[dylug] Re: Mozilla Warns of Firefox Security Holes

"nitin chandnani" <[email protected]> Thu, 03 Mar 2005 03:46:23 -0000
Newsgroups gmane.user-groups.linux.dylug
Message-ID <[email protected]>

Mr Malik
the only reason why MS would have hit STAR news is tht it wants to 
potray to plp tht they r really concerned about them..
but its just BULLSHIT casue even u know tht its their 
marketing strategy.....
its just tht MS wants to have its market caputered
so whtever any new S/W the rivals remove they 
brk it down to the core as they r the ones havin the complete
expretise and since it beeing a FREEWARE its very easy to 
get changes made in it...
m not favouring LINUX or WINDOWS its just to make this point 
tht if u think MS is for the plp then FORGET IT!!!
they r just into marketing casue even
they can feel if this trend of linux s/w n the OS as whole gets
compatible with windows the MS would be out off work very soon 
so its just the rival thing tht they wana tell plp they are taking 
care of them but really speaking they r the ones screwing the OS 
up...
just one more thing before i go...
LINUX is a freeware still we havent heard of VIRUS threats or hackin 
n stuff of LINUX as much as of windows....
n Y IS THE HOTMAIL SERVER RUNNING ON BSD?????n not on 2003server..
do u have any ans for it ....do u??? 
n trust me wht doc u have in for support 
anyone could do some research and get the same for MS....
;-)....


--- In [email protected], varun malik <varunone@y...> wrote:
> 
> Hi All,
> 
> How is everyone doing ? I was just checking out my Yahoo Groups 
Home Page and found that dygroups now has 61 members with the latest 
addition of Nitin. ( Welcome to the Group Nitin hope you have a nice 
time here. )
> 
> Now what i was wondering is have 61 members ... where is 
everyone ... Hardly 10-15 posts in 1month and half of them about 
jobs ... hmmm someone need to do something about it.
> 
> Amit, an interesting topic you came up with ... Sad only 1 
response. Anyways i think i rather go for free s/w cause at least 
then i can use it peacefully. Common open source is good, no doubt 
about it but tell me one thing ... if i give you the codes for Linux 
and charge you $100 will you still be that much interested in it. Or 
if i give you the codes that make gmail run and charge you for 
it ... fine you can open your own amit-mail but not everyone has the 
potential to do that.
> 
> Free makes more sense ... it reaches the masses.
> 
> And think about a clerk or a school teacher they need to use 
office suits, what good the code will be to them ??? At least using 
freeware they know they are not doing anything wrong and peacefully 
concentrate on their profession.
> 
> And fine if the guy who made it should get something out of it but 
HOW MUCH. Building Microsoft Office, must have cost bill gates a 
million but at the end of the day he made zillions.
> 
> I know many people will differ but these are my thoughts. 
Sometimes being computer engineers we forget that the rest of the 
world does not understand codes and needs what their brains can 
simply USE. Otherwise we'll loose our usefulness
> 
> A more serious issue came to my knowledge and i would like to 
share it with all. This one is specially for all my firefox loving 
friends who particularly hated my post against it. ( i am 
laughing ... u bet i am )
> 
> 
> Foundation releases an updated browser that includes fixes to many 
flaws.
> 
> Joris Evers, IDG News Service
> Monday, February 28, 2005
> 
> 
> Several security vulnerabilities in Firefox and the Mozilla Suite 
of Internet software put users of the open-source products at risk 
of hacker attacks, the Mozilla Foundation is warning.
> 
> The organization released Firefox 1.0.1, which fixes 17 security 
flaws in the popular Web browser. The most serious flaws could allow 
an attacker to gain full control over a victim's PC, the Mozilla 
Foundation says in a statement. Firefox 1.0 was released in November 
and has since been downloaded more than 27 million times.
> 
> Firefox 1.0.1 also includes several fixes to guard against 
spoofing of Web addresses and the security indicator on Web sites. 
These vulnerabilities could be exploited for phishing scams, which 
typically use spam e-mail messages to drive people towards 
fraudulent Web pages that look like legitimate e-commerce sites.
> 
> One of the changes made in Firefox 1.0.1 is in the way the browser 
handles international domain names (IDNs). These names are now 
displayed differently to make it easier to spot spoofed Web sites. 
Because of the way Firefox displayed IDNs, it was possible to 
register domain names with international characters that resembled 
other common characters, thus tricking users into believing they 
were on a trusted Web site.
> 
> For protection against possible exploitation of the security 
flaws, users should download and install the latest version of 
Firefox, the Mozilla Foundation says. The organization does not 
offer patches to fix the problems without having to install a new 
browser.
> 
> Most of these flaws also affect the Mozilla Suite, which includes 
a Web browser, an e-mail client, Internet Relay Chat client, and Web 
page editor. However users of the suite are left vulnerable because 
no fixes are yet available. Mozilla 1.7.6, the update that fixes the 
issues, is due out in "a couple of weeks," according to a Mozilla 
Foundation spokesperson.
> 
> 
> False Sense of Security?
> 
> The public warning of the security vulnerabilities is evidence 
that the Mozilla Foundation's products give a false sense of 
security, says Thor Larholm, a senior security researcher with PivX 
Solutions in Newport Beach, California.
> 
> "The only reason Mozilla and Firefox have a good track record in 
security with a low number of security vulnerabilities is simply 
because they don't tell anyone about them," Larholm says via e-mail.
> 
> "The Mozilla Foundation has fixed hundreds if not thousands of 
security vulnerabilities over the last few years without notifying 
the world and without providing security patches, instead they have 
simply just told their users to upgrade," he says. "We have to 
remember that all software has security vulnerabilities, the only 
difference is in how we anticipate them and inform the world about 
their existence."
> 
> -----------END---------
> 
> Need I say anything more ??!!!
> 
> Now if this was a case with Microsoft I am so sure it would have 
hit Star News by now. Well at least Microsoft does not hide its 
faults ( honesty is the best policy after all )
> 
> Well, i know you people are crazy for firefox ... i have only 1 
thing to say ... Better Upgrade Soon !!! 
> 
> Cheers
> Varun
> 
> PS : Waiting for comments, at least from vivek!
> 
> 
> Yahoo! India Matrimony: Find your life partneronline.