[38156] in bugtraq
Re: Firespoofing [Firefox 1.0]
daemon@ATHENA.MIT.EDU (Pavel Kankovsky)
Tue Jan 11 18:26:55 2005
Date: Tue, 11 Jan 2005 21:15:02 +0100 (MET)
From: Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
To: mikx <mikx@mikx.de>
Cc: full-disclosure@lists.netsys.com, bugtraq@securityfocus.com,
NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
In-Reply-To: <00c801c4f76b$36346020$280207d5@netvision.ads>
Message-ID: <20050111205452.5AC2.0@argo.troja.mff.cuni.cz>
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
On Tue, 11 Jan 2005, mikx wrote:
> The bug is confirmed but currently unfixed (open for more than 3 months). As
> a partial workaround set dom.disable_window_flip to true in about:config.
Setting most of dom.disable_window_open_feature.* to true (and making it
impossible to remove browser "decorations" from browser windows) is a
pretty efficient (even if not 100% bullet-proof) way to thwart this kind
of attack. As well as other GUI spoofing attacks.
--Pavel Kankovsky aka Peak [ Boycott Microsoft--http://www.vcnet.com/bms ]
"Resistance is futile. Open your source code and prepare for assimilation."