2006.11.24 Daily Security Reading
by Rodney Campbell on Nov.24, 2006, under Security
FireFox Password Manager Flaw w/ POC
The flaw derives from Firefox’s willingness to supply the username and password stored on one page on a domain to another page on a domain. For example, username/password input tags on a Myspace user’s site will be unhelpfully propagated with the visitor’s Myspace.com credentials. Because the username/password fields need not be visible on the page, your password can be stolen in an almost completely transparent fashion.
Remotely activate the ‘hands free’ function on an IP telephone (using software) to allow listening in to room conversations.