stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Mozilla Fails to Restrict Access to "shell:"







Mozilla Fails to Restrict Access to
"shell:"

Mozilla Fails to Restrict Access to
"shell:"
07/10/2004 11:02 AM

“This notice covers BOTH a security concern and a DOS. 1)Using the ‘shell:’ prefix in addresses on a windows PC allows access to the local file system. AFAIK all shell shortcuts in IE will also work in mozilla. Addresses such as ‘shell:cookies’ passes the call to explorer and it shows the desired location. Address to individual files or cookies are handled by Mozilla and treated as a ‘file:’ protocol. While I have not looked into the exploitability of this behavior, it would seem to be a security risk as IE has supposedly dropped this functionality in SP1 for IE 6. 2) By making a request for a file that does not exist on the user’s system using the ‘shell:’ prefix, Mozilla will continue to open windows until the user’s system crashes.” The resolution is to apply a patch or update to the latest version.




This is a GrokNews Entry: (what is grok?)





Similar Items

Mozilla Fails to Restrict Access to "shell:"

Grok Headline matches for Mozilla Fails to Restrict Access to "shell:"

Microsoft Products Fail to Restrict
"shell:" Access


Microsoft Products Fail to Restrict
"shell:" Access
07/13/2004 10:33 AM
“Jesse Ruderman has reported a vulnerability in MSN Messenger and Microsoft Word, allowing access to the Windows ‘shell:’ functionality….Solution: Do not follow links in MSN Messenger. Do not follow links from Word documents originating from untrusted sources.”

IE vs. Mozilla on the Shell Hole—Whose
Bug Is It?


IE vs. Mozilla on the Shell Hole—Whose
Bug Is It?
07/12/2004 02:35 PM
Opinion: Mozilla exposed the scheme, opened the hole. Now it's a debate in security circles. But the only way this is a vulnerability in Windows is if it's a vulnerability for a shell to be able to run programs.

IE May Share Shell Hole Found in Mozilla


IE May Share Shell Hole Found in Mozilla 07/13/2004 08:29 PM
Security firm Secunia reports four new "extremely critical" vulnerabilities in Internet Explorer that have some security experts asking whether any commercial browser can ever be secure.

MOZILLA: SHELL can execute remote EXE
program


MOZILLA: SHELL can execute remote EXE
program
07/12/2004 02:15 PM
liudieyu_at_umbrella.name (Jul 08 2004)

Timeline of Mozilla shell: Security
Vulnerability


Timeline of Mozilla shell: Security
Vulnerability
07/09/2004 10:04 PM

Use different home directories for GUI
and shell access


Use different home directories for GUI
and shell access
01/03/2005 11:55 AM
If you're like me and you regularly log into an OS X system from a remote location using Terminal, you most likely have a bunch of tools and scripts you regularly use. However, you also log on to the system using the GUI. Whe...

What Mozilla users should know about the
shell: protocol security issue


What Mozilla users should know about the
shell: protocol security issue
07/09/2004 08:02 AM
install this upgrade .. Hier de patch .. been released

mozilla.org/security/shell.html
track this site | 6 links


Webmail Access for Mozilla Thunderbird


Webmail Access for Mozilla Thunderbird 04/10/2005 11:40 PM
Finally, an extension to Mozilla Thunderbird which allows access to webmail! (One of the oft-most requested feature enhancements of the email client. Hooray for extensibility!) The Web-Mail extension creates a platform which other extensions use to integrate web based email accounts into Mozilla Thunderbird. POP is the only protocol supported, this means Thunderbird can only download emails. Currently supported via extensions: Hotmail (and MSN), Yahoo and Lycos. A step-by-step setup guide is available.

Access the Profile Manager for Mozilla
Thunderbird


Access the Profile Manager for Mozilla
Thunderbird
03/08/2004 11:18 PM
The Thunderbird email client features the ability to use multiple profiles on a single machine, much like its browser counterpart. However, there is no obvious way of accessing the Profile Manager with the Mac OS X version of...

Mozilla flaws could allow attacks, data
access


Mozilla flaws could allow attacks, data
access
04/18/2005 11:14 AM
Open-source specialist says vulnerabilities affect its namesake suite and the Firefox browser.

Vulns: Mozilla Browser Input Type HTML
Tag Unauthorized Access Vulnerability


Vulns: Mozilla Browser Input Type HTML
Tag Unauthorized Access Vulnerability
08/08/2004 03:46 PM
SecurityFocus Aug 8 2004 8:17PM GMT

Manage With the Windows Shell: Write
Shell Extensions with C#


Manage With the Windows Shell: Write
Shell Extensions with C#
06/30/2004 05:43 PM
In this article, Dino Esposito demonstrates how to create a Windows shell extension using C# code and the .NET Framework. He discusses the COM Interop layer and using a practical example, shows you techniques and tricks you need to know to build managed shell extensions.

Mozilla 1.7.1, Mozilla Firefox 0.9.2 and
Mozilla Thunderbird 0.7.2 Released


Mozilla 1.7.1, Mozilla Firefox 0.9.2 and
Mozilla Thunderbird 0.7.2 Released
07/08/2004 08:25 PM

Restrict MMC Snap-ins


Restrict MMC Snap-ins 09/01/2004 08:14 AM

Restrict Application Installations


Restrict Application Installations 06/13/2004 09:17 PM

New Patterns Restrict Hiring


New Patterns Restrict Hiring 03/06/2004 02:03 AM
While the economy has been expanding for six months, the nation's employers remain stubbornly reluctant to add jobs in the U.S.

Cuba tries to restrict the internet


Cuba tries to restrict the internet 01/10/2004 01:37 AM
Infoshop Jan 10 2004 0:03AM ET

CIA wants to restrict information in
Senate report


CIA wants to restrict information in
Senate report
06/16/2004 01:31 PM

Canada to restrict Internet drug sales


Canada to restrict Internet drug sales 06/24/2005 03:06 PM
Rockymountainnews.com - Fri Jun 24, 09:29 am GMT

Restrict Simple Finder users to only
certain applications


Restrict Simple Finder users to only
certain applications
08/27/2004 01:38 PM
The following hint was submitted by an anonymous tipster, who was somewhat uncertain if I should run it or not, as it does "reveal" a "security exploit" in OS X 10.3 However, I think it's fine to run, for a couple reasons. Fi...

Israel to restrict porn on cell phones


Israel to restrict porn on cell phones 12/27/2004 01:08 PM
ZDNet Dec 27 2004 5:14PM GMT

Music Industry DRM Firms Want You To Pay
To Restrict Your Fair Use


Music Industry DRM Firms Want You To Pay
To Restrict Your Fair Use
06/02/2004 02:58 PM

You know, I wrote this big, stupid rant (which is after the jump if you really want to read it) but let me cut to the quick: The music industry just took your lunch money, and now they want you to pay them to do it again.
Read [CNet via TechDirt< /a>]


California Senate Votes to Restrict
Google's Gmail


California Senate Votes to Restrict
Google's Gmail
05/27/2004 06:26 PM
Reuters-12 minutes ago1 Web search company, Google Inc., over concerns it could threaten the privacy of users. California's state Senate approved the ...

TELIASONERA: New technology to restrict
child pornography on Internet


TELIASONERA: New technology to restrict
child pornography on Internet
04/18/2005 11:49 PM
Kauppalehti Online Apr 19 2005 4:20AM GMT

Restrict keyboard input with this
quick-and-easy JavaScript


Restrict keyboard input with this
quick-and-easy JavaScript
09/21/2002 10:49 PM
CNET Sep 21 2002 10:01PM ET

U.S. May Restrict Sale of Social
Security Numbers (Reuters)


U.S. May Restrict Sale of Social
Security Numbers (Reuters)
03/17/2005 04:07 AM
Reuters - Seeking to combat rampant identity theft, U.S. lawmakers said on Thursday they may clamp new restrictions on companies that amass and sell social security numbers and other personal information.

L.A. Council Votes to Restrict
Superstores (Los Angeles Times)


L.A. Council Votes to Restrict
Superstores (Los Angeles Times)
08/11/2004 04:42 AM
Los Angeles Times - The Los Angeles City Council on Tuesday overwhelmingly backed a proposed law that would make it harder for Wal-Mart to erect superstores in the city by requiring the company to study whether surrounding areas would be harmed by the addition of the mammoth centers.

SCO may restrict Solaris, moves to push
IBM trial back


SCO may restrict Solaris, moves to push
IBM trial back
06/09/2004 05:35 PM
SYDNEY - Less than one week after Sun Microsystems Inc.'s chief operating officer Jonathan Schwartz pledged to open source its Solaris operating system, The SCO Group Inc. has stated that license restrictions prevent Sun from contributing its work to the GPL (General Public License).

California Senate Votes to Restrict
Google's Gmail (Reuters)


California Senate Votes to Restrict
Google's Gmail (Reuters)
05/27/2004 06:38 PM
Reuters - California's Senate voted on Thursday to support a bill to limit a new e-mail service by No. 1 Web search company, Google Inc., over concerns it could threaten the privacy of users.

disney's continued fight to restrict
speech through law as a tool against
competition


disney's continued fight to restrict
speech through law as a tool against
competition
05/25/2004 02:12 AM
As reported by Ernie, Disney is lobbying to get indecency regulations applied to cable -- yet another example (after the Sonny Bono Act) to use law to protect itself against competition. When your movies flop, and you've driven away the greatest animation company in the world, I guess there's not much strategy left.

Israeli Ministry to Restrict Porn on
Mobile Phones (Reuters)


Israeli Ministry to Restrict Porn on
Mobile Phones (Reuters)
12/26/2004 10:43 AM
Reuters - Israel's Communications Ministry said Sunday it amended licenses for mobile phone operators to restrict access to pornographic services following complaints that too many children were exposed to erotic material.

U.K. cell phone providers move to
restrict adult content


U.K. cell phone providers move to
restrict adult content
01/22/2004 02:13 AM
United Kingdom mobile providers team up to voluntarily censor online content.

RIAA Moves to Restrict Digital Radio
Home Recording


RIAA Moves to Restrict Digital Radio
Home Recording
06/17/2004 11:21 AM

CNet is reporting about the RIAA's appeal yesterday to the FCC to restrict end-users' ability to make home-recordings of music broadcasted over high-quality digital radio. Fortunately, the proposals are not going unopposed, as both consumer groups and electronics industry consortiums are pushing back against the RIAA's move to remove home-taping rights that consumers have had for years. Remember kids, Now That It's Digital, It's Wrong!
Read [CNet]


"Lawyers told Bush treaty banning
torture didn't restrict him "


"Lawyers told Bush treaty banning
torture didn't restrict him "
06/08/2004 08:23 PM

Ottawa moves to restrict music sharing
with proposed copyright reform


Ottawa moves to restrict music sharing
with proposed copyright reform
03/26/2005 01:01 PM
Canadian Press Mar 26 2005 5:03PM GMT

Yahoo! News Tech Tuesday Recommends
Mozilla 1.6 and Mozilla Thunderbird


Yahoo! News Tech Tuesday Recommends
Mozilla 1.6 and Mozilla Thunderbird
02/17/2004 11:55 PM

Comparative Mail Client Review Includes
Mozilla 1.6 and Mozilla Thunderbird 0.5


Comparative Mail Client Review Includes
Mozilla 1.6 and Mozilla Thunderbird 0.5
03/06/2004 01:59 AM

Mozilla Firefox Convert Robin Bloor
Switches to Mozilla Thunderbird


Mozilla Firefox Convert Robin Bloor
Switches to Mozilla Thunderbird
04/21/2004 05:07 PM

Introduction to Mozilla Firefox and
Mozilla Thunderbird for IE and Outlook
Express Users


Introduction to Mozilla Firefox and
Mozilla Thunderbird for IE and Outlook
Express Users
04/14/2005 04:08 PM

Grok Description matches for Mozilla Fails to Restrict Access to "shell:"
GrokA matches for Mozilla Fails to Restrict Access to "shell:"

Mozilla Fails to Restrict Access to "shell:"

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Back to Mercury
After 30 Years!

All the Mountain Dew
you can drink!

U.S. Marine Hassoun
Debriefed in Germany
(Reuters)

Bush Seeks Amendment
Against Gay Marriage
(AP)

Philippines Says
Hostage Freed in
Iraq (AP)

Our Airports,
Ourselves

Money, Politics, and
Four Rich Men

Interface Evolution
Dark Horse Comics
Presents Comic-Con
Contest Mania!

Three Years Of
Sideshow

Ma Bell should get
stingy

Americans Take Aid
to Cuba in Defiance
of Embargo

Freed Pakistan
Hostage Says Three
Beheaded in Iraq

BBC: British PM
Blair 'Considered
Resigning'

Bulgarians, Filipino
Under Death Threat
in Iraq

Politicians Must Not
Escape Blame Over
Iraq Intel Errors

2004-06-27T05:20:46
2004-06-27T16:09:52
2004-06-27T16:16:53
2004-06-27T16:20:47
2004-06-27T17:34:29
2004-06-28T16:25:11
2004-06-28T17:01:00
2004-06-28T17:08:53
2004-06-28T17:21:34
2004-06-28T21:56:22
2004-06-29T21:08:08
2004-06-29T21:49:21
2004-07-01T16:31:50
2004-07-01T19:40:43
2004-07-06T01:01:37
Free Download
Manager v0.9

The Rightness Of
Lightness
(washingtonpost.com)

OOo Tools
NomadSync
Gnocl
FOXNews executives
are preparing to hit
back hard -- if
rivals
self-servingly hype
the film!

Blogs, Bandwidth and
Banjos: Tightly knit
bonds in weblogging

Joe Wilson is an
Attention-Seeking
Jerk

Sport Relief: Will
you be taking part?

GM 'cow' protest at
supermarket

Georgia separatists
fuel tensions

F1: Raikkonen on
Silverstone pole

Carr lawyers act
over Mail story

alpha 2.x-Style-2
Fink 0.7.0
CVS_SNAP-20040710
(CVS)

JGraph 5.0 (For Java
1.3)

XChatOSD 5.11
(Module)

EU knows its cattle
better than its
citizens (Reuters)

Australian Surfer
Killed in Shark
Attack (Reuters)

what is grok?