Update: Firefox Password Manager Vulnerability

With Firefox 2.0.0.1 being released yesterday, many folks have been asking has this fixed the the Firefox Password Manager Vulnerability. The short answer is NO. However, there is a simple fix via an about:config tweak that will protect you until this is fixed in the 2.0.0.2 release next month. In order to get 2.0.0.1 with all its fixes out in a timely manner this fix was pushed back to the next release. Before you do this tweak take a look at this demonstration site, it will show you exactly how the vulnerability works. Be sure to visit the site again to test your browser after you have completed the tweak below:

  1. In a new tab type about:config in the address bar and press enter (or click go)
  2. In the filter filed copy and paste signon.prefillForms
  3. Double click the entry to change the value to false
  4. Close the tab

What this tweak does is when you come to a login page, Firefox will not automatically pre-fill with your saved user name and password. Instead as you start to type in your user name, a drop down will appear. Select the correct user name and the password will pre-fill from there.

Also see: Update: Firefox Password Manager Vulnerability Part 2

Source: mozillaZine Firefox Builds

Leave a Reply




 

December 2006
S M T W T F S
« Nov   Jan »
 12
3456789
10111213141516
17181920212223
24252627282930
31  

Upcoming Releases

Fx 3.0.12 -- July 21st
Fx 3.0.13 -- September 1st
Fx 3.5.2 -- End July/Early August

Chandler, AZ Weather

Categories

Archives

Blog Stats

  • 771,655 views
Upcoming Releases
- Fx 1.5.0.10/2.0.0.2
RELEASED February 23rd - Major Update (Fx 1.5.0.X to 2.0.0.X)
Mid/Late March - Fx 1.5.0.11/2.0.0.3
March 13 Tentative - Fx 1.5.0.12/2.0.0.4
April 2007 Tentative - Fx 3.0a2/Gecko 1.9a2
RELEASED February 7th - Fx 3.0a3/Gecko 1.9a3
March 19th Tentative - TB 1.5.0.10
RELEASED March 1st - TB 2.0b2
RELEASED January 24th - TB 2.0 (Final)
Late March 2007