R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Security hole hits Internet Explorer and Firefox

JavaScript flaw opens door to credit card thieves

Tom Sanders in California, vnunet.com 07 Jun 2006
ADVERTISEMENT

Microsoft's Internet Explorer and Mozilla's Firefox are both vulnerable to a new JavaScript flaw that could allow attackers to steal confidential information.

The flaw affects fully patched browsers on Windows, Linux and Mac systems, according to a posting on the Full Disclosure security mailing list.

The issue is caused by the 'OnKeyDown' JavaScript feature that allows websites to capture and duplicate keystrokes entered into data fields, including fields where users enter credit card information.

Security experts noted that exploiting the flaw would require the user to type a fair amount of text. Attackers would therefore most likely target online games or blogs.

Security website Secunia rated the flaw 'less critical' for Internet Explorer and Firefox.

Although the flaw requires a sophisticated attacker to effectively exploit it, it is noteworthy because it spans multiple operating systems and browser vendors.

The SANS Internet Storm Centre warned users to be cautious in allowing JavaScript to run.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Leeds, United Kingdom | UKCRN
Head of Service Management, Leeds You will lead the teams who manage all our systems hardware and infrastructure and provide helpdesk support to all users.  We'll look to you to develop and deliver network services ... more >
United Kingdom | London School of Economics and Political Science
  London School of Economics and Political Science The Library Analyst Programmer (fixed term 24 months) Salary: £30,201 - £36,563 pa incl The Library is at the heart of LSE, one of the world's greatest ... more >
Leeds, United Kingdom | UKCRN
Helpdesk Manager, Leeds You'll have the opportunity to develop a dedicated Help Desk Service so that services are clear, accountable and responsive to customer needs.  Planning, monitoring and controlling the use of helpdesk resources, you'll ... more >
United Kingdom | UKCRN
Technical Author, Leeds You'll be part of a team within our UKCRN Coordinating Centre, working closely with different members of staff on specific initiatives and also with core clinical and management staff. You will liaise ... more >
More job opportunities