• 01 December 2016

    Firefox Patches Zero-Day Flaw being used to target Tor Users — Updates Now! The critical Firefox vulnerability being actively exploited in the wild to unmask Tor users has been patched with the release of new browser updates.
     Both Mozilla and Tor Project has patched the vulnerability that allows attackers to remotely execute malicious code on Windows operating system via memory corruption vulnerability in Firefox web browser.

    Tor Browser Bundle is a repackaged version of the open-source Mozilla Firefox browser that runs connections through the Tor anonymizing network configured to hide its user's public IP address.

    However, the exploit code released by an unnamed online user was currently being exploited against Tor Browser users to leak the potentially identifying information of Tor users.
    "The security flaw responsible for this urgent release is already actively exploited on Windows systems," an official of the anonymity network wrote in an advisory published on Wednesday. 
    "Even though there is currently...no similar exploit for OS X or Linux users available, the underlying [Firefox] bug affects those platforms as well. Thus we strongly recommend that all users apply the update to their Tor Browser immediately."
    Soon after the Tor Project released the updated version of its browser, Mozilla also posted a blog post that said the company has also released an updated version of Firefox that patched the underlying vulnerability.

    The vulnerability, assigned CVE-2016-9079 and rated critical, also affects Mozilla's Thunderbird e-mail application and the Firefox Extended Support Release (ESR) version used by the Tor Browser.

    The attack code exploiting the underlying vulnerability initially circulated Tuesday on a Tor discussion list by an admin of the SIGAINT privacy-oriented public email service.
    "The exploit took advantage of a bug in Firefox to allow the attacker to execute arbitrary code on the targeted system by having the victim load a web page containing malicious JavaScript and SVG code," said Mozilla security official Daniel Veditz. 
    "It used this capability to collect the IP and MAC address of the targeted system and report them back to a central server. While the payload of the exploit would only work on Windows, the vulnerability exists on Mac OS and Linux as well."
    Firefox and Tor users are strongly recommended to update their web browsers to the latest Firefox version 50.0.2 and Tor Browser 6.0.7, respectively, as soon as possible.

    Meanwhile, people using both Tor and mainstream versions of Firefox can set the Firefox security slider to "High" in order to protect themselves from the attack.

    Doing so would render the exploit moot, Georg Koppen, Tor Browser Team Lead, told The Hacker News in an email, although the setting will prevent many websites from working as expected.
    "Apart from that we are currently working on sandboxing techniques that have [the] potential to mitigate this kind of attack," Koppen added. "They are, alas, not ready for the stable series yet. We plan to ship prototypes with the next planned alpha releases."
    For more details about the critical Firefox vulnerability, you can head on to our previous article, Firefox Zero-Day Exploit to Unmask Tor Users Released Online.


    Source of : http://thehackernews.com/



    Increase Website Traffic

    { 14 comments... read them below or Comment }

    1. Công ty Thu Mua Phe Lieu Phú Quý - Chuyên thu mua phế liệu giá cao, phế liệu đồng, phế liệu sắt, phế liệu inox, phế liệu công trình, LH: 0946396616
      Tổng hợp các tin tức về SEO - Dich Vu SEO | Khuong Bui SEO, Google luôn nhìn thấy bạn đang làm gì , đừng bao giờ tự tin rằng dùng các kỹ thuật để qua mặt Google
      Công Ty CP DV Đồ Cúng Tâm Linh, Chuyên cung cấp Do Cung Tron Goi cúng đầy tháng, cúng thôi nôi, Cung Dong Tho, cúng khai trương, cúng thần tài trọn gói | ĐT: 0914 69 59 19

      ReplyDelete
    2. mainkan poker online terbaik hanya di 988poker
      agen idn poker online terpercaya https://covidinfos.net/community/profile/situs988poker/

      ReplyDelete
    3. Heya i am for the first time here. I found this board
      and I find It really useful & it helped me out much. I hope to give
      something back and aid others like you aided me.
      https://chuyennhuong.co/cn/profile.php?id=195106

      ReplyDelete
    4. The most complete IDN Play server aka IDN Poker is one of the best servers in Asia as a trusted card gambling game service provider. Because therefore in IDN play poker has 9 favorite IDN poker card gambling games today. For card game lovers, it is very suitable for you to visit the IDN Poker site which provides the most complete 9 online IDN poker card gambling games.

      http://www.counterstrikesource.com/forums/profile.php?mode=viewprofile&u=34654

      ReplyDelete
    5. terima kasih situs ini sudah memberikan pengetahuan yang bagus dan apabila ada yang ingin bermain game BOLA bisa mengunjungi BOLA88 karena berapapun kemenangan anda pasti akan dibayar

      ReplyDelete
    6. Sbobet Buat android masih memakai instalasi manual sebab aplikasi dari sumber yang tidak diketahui masih memakai sistem biasa. Jadi belum terdapat sistem tab and play semacam sistem yang digunakan pada playstore.

      ReplyDelete
    7. This comment has been removed by the author.

      ReplyDelete
    8. Indokasino ialah web judi online yang sangat diminati oleh para penggemar game kasino sebab sediakan bermacam berbagai game kasino online yang lebih gampang dimainkan serta diakses, dengan bermacam berbagai tipe game yang sudah di sajikan, hingga para pemain lebih bebas dalam mennentukan game yang di ignginkan. Link alternatif unutk Indokasino

      ReplyDelete
    9. Lihat buku mimpi dan main di situs togel hongkong Togelfortuna. jp pasti dibayar

      ReplyDelete

  • Nisekoi Template Designed by Johanes Djogan

    ©2016 - ReDesigned By Ani-Sudo