Does this spoof effect you with Mozilla Firefox 0.9.3???  

28 members have voted

  1. 1. Does this spoof effect you with Mozilla Firefox 0.9.3???

    • yes
      16
    • no
      12


Recommended Posts

I installed Mozilla Firefox 0.9.3 earlier today and then later on just for the fun of it I decided to check to see if the vulnerability still effected me... strangly it does...

I was wondering if anyone else with Mozilla Firefox 0.9.3 is still being effected. link is below.

http://www.nd.edu/~jsmith30/xul/test/spoof.html

I think Firefox should have followed IE's lead in making the content area sunken into the browser window. It allows you to tell whether something is part of the browser window or not regardless of whether anything is spoofed.

https://www.neowin.net/forum/index.php?showtopic=192796

but it has been fixed in the nightly branch build I'm using since August 03.

Yup, it throws up

XML Parsing Error: undefined entity

Location: http://www.nd.edu/~jsmith30/xul/test/browser2.xul

Line Number 856, Column 36:              <menuitem accesskey="&releaseCmd.accesskey;"

-----------------------------------^

As far as I'm concerned, I can find no evidence to say that this was supposed to be in 0.9.3 at all... unless you can give a source which directly quotes a developer stating that, please stop spreading rubbish about a "messed up" release. Four security bugs were fixed with 0.9.3, and if you check the thread already linked, you'll see why I don't even consider this an exploit.

Kasteo, I'd be interested to know what build you're using, since I can't think of a fix for this at all, short of forcing the legitimate statusbar to display for XUL content (i.e. prevent popups disabling it), nor can I find any checkins or bugfixes to indicate that any change has been made in relation to this "bug" at all.

...

Kasteo, I'd be interested to know what build you're using, since I can't think of a fix for this at all, short of forcing the legitimate statusbar to display for XUL content (i.e. prevent popups disabling it), nor can I find any checkins or bugfixes to indicate that any change has been made in relation to this "bug" at all.

Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US; rv:1.7) Gecko/20040804 Firefox/0.9.1+

When you click on the example of an exploit XUL content link it will show....

XML Parsing Error: undefined entity
Location: http://www.nd.edu/~jsmith30/xul/test/browser2.xul
Line Number 856, Column 36:              &lt;menuitem accesskey="&amp;releaseCmd.accesskey;"
-----------------------------------^

I still see the spoof, but because of the way I have the browser configured, I'd never be fooled by it.. it's so vastly different looking from the way I have mine configured not to mention I have disabled the ability for javascript to hide things.

Still, it should be addressed. It's still in beta and in a constant state of change as bugs get fixed, so I'll give them a bit of time yet.. I just wish the gecko engine loaded images faster.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • With the current hardware prices Microsoft should lift the restriction. Then if you have the correct TPM then allow you to use X feature, if you don't have the correct TPM then don't but still actually let you run windows. 11. With a disclaimer during install that X features would be unavailable.
    • It's good for recycling of course. But commence inflation of a second hand RAM bubble and price gouging on DDR 4 inventory in 3... 2... 1...
    • Bypassed Windows 11 shows surprising stability on ancient, completely unsupported hardware by Sayan Sen When Windows 11 was first released, one of the most complained-about issues with the new desktop Microsoft OS was its higher system requirements, which pushed many relatively modern and powerful processors and devices onto the officially unsupported list. Thankfully, they have not been updated again for the base OS, though systems require four times the memory and storage if they want to run AI-powered apps and features. As such, Windows 11 technically runs on 4GB of memory, and there is no imposed restriction on the generation of memory it supports. Speaking of memory, prices are extremely high nowadays for hardware, especially DDR5 and DDR4 kits due to the current silicon shortage, and there are also reports of it affecting DDR2 as well, and it might only be a matter of time before even DDR1 gets affected. Before that could happen, an enthusiast took an ancient DDR1-based system and decided to try out Windows 11 on it to see how well the modern OS would fare on such hardware. The system runs an outdated graphics card interface standard based on AGP, or Advanced Graphics Port, called AGP 3.0 or AGP8x. AGP was essentially succeeded by the modern PCI Express (PCIe) bus standard. The user behind the experiment is retro hardware enthusiast Omores, who built the system around an ASRock ConRoe865PE motherboard based on Intel's i865PE chipset from way back in 2003, around the time when AGP was still in fashion. What made this board special back in the day was its unusual support for newer Core 2 Duo and even Core 2 Quad processors while still retaining older DDR1 memory support and an AGP8X graphics slot, making it an ideal bridge or link between two vastly different generations. Powering the machine was Intel's Core 2 Quad Q6600 alongside 3GB of DDR1 RAM and an ATI Radeon HD 4650 AGP graphics card, one of the final and most capable GPUs released for the aging AGP interface. While installing Windows 11 itself was relatively easy by bypassing Microsoft's hardware checks, getting the graphics card fully functional proved to be some challenge. Microsoft had quietly dropped native AGP support after the earliest releases of Windows 10, meaning newer versions of Windows no longer include the necessary Graphics Address Remapping Table (GART) drivers required for proper AGP acceleration. Without them, AGP graphics cards typically boot up, though with limited functionality, and can often throw a Code 43 error in Device Manager. To work around the limitation, Omores extracted Intel's legacy AGP440 SYS driver from an early Windows 10 release and paired it with a modified INF file so Windows 11 would correctly recognize the chipset. Following this and combined with AMD's final 64-bit Catalyst AGP drivers from 2012, the Radeon HD 4650 was able to operate with full AGP 8X acceleration intact. The result was said to be surprisingly usable for hardware that is over two decades old. Hardware-accelerated H.264 video playback worked correctly and benefited apps like Firefox, while legacy applications and games ran without major graphical issues. The system also successfully completed the 3DMark 2001 benchmark, although performance naturally lagged behind what the same hardware achieves under Windows 7, which is significantly lighter than Windows 11. There was, however, one unavoidable limitation as Microsoft's Windows 11 version 24H2 introduces a mandatory SSE4.2 CPU instruction requirement that cannot be bypassed through installer modifications or registry tweaks. Since no AGP-era processor supports SSE4.2, Windows 11 version 23H2 effectively becomes the final release capable of running on such systems. Regardless, it is still a very cool feat and quite fascinating to see just how stable Windows 11 turned out to be on such unfamiliar hardware. Source: Omores (Patreon) via O_MORES (Reddit)
    • That will only really help other players that are also responsible for creating the problem.
    • Well, it's good to know that they have found a workaround to a problem that they helped create, I guess...
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      538
    2. 2
      +Edouard
      266
    3. 3
      PsYcHoKiLLa
      151
    4. 4
      Steven P.
      98
    5. 5
      macoman
      66
  • Tell a friend

    Love Neowin? Tell a friend!