R E L A T E D   C O N T E N T
ADVERTISEMENT

Security hole hits Internet Explorer and Firefox

JavaScript flaw opens door to credit card thieves

Tom Sanders in California, vnunet.com 07 Jun 2006
ADVERTISEMENT

Microsoft's Internet Explorer and Mozilla's Firefox are both vulnerable to a new JavaScript flaw that could allow attackers to steal confidential information.

The flaw affects fully patched browsers on Windows, Linux and Mac systems, according to a posting on the Full Disclosure security mailing list.

The issue is caused by the 'OnKeyDown' JavaScript feature that allows websites to capture and duplicate keystrokes entered into data fields, including fields where users enter credit card information.

Security experts noted that exploiting the flaw would require the user to type a fair amount of text. Attackers would therefore most likely target online games or blogs.

Security website Secunia rated the flaw 'less critical' for Internet Explorer and Firefox.

Although the flaw requires a sophisticated attacker to effectively exploit it, it is noteworthy because it spans multiple operating systems and browser vendors.

The SANS Internet Storm Centre warned users to be cautious in allowing JavaScript to run.


All Bugs & Fixes

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Exeter, United Kingdom | Met Office
SOFTWARE ENGINEERS: ANALYSIS, VISUALISATION & DATA TEAM, £25,500+, Exeter Make a difference by visualising world-class research How many programming jobs put you in a position to make a real difference to your own future and ... more >
Warrington, United Kingdom | Environment Agency
Technical Architect, Warrington, Salary and package to attract the best These positions require highly skilled Technical Architects with demonstrable experience of working within a complex and distributed infrastructure environment. Working within the Service Assurance team ... more >
United Kingdom | Bloomberg LP
Client Development Support Specialist - 21350 The Company Bloomberg is the leading global provider of financial data, news and analytics. The BLOOMBERG TERMINAL and Bloomberg's media services provide real-time and archived financial and market data, ... more >
United Kingdom | Bloomberg LP
Financial Software Development Intern - Summer 2008 - 20735 The Company Bloomberg is the leading global provider of financial data, news and analytics. The BLOOMBERG PROFESSIONAL service and Bloomberg's media services provide real-time and archived ... more >
More job opportunities