-

 -

 - e-mail

 

 -

   Mozilla_FireFox

 -

 LiveInternet.ru:
: 07.06.2005
:
:
: 1705

:

security.


: release(311), media(193), hints(68), community(165), browser wars(86), addons(250)
(3)

Firefox 3.5.1 Unicode Data Remote Stack Buffer Overflow

, 20 2009 . 14:29 +
security

(0)

Firefox 3.5 unicode stack overflow

, 16 2009 . 07:09 +
security

(0)

Firefox 3.5 Heap Spray Vulnerabilty

, 14 2009 . 01:39 +
cyber_alien (Mozilla_FireFox) Firefox 3.5 , .

: Mozilla Firefox Elements Handling Memory Corruption Vulnerability
: Firefox 3.5 Heap Spray Vulnerabilty

Javascript .
UPD: about:config javascript.options.jit.content false. Firefox .
security

(0)

Firefox 3.0.8

, 28 2009 . 04:03 +
release
security

(0)

, 16 2009 . 10:45 +
addons
security

(0)

Firefox

, 24 2009 . 10:23 +
security

(1)

, 06 2009 . 22:15 +
addons
security
media
browser wars

:  
(0)

Browser Security Handbook

, 27 2009 . 02:50 +
security

:  
(0)

, 12 2008 . 20:09 +
security
community

:  
(1)

,

, 08 2008 . 08:25 +
cyber_alien (Mozilla_FireFox) BitDefender . , Trojan.PWS.ChromeInject, .

. PayPal, online . , .

. .

UPD: Gartner
addons
security

(0)

Pen Testing the Web with Firefox

, 13 2008 . 13:28 +
security
media

(4)

Firefox

, 09 2008 . 14:28 +
cyber_alien (Mozilla_FireFox) - d'n'b unreleased :X
Black Hat, 2 7 . (Itzik Kotler) Radware Black Hat Jinx, - Firefox.

Firefox 3 3.0.1. Jinx . JavaScript , , .. , Windows, Linux Macintosh . .

, " - , - , ". Jinx (., ). , , Radware Jinx- , Microsoft Internet Explorer.
security

(0)

Site Security Policy

, 09 2008 . 20:30 +
cyber_alien (Mozilla_FireFox) Mozilla Site Security Policy (SSP), (XSS), CSRF (Cross Site Request Forgery, , img src , . XSS - , , CSRF , , ). , IFRAME JavaScript, , , web-, web-, .

HTML/JavaScript , iGoogle, eBay, Roxer, Windows Live, MySpace / Facebook Widgets .. SSP Firefox, Web , . SSP , . , ( , ), iframe, javascript src img src.

SSP ( HTTP ):

// script src
X-SSP-Script-Source: allow *.example.com; deny public.example.com

// .
// HEAD HTTP "Policy-Query".
X-SSP-Request-Source: deny * post; allow * get; expires 60
X-SSP-Request-Source: allow *.example.com post,get; deny public.example.com *; expires 3600
X-SSP-Request-Target: allow *.example.com *, deny public.example.com post

// URI POST
X-SSP-Report-URI: http://www.example.com/policy.cgi

:
OpenNet.ru
SlashDot
Site Security Policy
addons
security

(2)

, 08 2008 . 09:46 +
security

:  
(1)

Flash update

, 10 2008 . 10:39 +
cyber_alien (Mozilla_FireFox)

Flash 9.0.124, 7 .
addons
security

:  
(0)

, 26 2008 . 12:19 +
security
hints

(0)

Thunderbird

, 28 2008 . 17:12 +
security

:  
(0)

SeaMonkey

, 11 2008 . 13:59 +
security

(7)

, 09 2008 . 01:12 +
security

(0)

Mozilla Firefox

, 08 2008 . 20:06 +
 (Mozilla_FireFox) : Mozilla Firefox 2.0.x

, XSS , DoS , .

1) - . .

2) - Javascript. .

.

3) - , . .

4) - Javascript. Javascript "chrome".

5) - Javascript. "XMLDocument.load()", .

6) - , , "designMode". , .

.

7) - , . , .

8) - , Firefox "302" URL "element.sheet.href". URL.
security


 : 9 8 7 [6] 5 4 ..
.. 1