em_te Posted October 3, 2006 Share Posted October 3, 2006 http://developer.mozilla.org/devnews/index...ted-at-toorcon/ We got a chance to talk to Mischa Spiegelmock, the Toorcon speaker that reported the potential javascript security issue referenced earlier. He gave us more code to work with and also made this statement and agreed to let me post it here:The main purpose of our talk was to be humorous.As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has. I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven?t used it to take over anyone else?s computer and execute arbitrary code. I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not. I apologize to everyone involved, and I hope I have made everything as clear as possible. Sincerely, Mischa Spiegelmock Even though Mischa hasn?t been able to achieve code execution, we still take this issue seriously. We will continue to investigate. -Window Snyder Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/ Share on other sites More sharing options...
xpgeek Posted October 3, 2006 Share Posted October 3, 2006 What a (nasty name to call a person) this guy is. Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587925055 Share on other sites More sharing options...
zeroday Posted October 3, 2006 Share Posted October 3, 2006 The allegedly critical hole reported yesterday in Firefox's JavaScript implementation has turned out, not surprisingly, to be a hoax. Mischa Spiegelmock, who made the claim at the Toorcon hacker conference, told Mozilla's security chief Window Snyder, "The main purpose of our talk was to be humorous." While it is possible to create a stack overflow, the only result he has been able to produce is a browser crash. Neither he, nor anyone else, has managed to execute code via this hole. Spiegelmock claims to know nothing about the other 30 holes reported in the media. The Mozilla team nevertheless plans to look into the matter in order to detect and remedy any flaws. Source Moz Dev Centre Entry: We got a chance to talk to Mischa Spiegelmock, the Toorcon speaker that reported the potential javascript security issue referenced earlier. He gave us more code to work with and also made this statement and agreed to let me post it here: The main purpose of our talk was to be humorous. As part of our talk we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this, and I personally have not gotten it to result in code execution, nor do I know of anyone who has. I have not succeeded in making this code do anything more than cause a crash and eat up system resources, and I certainly haven’t used it to take over anyone else’s computer and execute arbitrary code. I do not have 30 undisclosed Firefox vulnerabilities, nor did I ever make this claim. I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not. I apologize to everyone involved, and I hope I have made everything as clear as possible. Sincerely, Mischa Spiegelmock Even though Mischa hasn’t been able to achieve code execution, we still take this issue seriously. We will continue to investigate. -Window Snyder Moz Dev Entry Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926500 Share on other sites More sharing options...
hagjohn Posted October 3, 2006 Share Posted October 3, 2006 Funny... ha ha!!!! I hope they do not invite him back to ever speak again. Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926552 Share on other sites More sharing options...
Randolph Posted October 3, 2006 Share Posted October 3, 2006 Funny... ha ha!!!! I hope they do not invite him back to ever speak again. LOL now that is funny. :rofl: Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926563 Share on other sites More sharing options...
Meraklis56 Posted October 3, 2006 Share Posted October 3, 2006 lol...let me ask.Did they pay him to say that he was laying? Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926604 Share on other sites More sharing options...
zeroday Posted October 3, 2006 Share Posted October 3, 2006 heh..so thats what happened to my thread lol. Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926891 Share on other sites More sharing options...
Fred Derf Veteran Posted October 3, 2006 Veteran Share Posted October 3, 2006 heh..so thats what happened to my thread lol. Oops. Sorry. [Threads Merged] Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926975 Share on other sites More sharing options...
Master Shake Posted October 3, 2006 Share Posted October 3, 2006 I love Firefox. Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587926998 Share on other sites More sharing options...
Badtz-Maru Posted October 3, 2006 Share Posted October 3, 2006 Three of my major news sources, Slashdot, Ars, and bit-tech had reported this flaw, and now its fake? lol Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927022 Share on other sites More sharing options...
Pink Floyd Veteran Posted October 3, 2006 Veteran Share Posted October 3, 2006 ppl have too much time to waste :no: Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927043 Share on other sites More sharing options...
Futurix Posted October 3, 2006 Share Posted October 3, 2006 Funny that people from Mozilla.org managed to reproduce crash :whistle: Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927155 Share on other sites More sharing options...
halcyoncmdr Posted October 3, 2006 Share Posted October 3, 2006 As it said: While it is possible to create a stack overflow, the only result he has been able to produce is a browser crash. Neither he, nor anyone else, has managed to execute code via this hole. So while they can reproduce the crash is beside the point, no code is able to be executed through this hole, yet :shiftyninja: Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927170 Share on other sites More sharing options...
someware Posted October 3, 2006 Share Posted October 3, 2006 hmmm, whether or not there was a hole I don't think it really matters It's just quite funny the effect the media has, not even the media, the internet!, the spread of word by individuals posting the same content from one forum to another. The untruthful content ends up on hundreds of sites... millions of people read it and believe it to be gospel. There are probably thousands of people walking around today thinking their Firefox is insecure lol! :) Then again only geeks use firefox and tbh the sensible people out there will be running virus scanners and firewalls. When I saw the announcement of the '30 exploits' I thought ah well, they'll prolly fix it soon enough who cares :) Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927222 Share on other sites More sharing options...
burnsflipper Posted October 3, 2006 Share Posted October 3, 2006 Then again only geeks use firefox and tbh the sensible people out there will be running virus scanners and firewalls. I use Firefox, and I'm a designer, not a geek :whistle: Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927237 Share on other sites More sharing options...
Favorable7404 Posted October 4, 2006 Share Posted October 4, 2006 Demote them to script kiddie, like we did to Pluto! Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927559 Share on other sites More sharing options...
crimsonhead Posted October 4, 2006 Share Posted October 4, 2006 I have a bomb attached to my chest! And there's more where that came from! Note: I do not have a bomb, it was a joke (funny right). I only have a few sparklers which I have never managed to burn anybody with. (but they sure are pretty). Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587927567 Share on other sites More sharing options...
Malisk Posted October 4, 2006 Share Posted October 4, 2006 Three of my major news sources, Slashdot, Ars, and bit-tech had reported this flaw, and now its fake? lol Yes. I've seen it before, and I think this is a kind of new problem with the fast travelling unverified news getting mirrored on news sites, major or not. Don't go believe e.g Slashdot has much of a quality control in place. Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587928055 Share on other sites More sharing options...
someware Posted October 4, 2006 Share Posted October 4, 2006 I use Firefox, and I'm a designer, not a geek :whistle: hehe, i'm a geek :) Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587928182 Share on other sites More sharing options...
The_Decryptor Veteran Posted October 4, 2006 Veteran Share Posted October 4, 2006 Yes. I've seen it before, and I think this is a kind of new problem with the fast travelling unverified news getting mirrored on news sites, major or not. Don't go believe e.g Slashdot has much of a quality control in place. They reported the combined statement by Mozilla and these guys, Mozilla said it knew of the flaw they were talking about (the DoS one), and the "report" included what the guys said. I would rather them report on it, than just ignore it (even if it turns out to be a non-issue) Link to comment https://www.neowin.net/forum/topic/500453-firefox-security-hole-was-just-a-joke/#findComment-587928197 Share on other sites More sharing options...
Recommended Posts