From
C|Net News:
The open-source Firefox Web browser is critically flawed in the way it handles JavaScript, two hackers said Saturday afternoon.
An attacker could commandeer a computer running the browser simply by crafting a Web page that contains some malicious JavaScript code, Mischa Spiegelmock and Andrew Wbeelsoi said in a presentation at the ToorCon hacker conference here. The flaw affects Firefox on Windows, Apple Computer's Mac OS X and Linux, they said.
Props goes to Mischa and Andrew on their discovery. But I wanted to take a moment to quote Window Snyder, Mozilla's Security Chief.
"What they are describing might be a variation on an old attack. We're going to do some investigating."
I had a good feeling after reading that. I mean, she just took it, and said "we'll look into it." But then in the next paragraph, she goes on to say...
"It looks like they had enough information in their slide for an attacker to reproduce it. I think it is unfortunate because it puts users at risk, but that seems to be their goal."
WTF?? It seems to be their goal to put users at risk?? Of course, they're hackers. Right? Hackers are evil! Screw you Window Snyder. Stop with the stereotypes already.
When will they understand?