A serious flaw in how Firefox handles log-ons could be used by identity thieves to dupe users into disclosing passwords, a noted security researcher said Wednesday.Aviv Raff, an Israeli researcher best known for ferreting out browser flaws, revealed the Firefox spoofing vulnerability on his personal blog, and posted a demonstration video there. He did not go public with any proof-of-concept code or working exploit, however.According to Raff, Firefox 2.0.0.11 — Mozilla Corp.’s most current version — fails to sanitize single quotation marks and spaces in what’s called the “Realm” value of an authentication header. “This makes it possible for an attacker to create a specially crafted Realm value which will look as if the authentication dialog came from a trusted site,” said Raff.Raff outlined a pair of possible attack vectors. One would rely on a malicious site that included a link to a trusted site — a well-known bank, say, or a Web e-mail service such as Gmail or Hotmail — that when clicked would display its usual log-on dialog. In the background, however, the attacker would have crafted a script that exploited the Firefox vulnerability to redirect the username and password entered by the user to the hacker’s server instead of the real deal. Alternately, a rigged image could be delivered via e-mail or embedded in a blog or MySpace page that when clicked generated a legitimate-looking log-on dialog.Raff’s video — a lower-resolution version is on YouTube — shows a spoof of Google Inc.’s Checkout payment system. “Until Mozilla fixes this vulnerability, I recommend not to provide username and password to Web sites which show this dialog,” said Raff in his blog.The company last patched Firefox in late November when it updated the browser to 2.0.0.11. Thursday, Mozilla’s chief of security, Window Snyder, would only say that her team is investigating Raff’s claims.By Gregg Keizer, Computerworld (US online) Related content news UK Cyber Security Council CEO reflects on a year of progress Professor Simon Hepburn sits down with broadcaster ITN to discuss Council’s work around cybersecurity professional standards, careers and learning, and outreach and diversity. By Michael Hill Sep 27, 2023 3 mins Government Government Government news FIDO Alliance certifies security of edge nodes, IoT devices Certification demonstrates that products are at low risk of cyberthreats and will interoperate securely. By Michael Hill Sep 27, 2023 3 mins Certifications Internet Security Security Hardware news analysis Web app, API attacks surge as cybercriminals target financial services The financial services sector has also experienced an increase in Layer 3 and Layer 4 DDoS attacks. By Michael Hill Sep 27, 2023 6 mins Financial Services Industry Cyberattacks Application Security news Immersive Labs adds custom 'workforce exercising' for each organizational role With the new workforce exercising capability, CISOs will be able to see each role’s cybersecurity readiness, risk areas, and exercise progress. By Shweta Sharma Sep 27, 2023 3 mins Security Software Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe