Dubbed the "Reverse Cross-Site Request" vulnerability by its discoverer, the vulnerability is in Firefox's password-saving feature. Attackers can exploit the flaw by crafting malicious HTML code that hijacks a username and password from a legitimate site, such as a blog or message forum, then transports the log-in to another site. Users would not notice that the theft had even taken place, said Robert Chapin, who reported the bug to Mozilla earlier this month.
Danish vulnerability tracker Secunia rated the threat as "Less critical," the second out of five possible rankings.
Chapin cited an October fraud on MySpace as the first evidence of an RCSR-based attack. "A recent large-scale attack using RCSR targeted MySpace.com users involved fake log-in forms on the MySpace site inviting users to type in their username and password," he wrote in a warning.
Current versions of Firefox, including 1.5.0.8 and 2.0, are vulnerable to RCSR attack; until a patch is available, users can deflect such attacks by disabling the automated password saving feature. In Firefox, users should select Tools|Options|Security, then clear the box marked "Remember passwords for sites."
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.