Recent Articles

How Will Your Network Be Compromised?
Every time I attend a "Security Guru's" meeting, I'm amazed by how much time and effort is spent on discussing the complex hacking and computer compromise of computer networks and systems.

Most People Unaware of IM Threats
IMLogic recently conducted a survey of 1,100 enterprise instant message users, and found that most people unknowingly expose their computers and company networks to security threats.

Crouching Trojan, Hidden Malware
Trojans are not just more dangerous than computer viruses, they're stealthier, too. Find out where they hide.

10.05.05


SpreadFirefox.com Hacked Again

By David Utter

The evangelist site for the Firefox browser has been attacked again and will be offline through October.

MozillaZine reports that an unpatched vulnerability in the TWiki software was exploited by remote attackers. Only Spread Firefox was affected; no other Mozilla sites were impacted by the attack.

Despite new processes being in place after a July attack exploited an unpatched flaw in the Drupal content management system, administrators failed to update the TWiki software. Mozilla says TWiki is not used on the main Spread Firefox site.

The Mozilla Foundation notified its registered users via email about the attack; part of the message appears below:

The TWiki software was disabled as soon as we were aware of the attempts to access SpreadFirefox.com. This exploit was limited to SpreadFirefox.com and did not affect mozilla.org web sites or Mozilla software.

We have scanned Spread Firefox servers and at this time do not believe any sensitive data was taken, but as a precautionary measure we have shutdown the site and will be rebuilding the web site from scratch.



About the Author:
David Utter is a staff writer for WebProNews covering technology and business.

AboutEnterpriseSecurityNews
Security news and updates for your enterprise

EnterpriseSecurityNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
DatabaseProNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITmanagementNews.com

 

-- EnterpriseSecurityNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2005 iEntry, Inc. All Rights Reserved Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article

Enterprise Security News News Archives About Us Feedback EnterpriseSecurityNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact