Posts Tagged ‘Firefox’

After day 1 of Pwn2Own, web browsers appear to have taken a big hit, but Google’s Chrome appears to have come out unscathed.

It didn’t take long, with Safari 4 on Mac OS X Snow Leopard the first victim thanks to the work of Charlie Miller. Millers set up a remote exploit at a web site through which a conference organisers MacBook was taken control after surfing to it.

Internet Explorer 8 on Windows 7 was next, with a similar exploit allowing Peter Vreugdenhil to take control of an organisers laptop once they browsed to a website with the infected code.

Firefox 3 was also exploited on Windows 7 using a memory corruption vulnerability, with another exploit that allows a remote attacker access to a users PC.

Both Opera and Google Chrome were not hacked, with Charlie Miller stating “there are bugs in Chrome but they’re very hard to exploit. I have a Chrome vulnerability right now but I don’t know how to exploit it. It’s really hard. They’ve got that sandbox model that’s hard to get out of. With Chrome, it’s a combination of things — you can’t execute on the heap, the OS protections in Windows and the Sandbox.”

All systems were patched and updated to their latest versions, with the exploits used to remain a secret until browser makers can update their browsers.

Tags: , , , , , Categories: Chrome, Firefox, Internet Explorer, Safari Comments Off on Safari, Firefox, and IE hacked at Pwn2Own

Mozilla has announced that they are stopping development for Firefox on Windows Mobile devices.

The announcement is no surprise, with the announcement of Windows Phone 7 series expected to limit the device to just Internet Explorer on it’s mobile devices, much like Apple has done with it’s iPhone.

“We have been building a version of Firefox for Windows Mobile for quite a while, with the expectation that Microsoft would be doubling down in the mobile market and hoping that they would put out a great new mobile operating system” wrote Mozilla Mobile Team Technical Lead, Stuart Parmenter.

“While we think Windows Phone 7 looks interesting and has the potential to do well in the market, Microsoft has unfortunately decided to close off development to native applications.  Because of this, we won’t be able to provide Firefox for Windows Phone 7 at this time” continued Parmenter.

All hope isn’t totally lost, with Parmeter adding “while I hope that we do see Microsoft provide us with a way to build Firefox for Windows Phone 7, we will continue to focus on the things that we can control: building a great consumer product on both Android and Maemo.”

Mozilla have released an update for Firefox 3.6 users, taking the browser to version 3.6.2.

The latest update fixes several security issues, one of which is rated as critical, the highest on the Firefox security severity scale.

A full list of changes can be read in the release notes.

Existing users are strongly urged to accept the update when their browser prompts them in the next 2-3 days, or alternatively, Firefox 3.6.2 can be downloaded from the Firefox website.

Tags: , , , , , Categories: Firefox Comments Off on Firefox 3.6.2 released

Mozilla is hard at work on the next version of Firefox, and the latest alpha builds include out-of-process support for plugins.

“Plugins such as Flash and Silverlight run in a separate process from the browser. If a plugin crashes it will not crash the browser, and unresponsive plugins are automatically restarted” said an announcement from Mozilla.

Currently, out-of-process support is only available on Windows and Linux versions, with Mac support still under development. This is only the first step, with each tab also expected to be moved to it’s own process in time, much like rivals Internet Explorer and Chrome have already done.

You can download the new test version of Firefox from the Mozilla Developer News Blog.

Private browsing will now extend to the Flash plug-in with Flash Player 10.1 Adobe have announced.

“Integrating with your web browser, Flash Player 10.1 will automatically clear stored data in accordance with your browser’s private browsing settings” said Adobe Engineer Jimson Xu.

Flash Player 10.1 supports private browsing with Internet Explorer 8+, Mozilla Firefox 3.5+, and Google Chrome 1.0+, with Apple’s Safari 2.0+support coming soon.

Missing from this list is Opera, which has only recently included private browsing in the latest 10.50 alpha release.

Adobe Flash Player 10.1 is currently in Beta and is expected in the first half of this year. Beta 2 can be downloaded from Adobe Labs.

Tags: , , , , , Categories: Chrome, Firefox, Internet Explorer, Opera, Safari Comments Off on Flash Player 10.1 supports private browsing

Mozilla appears to have let it’s guard down, with a Firefox add-on that included a Trojan that could allow remote access to a users PC.

Two add-ons were affected; Master Filer which was infected with a password-stealing Trojan called Win32.LdPinch.gen, and Sothink Web Video Downloader which was infected with a backdoor Trojan called Win32.Bifrose.32.Bifrose.

Mozilla has issued a statement:

“If a user installs one of these infected add-ons, the trojan would be executed when Firefox starts and the host computer would be infected by the trojan. Uninstalling these add-ons does not remove the trojan from a user’s system. Users with either of these add-ons should uninstall them immediately. Since uninstalling these extensions does not remove the trojan from a user’s system, an antivirus program should be used to scan and remove any infections.”

Mozilla believe only 4,600 people are infected after downloading these add-ons.

How these add-ons made it online is unknown, as Mozilla scans all add-ons for viruses before they are approved. Mozilla now plans on using two different malware detection tools to try and stop this issue from reoccurring in the future.

Tags: , , , , Categories: Firefox Comments Off on Firefox add-on included Trojan virus

Mozilla’s Stephen Horlander has been hard at work, working on tab animations for the next version of Firefox, Firefox 4.0. The aim is to improve the user experience.

“One area that animation would be very beneficial is with tab interactions. Specifically moving/arranging tabs on the tab strip, closing/opening tabs and tearing off tabs into new windows. Presently the feedback here isn’t as good or as elegant as it could be” said Horlander.

“Some of the goals for animation are to make browsing feel faster, adding visual affordances that makes tasks more understandable and to make the browser more visually appealing. There is much more detail on the Wiki articles linked above. My goal was to quickly demo how this would actually look and feel because still images and wireframes can only convey so much.”

Below is am image preview of what it might look like when opening a new tab.

Video’s of the preview tab animations can be found in Horlander’s blog post.

After an almost month long release candidate, Mozilla has released the final version of Firefox Mobile for Maemo devices.

Firefox Mobile is almost a direct port of it’s big brother Firefox, with a completely redesigned user interface for touch screens.

The browser includes the awesome bar, a download manager, early HTML5 support, tabbed browsing, add on support, safe browsing, and is currently available in over 30 languages.

Firefox Mobile can be downloaded and installed on the Nokia N900, with more Maemo devices expected on the market soon.

Tags: , , , , , Categories: Fennec, Firefox Comments Off on Firefox Mobile released

Firefox 3.6 has introduced a new tab behaviour, where new tabs are opened next to your currently selected tab, while Firefox 3.5 and older would open new tabs at the end of all your tabs.

If you don’t like this new behaviour, you can change it back to the way it was. Simply follow these steps:

  1. Go to about:config in the address bar
  2. Search for browser.tabs.insertRelatedAfterCurrent
  3. Double click the value to change it from true to false
  4. Done!

Enjoy surfing the way you are used too.

As announced yesterday, Mozilla have released Firefox 3.6 right as expected at 9:30 PST.

Firefox includes many new features, including:

  • Support for a new type of theme called Personas
  • Checks for out-of-date plugins
  • Full screen support for HTML5 <video> tags
  • More HTML5 element support
  • Improved JavaScript speed and stability
  • Plus more

A full list of changes in Firefox 3.6 can be found in the release notes.

Mozilla have also released a 2 minute video showing some of these new features.

Firefox 3.6 can be downloaded from the Firefox website, or current Firefox users can go to the Help menu and select Check for Updates.

Tags: , , , Categories: Firefox Comments Off on Firefox 3.6 Released