Netscape and Mozilla leak Web surfing data

Matthew Broersma, ZDNet UK
16 September 2002 08:50 AM
Tags: netscape, web, data, flaw, mozilla, leak, browsers, bug
Netscape and other Web browsers based on the Mozilla development project contain a bug that leaks users' Web surfing data, according to a new report.

The bug reveals the URL of the page a user is viewing to the Web server of the site visited last. This allows a Web server to track where users go after they leave the site, even if the next Web address comes from a bookmark or is manually typed into the browser.

Researcher Sven Neuhaus, who published a security alert about the issue to the Bugtraq mailing list on Wednesday, said he had confirmed the bug in Mozilla 1.0, 1.0.1 and 1.1, though it probably also exists in older Mozilla versions. It also appears in browsers based on Mozilla's technology, including Netscape 7 and Galeon, a Linux application, he said.

Mozilla is an open-source project initiated by Netscape Communications, now part of AOL Time Warner, to foster volunteer interest in its browser technology. Mozilla's features and its Gecko rendering engine are now used in the Netscape 7 commercial software from AOL Time Warner.

The problem lies with a component called "onunload", Neuhaus said. He created a demonstration exploiting the bug, which he said is several weeks old, hoping to prompt Mozilla developers to deliver a fix.

In the meantime, Neuhaus said the vulnerability can be worked around by switching off Javascript.

Advertisement

Talkback 0 comments


Latest Videos

Blogs

  • Chris Duckett PayPal launches Aussie developer program
    PayPal announced the opening of its certification program for Australian developers today, making Australia the first country outside of the US to offer certification.
  • Array Cash cow in a BigTinCan?
    Around one third of Australia's telcos have shut their doors over time, but that isn't stopping new ventures hoping to chip away at carriers' mobile call bonanza. By fighting carriers at the smartphone rather than the home phone, could the latest two contenders be onto something big?
  • Array A third of the way to a zettabyte
    This week on Twisted Wire we look at how internet usage is changing in Australia and around the world. How are we meeting this demand and how is the cost structure changing for the service provider?
  • More blogs »

Tags

Back to top

Featured