Jump to content

Browser security test


CeeCee

Recommended Posts

I guess I don't understand it. It says I have 1 medium risk vulnerability "Mozilla XMLSerializer Same Origin Policy Violation Vulnerability (bid5766)" and recommends I should upgrade to Mozilla 1.0.2 or later. The only Mozilla app I'm using is FireFox 2.0.0.5 so I don't know what I'm supposed to do.

Link to comment
Share on other sites

That was posted a while back I think. Never used to work for me on Firefox but works now. Not sure how much use it is though - FF passes, IE passes, I even fired up the sodding awful AOL browser and that passed :blink:

Link to comment
Share on other sites

Since their latest security news is from 2005 I consider this a bit out of date.....

 

Actually I tried this back then as well, lets see how I go this time.

 

Same as last time 1 risk:

 

Medium Risk Vulnerabilities

 

Mozilla XMLSerializer Same Origin Policy Violation Vulnerability (bid5766)

 

Description

This bug can allow a malicious web site to access your data on other web sites. For example it can be used to read you mail from a web mail system.

 

Mozilla is an open source browser. From Netscape 6 onwards, Mozilla's source code has been used to create Netscape browser. As a result, Netscape suffers from many of the same vulnerabilities as Mozilla.

 

Other browsers, such as Galeon, Phoenix, Camino (Chimera) also use Mozilla's source code and can be vulnerable too.

 

 

Technical Details

XMLSerializer object can be created by JavaScript code and used to serialize XML (or HTML) documents. serializeToStream method does not enforce same origin policy.

 

It is possible to open a document in a different domain and then use serializeToStream method to get the contents of the document.

 

 

Recommendations

 

  • Netscape users need to upgrade to Netscape 7.01 or later to fix this vulnerability.
  • Mozilla users need to upgrade to version 1.0.2 or later
  • Galeon users - upgrade your Mozilla installation to version 1.0.2 or later and upgrade to Galeon version that supports it (1.2.6 or later)
  • Phoenix users - upgrade to Phoenix 0.5 or later
  • Camino (Chimera) users - upgrade to version 0.7

 

Additional Information

 

 

fireryone

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.