosure@lists.grok.org.uk
Delivered-to: sp-com-lists@consult.net
Delivered-to: bugtraq-list@securepoint.com
Delivered-to: mailing list bugtraq@securityfocus.com
Delivered-to: moderator for bugtraq@securityfocus.com
In-reply-to: <6905b1570702220512i51bc09cdt493a48d78ce93182@mail.gmail.com>
List-help: <mailto:bugtraq-help@securityfocus.com>
List-id: <bugtraq.list-id.securityfocus.com>
List-post: <mailto:bugtraq@securityfocus.com>
List-subscribe: <mailto:bugtraq-subscribe@securityfocus.com>
List-unsubscribe: <mailto:bugtraq-unsubscribe@securityfocus.com>
Mailing-list: contact bugtraq-help@securityfocus.com; run by ezmlm
References: <Pine.LNX.4.58.0702220046430.6282@dione> <6905b1570702211617k183d9260i9e00ed6f80accd73@mail.gmail.com> <Pine.LNX.4.58.0702220146180.6282@dione> <6905b1570702220512i51bc09cdt493a48d78ce93182@mail.gmail.com>
User-agent: Thunderbird 1.5.0.10pre (Windows/20070221)
pdp (architect) wrote:
> However, here is an interesting thought for you: instead of asking the
> user into bookmarking a page you can supply the bookmark directly to
> their browser by using Live Bookmarks. So, a mainstream attack will be
> when a SPLOG network injects malicious links into their feeds. If
> someone happens to be subscribed to this network with a Live Bookmark
> and they click on it... well you know.
> 
> I haven't tested this, although it should work.

It doesn't work -- thankfully we thought of that back when we implemented
Live Bookmarks in Firefox 1.0

<Prev in Thread] Current Thread [Next in Thread>