View unanswered posts | View active topics It is currently Thu Apr 18, 2024 11:52 pm



Reply to topic  [ 5 posts ] 
 TWGS BUG: FireFox Security lost with Jumpgate link. 
Author Message
Gameop
User avatar

Joined: Sun Aug 28, 2011 2:56 am
Posts: 81
Location: Montana
Unread post TWGS BUG: FireFox Security lost with Jumpgate link.
Here's an interesting one:

Image

If you click the jumpgate logo above... it sends you to the jumpgate page.

*IF* you do it when you don't have a browser open... it'll open one.

The problem is... if your default browser is firefox... it'll open it in safemode, no add-ons running (Little things like password protection, BlackLists/WhiteLists to keep small children off places on the internet they shouldn't be visiting, Ad-Block Plus, The Persona isn't even there...).

I haven't tried this with any other browser set as my default (IE isn't even allowed internet access on my machine, and I haven't installed Opera or Chrome on this machine yet).

I would say this is an important thing to fix, it has nothing to do with the security of TWGS, but its a security flaw put on a system because of it, and it shouldn't be there any longer than necessary.... but that's just me

_________________
ShapeShifter:
Image

Website/Blog: http://www.netcessor.com/topper
TWGS Server: telnet://108.59.108.53:23


Thu Sep 15, 2011 4:12 pm
Profile YIM
Site Admin
User avatar

Joined: Sun Dec 24, 2000 3:00 am
Posts: 3150
Location: USA
Unread post Re: TWGS BUG: FireFox Security lost with Jumpgate link.
I will definitely have a look at it, but the security risk and bug is with Firefox, because TWGS is using a standard method to open the browser. It uses the Windows Shell api ShellExecute function to fire up the browser. I guarantee TWGS isn't the only program that does this.

_________________
John Pritchett
EIS
---
Help fund the TradeWars websites! If you open a hosting account with A2 Hosting, the service EIS uses for all of its sites, EIS will earn credits toward its hosting bill.


Thu Sep 15, 2011 4:47 pm
Profile WWW
Gameop
User avatar

Joined: Sun Aug 28, 2011 2:56 am
Posts: 81
Location: Montana
Unread post Re: TWGS BUG: FireFox Security lost with Jumpgate link.
John Pritchett wrote:
I will definitely have a look at it, but the security risk and bug is with Firefox, because TWGS is using a standard method to open the browser. It uses the Windows Shell api ShellExecute function to fire up the browser. I guarantee TWGS isn't the only program that does this.


K... I'll mention it on their site. Previous versions of Firefox had a setting to disable Safe Mode (Described as 'for very stable systems only')... I may have just found out why that was there....lol

_________________
ShapeShifter:
Image

Website/Blog: http://www.netcessor.com/topper
TWGS Server: telnet://108.59.108.53:23


Thu Sep 15, 2011 4:53 pm
Profile YIM
Gameop
User avatar

Joined: Sun Aug 28, 2011 2:56 am
Posts: 81
Location: Montana
Unread post Re: TWGS BUG: FireFox Security lost with Jumpgate link.
Found it: http://support.mozilla.com/en-US/questi ... wer-128337

Well this solution was a hack from a year ago... there used to be a switch in the addressbar "about:config" settings

_________________
ShapeShifter:
Image

Website/Blog: http://www.netcessor.com/topper
TWGS Server: telnet://108.59.108.53:23


Thu Sep 15, 2011 4:58 pm
Profile YIM
Site Admin
User avatar

Joined: Sun Dec 24, 2000 3:00 am
Posts: 3150
Location: USA
Unread post Re: TWGS BUG: FireFox Security lost with Jumpgate link.
Crazy stuff. I would think they'd provide two versions, one with and one without safe mode. That way if you don't want/need it, it's not there and doesn't pose a security risk.

_________________
John Pritchett
EIS
---
Help fund the TradeWars websites! If you open a hosting account with A2 Hosting, the service EIS uses for all of its sites, EIS will earn credits toward its hosting bill.


Thu Sep 15, 2011 6:04 pm
Profile WWW
Display posts from previous:  Sort by  
Reply to topic   [ 5 posts ] 

Who is online

Users browsing this forum: No registered users and 6 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
cron
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group.
Designed by STSoftware.