Language Selection

English French German Italian Portuguese Spanish

IE And Firefox Sport New Zero-day Flaw

Filed under
Security

Multiple security organizations warned Tuesday that Internet Explorer, Firefox, Mozilla, and SeaMonkey -- on Windows, Linux, and the Mac -- are vulnerable to a JavaScript bug that could allow a determined attacker to dupe users into giving up sensitive personal information such as credit card or bank account numbers and passwords.

According to Symantec, which issued an alert late afternoon Tuesday, all versions of the Microsoft and Mozilla browsers could be used to harvest data through a JavaScript key-filtering vulnerability.

"This issue is triggered by utilizing JavaScript 'OnKeyDown' events to capture and duplicate keystrokes from users," went the Symantec warning.

The bug would let crafty criminals filter keystrokes entered into a form, say a credit card form to pay for online goods, to an invisible file upload dialog on the same Web page.

Full Story.

More in Tux Machines

Thank You Akademy 2014 Sponsors

Akademy is a non-commercial event, free of charge for all who want to attend. Generous sponsor support helps make Akademy possible. Most of the Akademy budget goes towards travel support for KDE community members from all over the world, contributors who would not be able to attend the conference otherwise. The wide diversity of attendees is essential to the success of the annual in-person Akademy conference. Many thanks to Akademy 2014 sponsors. Read more

Linux @ About.com

During the past month I have been in discussions with a number of people at about.com. I have been provided with the opportunity of writing articles on the linux.about.com subsite and I am in full control of all the content that will appear on that site. It is early days and there is some old content on the site which is a bit out of date but I plan to make linux.about.com a great resource for everyone. Read more

Leftovers: Software

today's howtos