<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iTechLog &#187; Browser Security</title>
	<atom:link href="http://itechlog.com/tag/browser-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://itechlog.com</link>
	<description>Your source to IT solutions, interesting technology news and a hint of Space and Physics.</description>
	<lastBuildDate>Wed, 09 May 2012 13:02:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Firefox Vulnerability</title>
		<link>http://itechlog.com/security/2009/03/26/firefox-vulnerability/</link>
		<comments>http://itechlog.com/security/2009/03/26/firefox-vulnerability/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 16:29:08 +0000</pubDate>
		<dc:creator>Alex Costa</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[bug 485217]]></category>
		<category><![CDATA[Firefox security]]></category>
		<category><![CDATA[Mozilla]]></category>

		<guid isPermaLink="false">http://itechlog.com/security/2009/03/26/firefox-vulnerability/</guid>
		<description><![CDATA[<a href="http://itechlog.com/security/2009/03/26/firefox-vulnerability/" title="Firefox Vulnerability"></a>Security Focus has published a vulnerability found on Firefox (all releases and platforms) causing a serious security flaw. An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious file using the affected browser. Exploit code &#8230;<p class="read-more"><a href="http://itechlog.com/security/2009/03/26/firefox-vulnerability/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<a href="http://itechlog.com/security/2009/03/26/firefox-vulnerability/" title="Firefox Vulnerability"></a><p><img style="max-width: 800px; float: left; margin-top: 10px; margin-bottom: 10px; margin-right: 10px;" src="http://itechlog.com/wp-content/uploads/2009/03/firefox.jpg" height="114" width="119" />Security Focus has published a <a href="http://www.securityfocus.com/bid/34235/info" target="_blank">vulnerability found on Firefox</a> (all releases and platforms) causing a serious security flaw. An attacker can exploit this issue by enticing an unsuspecting victim to view a malicious file using the affected browser. </p>
<p><font color="#666666"><i><em>Exploit code at the link iframes a little xml file with an xslt transform that causes a crash reliably on 3.0 branch and trunk (and presumably 1.9.1, didn’t test). Null, but it’s being called, assuming the worst for the moment.&nbsp; &#8211; </em></i><em><small>extracted</small></em></font></p>
<p>Mozilla developers have already <a target="_blank" href="https://bugzilla.mozilla.org/show_bug.cgi?id=485217">worked out&nbsp; a fix</a> which will be added to <a target="_blank" href="https://wiki.mozilla.org/Releases/Firefox_3.0.8">Firefox 3.0.8 which is due next week</a>.</p>
<div class="zemanta-pixie"><img class="zemanta-pixie-img" src="http://img.zemanta.com/pixy.gif?x-id=17feb71e-6482-80fc-a0ae-2d75cc421aff" /></div>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Browser+Security' rel='tag' target='_self'>Browser Security</a>, <a class='technorati-link' href='http://technorati.com/tag/bug+485217' rel='tag' target='_self'>bug 485217</a>, <a class='technorati-link' href='http://technorati.com/tag/Firefox+security' rel='tag' target='_self'>Firefox security</a>, <a class='technorati-link' href='http://technorati.com/tag/Mozilla' rel='tag' target='_self'>Mozilla</a></p>

<!-- end wp-tags-to-technorati -->
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li>August 1, 2011 -- <a href="http://itechlog.com/itechlog-news/2011/08/01/chrome-overtakes-firefox-uk-number-two-browser-spot-in-july/" title="Chrome Overtakes Firefox for UK Number Two Browser Spot in July">Chrome Overtakes Firefox for UK Number Two Browser Spot in July</a></li><li>July 21, 2009 -- <a href="http://itechlog.com/itechlog-news/2009/07/21/firefox-add-on-collector/" title="Firefox Add-on Collector">Firefox Add-on Collector</a></li><li>May 21, 2009 -- <a href="http://itechlog.com/open-source/2009/05/21/mozilla-fennec-the-firefox-gone-mobile/" title="Mozilla FENNEC &#8211; the Firefox gone mobile">Mozilla FENNEC &#8211; the Firefox gone mobile</a></li><li>December 17, 2008 -- <a href="http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/" title="Browser Password Security test &#8211; most failed">Browser Password Security test &#8211; most failed</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://itechlog.com/security/2009/03/26/firefox-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browser Password Security test &#8211; most failed</title>
		<link>http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/</link>
		<comments>http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 00:37:17 +0000</pubDate>
		<dc:creator>Alex Costa</dc:creator>
				<category><![CDATA[Itechlog News]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[CIS]]></category>
		<category><![CDATA[Firefox]]></category>

		<guid isPermaLink="false">http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/</guid>
		<description><![CDATA[<a href="http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/" title="Browser Password Security test - most failed"></a>Google Chrome and Safari are tied at the bottom of the list of a password security test run by CIS - Chapin Information Services. Two years ago CIS discovered a flaw on Mozilla that could give &#8220;clever attackers&#8221; access to &#8230;<p class="read-more"><a href="http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/">Read more &#187;</a></p>]]></description>
			<content:encoded><![CDATA[<a href="http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/" title="Browser Password Security test - most failed"></a><p>Google Chrome and Safari are tied at the bottom of the list of a password <a href="http://www.info-svc.com/news/2008/12-12/" target="_blank">security test run by CIS </a>- Chapin Information Services.</p>
<p>Two years ago CIS <a href="http://www.info-svc.com/news/11-21-2006/" target="_blank">discovered a flaw on Mozilla</a> that could give &#8220;clever attackers&#8221; access to your saved passwords. A few days ago CIS ran a security test on all the major browsers and to their horror and surprise most of them did really badly, including Internet Explorer.</p>
<p>Among the problems are three in particular that, when combined,<br />
allow password thieves to take passwords without the user’s knowledge.<br />
They are:</p>
<ol>
<li>The destination where passwords are sent is not checked.</li>
<li>The location where passwords are requested is not checked.</li>
<li>Invisible form elements can trigger password management.</li>
</ol>
<p><span id="more-144"></span></p>
<p><a title="Test Results" href="http://itechlog.com/wp-content/uploads/2008/12/browser_pwd_managers.jpg" target="_blank"><img src="http://itechlog.com/wp-content/uploads/2008/12/browser_pwd_managers.jpg" alt="" width="472" height="317" /></a></p>
<p>You can <a href="http://www.info-svc.com/news/2008/12-12/pm-evaluator/" target="_blank">test your own browser</a> at the CIS website.</p>

<!-- start wp-tags-to-technorati 1.02 -->

<p class='technorati-tags'>Technorati Tags: <a class='technorati-link' href='http://technorati.com/tag/Browser+Security' rel='tag' target='_self'>Browser Security</a>, <a class='technorati-link' href='http://technorati.com/tag/Chrome' rel='tag' target='_self'>Chrome</a>, <a class='technorati-link' href='http://technorati.com/tag/CIS' rel='tag' target='_self'>CIS</a>, <a class='technorati-link' href='http://technorati.com/tag/Firefox' rel='tag' target='_self'>Firefox</a></p>

<!-- end wp-tags-to-technorati -->
<h3  class="related_post_title">Related Posts</h3><ul class="related_post"><li>August 1, 2011 -- <a href="http://itechlog.com/itechlog-news/2011/08/01/chrome-overtakes-firefox-uk-number-two-browser-spot-in-july/" title="Chrome Overtakes Firefox for UK Number Two Browser Spot in July">Chrome Overtakes Firefox for UK Number Two Browser Spot in July</a></li><li>January 20, 2011 -- <a href="http://itechlog.com/web-design/2011/01/20/push-up-the-web/" title="Push up the Web">Push up the Web</a></li><li>October 25, 2010 -- <a href="http://itechlog.com/security/2010/10/25/laptop-mobile-and-firefox-security/" title="Laptop, mobile and Firefox security">Laptop, mobile and Firefox security</a></li><li>September 6, 2010 -- <a href="http://itechlog.com/itechfeed/2010/09/06/echofon-shamefully-drops-firefox-for-linux/" title="Echofon shamefully drops Firefox for Linux">Echofon shamefully drops Firefox for Linux</a></li><li>May 21, 2009 -- <a href="http://itechlog.com/open-source/2009/05/21/mozilla-fennec-the-firefox-gone-mobile/" title="Mozilla FENNEC &#8211; the Firefox gone mobile">Mozilla FENNEC &#8211; the Firefox gone mobile</a></li></ul>]]></content:encoded>
			<wfw:commentRss>http://itechlog.com/itechlog-news/2008/12/17/browser-password-security-test-most-failed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

