Researcher Finds Scores of Web Browser Holes
A prominent security researcher has published the results of application tests on prominent Web browsers that he claims has uncovered scores of new, previously unknown security holes.
Michal Zalewski is a Poland-based security researcher for Google. In a post on January 1, Zalewski used a blog post to publish the partial results of tests he performed with an application testing - or "fuzzing" - tool called cross_fuzz. The results include the discovery of a large number of remotely exploitable holes in Microsoft's Internet Explorer, Mozilla's Firefox browser, the Opera browser and those using the WebKit HTML rendering engine, which includes Apple's Safari and mobile browsers.
Fuzzers are a kind of automated application testing tool that barrage software applications with data inputs in various formats in an effort to expose vulnerable code and induce crashes. Cross_fuzz is described as a fuzzer that finds holes by exploiting document object model (DOM) operations across and between Web pages.
Editor's Pick
Many of the vendors in question were notified of the holes more than six months ago, prompting Zalewski's call for broader "community engagement" to get the holes fixed. Zalewski claims that "third parties" may be aware of at least one of the remotely exploitable holes he discovered.
Zalewski who is aprominent member of Google's vulnerability research team, has discovered critical holes in common browsers before. He said that the cross_fuzz tool is continuing to find new holes in - published a link to the cross_fuzz application for others to download and try.
Commenting on this Article is closed.
Today's Most Popular
- Anatomy of a LulzSec Attack 'Singles Out' Web 2.0 Weakness
- Common Firewall Feature Enables TCP Hijacking Attacks
- Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops
- Facebook Cancellation Malware Disguised As Adobe Update Making Rounds
- OPINION: Are Anonymous Members Forged in the Crucible of IT Compliance?
Most Commented Stories
-
Forget 'Brogrammers,' Women Have The Edge In DEFCON Social Engineering Contest (9)
-
Defense Contractor Northrop Grumman Hiring For Offensive Cyber Ops (10)
-
The Internet Crime Complaint Center recently warned of malware targeting travelers connecting to Wi-Fi. When traveling, do you (1)
-
HULK DDoS Tool Smash Web Server, Server Fall Down (4)
-
Report: Diablo III Users Find Accounts Hacked, Gold Stolen And New 'Mystery' Friends (2)
Newsletter Sign-up
Take Our Poll
Listen to Latest Podcasts
-
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.
-
You are missing some Flash content that should appear here! Perhaps your browser cannot display it, or maybe it did not initialize correctly.



