Datamation Logo

Mozilla Flaw Springs Privacy Leak

September 16, 2002
Datamation content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

Researchers have found a flaw in Mozilla-based browsers that springs data on
the Web surfing movements of users.

Head researcher at Neopoly Sven Neuhaus said the bug, first discovered
in May, is a serious privacy issue.

In a demonstration of
the flaw, Neuhaus says it exposes the URL of the page a user is viewing to
the Web server of the site visited last, allowing a Web site to track where
a viewer goes next regardless of whether the URL is entered manually or via
a bookmark.

“This bug is still present in the Mozilla 1.1 release… It’s been three
months,” Neuhaus said in a plea for a fix on Bugzilla, the site used to
track vulnerabilities in Mozilla releases.

It affects Mozilla browser versions 0.9x, 1.0, 1.0.1, 1.1 and 1.2 alpha;
Netscape 6.x and 7; Galeon 1.2.x and Chimera 0.5.

Mozilla users are urged to disable JavaScript as a temporary workaround
until a fix is issued. The flaw exists in the “onunload” handler which
loads an image from the referring server about a user’s surfing movements.

In addition to disabling JavaScript, users can avoid the bug by creating a
file “user.js” in the profile folder (the one with the pref.js file) and put
the following line in the file:
user_pref(“capability.policy.default.Window.onunload”, “noAccess”);

This stops the “onunload” handler from being activated.

Mozilla.org, the open source browser project backed by AOL Time Warner
, just released
the 1.1 upgrade to provide increased support for Linux and Mac platforms but
the privacy flaw remains in the upgrade, Neuhaus said.

  SEE ALL
ARTICLES
 

Subscribe to Data Insider

Learn the latest news and best practices about data science, big data analytics, artificial intelligence, data security, and more.

Datamation Logo

Datamation is the leading industry resource for B2B data professionals and technology buyers. Datamation's focus is on providing insight into the latest trends and innovation in AI, data security, big data, and more, along with in-depth product recommendations and comparisons. More than 1.7M users gain insight and guidance from Datamation every year.

Advertisers

Advertise with TechnologyAdvice on Datamation and our other data and technology-focused platforms.

Advertise with Us

Our Brands


Privacy Policy Terms & Conditions About Contact Advertise California - Do Not Sell My Information

Property of TechnologyAdvice.
© 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.