Free Newsletters :
Visit ServerWatch for summaries of server and development tool updates, the latest on server news and trends, and more.

Will Mozilla's Fuzzer Break The Web?

July 31, 2007
By Sean Michael Kerner




UPDATED: The Web browser is the most basic common unit of the Internet experience for much of the global community. It's also one of the most attacked. And it's not just the bad guys breaking the browsers anymore, but also the browser vendors.

On Wednesday, Mozilla will take a massive step forward and explain to an audience at the annual Black Hat show in Las Vegas how to break the browser using tools that Mozilla has developed and is expected to release.

In a session called Building and Breaking the Browser, Mozilla's Chief Security Officer Window Snyder is expected to discuss a number of security tools, including protocol fuzzers for HTTP and FTP and a fuzzer for JavaScript. While the intention is to make Mozilla's Firefox technology even more secure, the tools could potentially also put millions at risk.

Fuzzing is also known as fault-injection testing and is a widely used technique in security circles to try and break down applications and expose flaws. The Black Hat session abstract indicates that at least one of those tools will be released at the Black Hat event.

In a discussion with internetnews.com in March, Snyder indicated that Mozilla already runs the whole spectrum of security testing tools and approaches on its products.

She also said that Mozilla's security effort could also one day lead to a Mozilla open source effort on security tools and information. Snyder noted that when Mozilla makes such tools and information available, they will be part of the balance that Mozilla is striving to seek between functionality, security and disclosure.

Ahead of Black Hat, internetnews.com approached other browsers for any information they might have had on Mozilla's fuzzer, and Opera came up with the most over Microsoft and Google.

Opera spokesman Thomas Ford told internetnews.com via e-mail that Mozilla sent its fuzzer to two Opera developers, and the testing group is now testing it against different products.

A Google spokesperson said that likely contacts at Google were not aware of the Mozilla fuzzer. Google recently revealed its own fuzzer effort called Lemon, though it's not likely to be publicly released.

The Google spokesperson also told internetnews.com that without knowing any details of the Mozilla fuzzer, it is impossible to know whether it would be something that Google would use in addition to Google Lemon.

Microsoft did not directly answer a question about whether it was aware of Mozilla's fuzzer. A Microsoft spokesperson noted, however, that fuzzing is an important part of the security development lifecycle process, and Microsoft is supportive of other companies adopting similar methods to help protect their users.

But Opera's Krogh still had his concerns about how Mozilla's fuzzer could end up being used.

"Any tool given to the public to find ways of exploiting a piece of software is at risk of being misued," Krogh said. "When an organization publishes such tools, it must consider whether that tool can be a disservice to millions of innocent bystanders."

Opera uses fuzzers and other tools, homegrown and otherwise, to secure its browser technology.

This article was first published on InternetNews.com. To read the full article, click here.

1
Heroes Happen Here Launch Events
Attend the upcoming launch of three powerful new products, take a test drive, meet the teams, and leave with promotional copies of Windows Server 2008, Microsoft SQL Server 2008, and Microsoft Visual Studio 2008. Register here. »

 
Install What You Need with Windows Server 2008
Windows Server 2008 is Microsoft's most full-featured server operating system yet, so it's ironic that one of its most exciting new features is an install option that cuts out most of the other features. Paul Rubens explores why a Server Core installation makes a great deal of sense in many instances. »

 
Simplify Big Business IT for Small and Midsize Companies
Windows Small Business Server 2008 and Windows Essential Business Server 2008 deliver all-in-one solutions to help fuel growth for customers and partners. »

 
Q&A with Bob Muglia: Senior VP, Server and Tools Division
Bob Muglia, senior vice president, Server and Tools Division, discusses Microsoft's new interoperability principles and the steps the company is taking to increase the openness of its products. »

 
Q&A with Lutz Ziob, GM of Microsoft Learning
Lutz Ziob, the general manager of Microsoft Learning, talks about how IT professionals can become certified heroes within their enterprises by getting trained and certified in Windows Server 2008. »
On the Forums


JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers

Solutions
Whitepapers and eBooks
Microsoft Article: Will Hyper-V Make VMware This Decade's Netscape?
Microsoft Article: 7.0, Microsoft's Lucky Version?
Microsoft Article: Hyper-V--The Killer Feature in Windows Server 2008
Avaya Article: How to Feed Data into the Avaya Event Processor
Microsoft Article: Install What You Need with Windows Server 2008
HP eBook: Putting the Green into IT
Whitepaper: HP Integrated Citrix XenServer for HP ProLiant Servers
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 1
Intel Go Parallel Portal: Interview with C++ Guru Herb Sutter, Part 2--The Future of Concurrency
Avaya Article: Setting Up a SIP A/S Development Environment
IBM Article: How Cool Is Your Data Center?
Microsoft Article: Managing Virtual Machines with Microsoft System Center
HP eBook: Storage Networking , Part 1
Microsoft Article: Solving Data Center Complexity with Microsoft System Center Configuration Manager 2007
MORE WHITEPAPERS, EBOOKS, AND ARTICLES
Webcasts
Intel Video: Are Multi-core Processors Here to Stay?
On-Demand Webcast: Five Virtualization Trends to Watch
HP Video: Page Cost Calculator
Intel Video: APIs for Parallel Programming
HP Webcast: Storage Is Changing Fast - Be Ready or Be Left Behind
Microsoft Silverlight Video: Creating Fading Controls with Expression Design and Expression Blend 2
MORE WEBCASTS, PODCASTS, AND VIDEOS
Downloads and eKits
Sun Download: Solaris 8 Migration Assistant
Sybase Download: SQL Anywhere Developer Edition
Red Gate Download: SQL Backup Pro and free DBA Best Practices eBook
Red Gate Download: SQL Compare Pro 6
Iron Speed Designer Application Generator
MORE DOWNLOADS, EKITS, AND FREE TRIALS
Tutorials and Demos
How-to-Article: Preparing for Hyper-Threading Technology and Dual Core Technology
eTouch PDF: Conquering the Tyranny of E-Mail and Word Processors
IBM Article: Collaborating in the High-Performance Workplace
HP Demo: StorageWorks EVA4400
Intel Featured Algorhythm: Intel Threading Building Blocks--The Pipeline Class
Microsoft How-to Article: Get Going with Silverlight and Windows Live
MORE TUTORIALS, DEMOS AND STEP-BY-STEP GUIDES