Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.
|
|||||||
Download Now:
Critical Firefox 3.5 bug discovered
|
|
Thread Tools | Search this Thread |
|
#1
|
||||
|
||||
|
Critical Firefox 3.5 bug discovered
US-CERT posted a warning yesterday, of a critical vulnerability affecting the recently launched Firefox 3.5. The bug is due to an error in the way JavaScript code is processed. By exploiting this anomaly, an attacker may be able to execute arbitrary code. Furthermore, exploit code is publicly available for this vulnerability.
Read the whole story
__________________
"Dependence begets subservience and venality, suffocates the germ of virtue, and prepares fit tools for the designs of ambition." -Thomas Jefferson
|
|
#2
|
||||
|
||||
|
No Script to the Rescue.......
The article goes on to state the problem is with a Java Script exploit, so......
Everyone should install the "No Script" add-on. Regardless of which version of FF you're using. FF2 is probably as safe or safer than a newer version with this extension operating. It's like a bloody miracle! |
|
#3
|
||||
|
||||
|
but then you can't run Java script?
|
|
#4
|
||||
|
||||
|
On the upside, neither can the a**holes who are trying to hack your computer.
Besides, you can "white list" any site you want, just by clicking on the "S" icon at the bottom of the screen. Answer "B": Unless you actually want to be annoyed with "Vibrance" ads you generally don't have to permit Java anyway. Go to the site and check it out for yourself... http://noscript.net/ Last edited by captaincranky; 07-15-2009 at 12:21 PM.. |
|
#5
|
||||
|
||||
|
oooww! ok sweet! as long as theres a white list I shall go get this now! =)
cheers for the advice. |
|
|
|
#6
|
|||
|
|||
|
First of all, Java is not the same as Javascript. They're not even second cousins once removed...
Secondly; Javascript is used by almost every major website in the world today ( I say almost because there might be one or two who don't use it ) for a lot more than serving ads... Think Ajax, visual effects, statistics, dynamic HTML, etc... To say that "you generally don't have to permit Java[script] anyway" is about the same as saying "you generally don't have to permit images anyway", or "you generally don't have to permit stylesheets anyway"... It's kind of true, but then again, why aren't you using Lynx to browse the web? |
|
#7
|
||||
|
||||
|
I enjoy the Internet and the media-rich content is has to offer.
Much like I wouldn't cover a leather sofa with a sheet of plastic to protect it, I'm not going to turn off JavaScript. I hope many other people feel the same way. |
|
#8
|
||||
|
||||
|
Some people here don't use No-Script? I can't imagine not using it while on FF its one of the greatest add-ons...it's rather easy to turn on/off depending on the site you're on.
|
|
#9
|
||||
|
||||
|
Quote:
As I said before, "No Script" allows "white listing", so you you can accept or reject as much content as your security software can handle. Why are "guest" (anonymous) posts always the most abrasive? And for the record, "Guest", most sites do not require Java script running to display images. And the reason I don't use "Lynx" to browse the web is because I don't need it, I have "No-Script". Last edited by captaincranky; 07-15-2009 at 08:56 PM.. |
|
#10
|
||||
|
||||
|
Wow, another amazingly friendly 'Guest' user
|
|
#11
|
||||
|
||||
|
I'm like an oracle, you say they're abrasive, they predictably become more so. I suppose it easier than thinking of something worthwhile to say. "Hence I shall remain anonymous", how convenient. Most of our guest posers, er I mean posters would probably spend their time in a more worthwhile manner trashing celebrities at OK magazine's site.
|
|
#12
|
||||
|
||||
|
Hehe
I suspect it's the pleasant Guest user that was showing the same level of immaturity in this post here |
|
#13
|
||||
|
||||
|
Reruns of "Profiler"......Or, Have You Seen "Criminal Minds".....?
See, all along I've thought that Techspot has needed a behavioral analysis unit/thread.
My money's on a 13 year old closet case with a big mouth, little ****, and daddy's computer. Will the mystery guest sign in please? Oh, never mind, please spare us. |
|
#14
|
|||
|
|||
|
Just use a more secure browser, Opera has had less security flaws and it has way more features out of the box than the touted Firefox security do has a larger attack profile. Admittedly the first two Firefox has been secure but since the release of three there's been update after update to the browser. Quality control has gone to the dogs with Mozilla, and it's starting to tarnish them. They now seem to put more premium on 'features' than they do on security.
Firefox has done wonders for the web, but come on start growing up and releasing more secure software please? Even IE is becoming more 'secure'. |
|
#15
|
||||
|
||||
|
Quote:
I always find it rather silly to suggest, (as many,many people often do), that all security flaws should be worked out before the product's release. Many individuals are working in different directions on such a large project, and preconceiving all the different possible future exploits that another group out people might eventually uncover, seems, (to me at least), a comprehensively unrealistic expectation. We're on the same page however with which version of FF is the best browsing experience, as I still use, (and trust), V2.xxxx. As to your assertion that Opera is the best, let me say this, I have and use Opera, it's a decent product, but (to me at least), has its own sets of quirks. For example, with an extended download, (IE, a Linux distro), after a certain point, the browser crashes to unresponsiveness, taking out most of the graphics in my internet machine. So we're clear, the download does continue to a successful conclusion, but it's even difficult to access "Spider Solitare" in the meantime. As I stated above, any version of FF can be improved with the addition of "No Script". You can confront yourself with as much crap advertising as you can handle, test your security software's fortitude, and experience all of the media richness you desire, simply by white listing whatever content pleases you. Call me miss informed, or crazy, your choice, but I don't seem to need extended attention in the malware removal forum, and I attribute this in part to the script blocking add-on. |
|
#16
|
|||
|
|||
|
I am interested in what the symptoms are of this bug. I battled one all day yesterday after finally being able to get rid of it. It would not allow me to get to any virus software to download it and if it did it would let me run it. My virus protection did not catch it and the whole time I kept getting java script errors.
|
|
#17
|
||||
|
||||
|
3.5.1 has fixed the issue. Carry on.
|
|
#18
|
|||
|
|||
|
Hi, it's me again.
First of all, if my post came across as abrasive, that's unfortunate, and not really intended. Snowchick7669: No, I am not that user from whatever thread. And let me know where you find something immature in my previous post. Critical and abbrasive != immature. CaptainCranky: I never said anything about sites using javascript to show images. I was simply equating your blanket statement with another, equally silly statement. Also, no, I will not sign in. I really don't need another account on some tech board. I stand by my earlier statement: JavaScript is used by most, if not all, major websites in the world today, and by blocking it, you lose out on scores of design and functionality improvements. Turning off javascript will effectively cripple your browser. Last edited by Matthew; 07-22-2009 at 09:48 AM.. Reason: Stripped the super abrasive crap out. Let's not have to close the thread, c'mon people. |
|
#19
|
||||
|
||||
|
To "No Script", or to Not "No Script"..That is the Question
Quote:
Quote:
Quote:
But as to the topic. Certain sites do require Java running to gain access to their image library, and/or to view them, at least at full resolution. So, I think you've misinterpreted what I said. Or, in a spirit of co-operation, I was unable to state my point effectively. Quote:
First, "No Script" blocks pop-up ads, such as vibrance, and most flash from the jump. Why this is seen as a bad thing, I have no idea. Second, my understanding is that script is still running within the browser itself, and the add-on is merely preventing sites from running it in the browser. And more specifically, preventing third party sites from inflicting script on you. As I stated earlier, you can "white list" any site you desire, allow any, (or all), "interested parties", at your discretion or for that matter peril. One particular "interested party" is "Google Analyltics", and I think that the first part of the second word speaks volumes about that. So, basically wherever you go, and whenever you go there, Google is running script that basically, puts their inquisitive nose up your unsuspecting a**! Hey, but it's your call, white list it, they deserve to know, just ask them. I ignored this extension for many months, and was very skeptical about its usefulness. Now, quite simply, I "don't leave home without it"! |
|
#20
|
|||
|
|||
|
Quote:
Quote:
Quote:
Personally, I have never felt the need for such an app, and malware is a non-occurring phenomenon on my computers. |
![]() |
| Similar Topics | ||||
| Topic | Replies | Forum | ||
Firefox 3.6.2 released, plugs critical security hole
|
9 | TechSpot News and Comments | ||
Firefox update addresses critical security hole
|
8 | TechSpot News and Comments | ||
Mozilla patches 9 Firefox bugs, four critical
|
1 | TechSpot News and Comments | ||
just discovered you
|
2 | Introduce yourself | ||
| Thread Tools | Search this Thread |
|
|
All times are GMT -4. The time now is 04:54 PM.




Firefox 3.6.2 released, plugs critical security hole