• Our software update is now concluded. You will need to reset your password to log in. In order to do this, you will have to click "Log in" in the top right corner and then "Forgot your password?".
  • Welcome to PokéCommunity! Register now and join one of the best fan communities on the 'net to talk Pokémon and more! We are not affiliated with The Pokémon Company or Nintendo.

Very, very dangerous generic hole in almost all browsers found!

Poke Trainer Gary

Optimistic
  • 43
    Posts
    15
    Years
    Hi malware fighters,

    There is a new very dangerous generic gaping browser hole that affects all browsers (only the lynx browser is secure from it), and makes an attacker can take over the browser completely. It is almost impossible to patch, because it is inherent to the way modern browsers work.
    NoScript add-on for Fx works in almost 100% of the cases against this, but Giorgio Maone advises to enable the "Plugins|Forbid IFRAME" option.
    It seems like the exploit basically creates a frame that is hidden underneath the main content frame that a user is seeing. The main content could be a flash game or any sort of incentive to keep a user clicking. All of the clicks that the user is making are used to click on content in the hidden frame. Again, just my speculation based on the information provided by RSnake and Jeremiah above in a limited disclosure.

    In a nutshell, it's when you visit a malicious website and the attacker is able to take control of the links that your browser visits. The problem affects all of the different browsers except something like lynx. The issue has nothing to do with JavaScript so turning JavaScript off in your browser will not help you. It's a fundamental flaw with the way your browser works and cannot be fixed with a simple patch. With this exploit, once you're on the malicious web page, the bad guy can make you click on any link, any button, or anything on the page without you even seeing it happening.
     

    Innocence

    PC Lurker: I'm watching you...
  • 1,041
    Posts
    19
    Years
    Scary, but I fail to see the practical use. Any executable file downloads will still show a warning if activated, and it's difficult to do any real damage without having the user download your virus/malware.

    I understand cookies etc. could hurt, but the main thing is, stay away from seedy sites.

    -Ryan
     
  • 7,741
    Posts
    17
    Years
    • Seen Sep 18, 2020
    I find it funny that people announce these things for all hackers to see, as you just did.
    I have many browsers, including Lynx, so there's a reason to use it if I ever needed one. ¦D
     
  • 1,024
    Posts
    16
    Years
    Ok well I already have Firefox and NoScript so I thought I was already immune to attacks from most shady sites but now from what you said that its better to forbid IFRAME I have just done it now.
     
    Last edited:

    Zet

  • 7,690
    Posts
    16
    Years
    it's easier not to be stupid enough to go onto a site that has a person who would take all that time just to find the right coding to do that
     
    Back
    Top