On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

October 3rd, 2006

Embarrassing Firefox pranksters

Posted by George Ou @ 3:30 pm

Categories: Security

Tags:

Two of the presenters at the ToorCon 8 event embarrassed themselves by pulling a prank on the media and Mozilla.  The two claimed to have remotely compromised Mozilla Firefox when in fact they had only crashed it.  They have now backpedaled and retracted their statement with this letter to Mozilla stating that it was meant to be "humorous" but no one in the security community found it to be amusing.  As for the claim that they had 30 zero-day vulnerabilities, Mischa Spiegelmock blamed his co-presenter Andrew Wbeelsoi and said he had nothing to do with it.  Unfortunately for Spiegelmock, the time to speak up would have been Saturday during the presentation.

Taking the cautious and responsible approach, Window Snyder (Chief of Mozilla security) was still concerned about the crash in Mozilla Firefox and is treating it as a potentially serious flaw.  Snyder stated that Spiegelmock was cooperating with Mozilla.

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

Related Discussions on TechRepublic

Did you know you can take part in these discussions with your ZDNet membership?

  • Talkback
  • Most Recent of 235 Talkback(s)
Fox didn't "accuse". She stated by default.
Fox did say the things George has said she said, and you apparently just don't have much use for the english language when it states a fact you don't care for.

You had better face facts; if Lyn... (Read the rest)
Posted by: Cayble Posted on: 02/05/08 You are currently: a Guest | | Terms of Use
They embarrassed more than themselves  tic swayback | 10/03/06
Mozilla took this seriously and still is  georgeou | 10/03/06
Good to see  nucrash | 10/03/06
Mozilla and the media is acting responsibly  georgeou | 10/03/06
Wrong!!!  techboy_z | 10/04/06
Have you dealt anything with journalism?  nucrash | 10/04/06
True, individual bloggers like George Ou (Dan Quayle) probably over did it,  DonnieBoy | 10/04/06
Be thankful I am not a Moderator  nucrash | 10/04/06
If you can't stand the heat, get out of the kitchen. George throws up  DonnieBoy | 10/04/06
I would never do that  tic swayback | 10/03/06
You did see the correction right?  georgeou | 10/03/06
Corrections are good  tic swayback | 10/03/06
You don't correct all of your mistakes George  dgtruckses | 10/03/06
Wasn't a mistake  georgeou | 10/03/06
So why don't you deliver?  Robert Crocker | 10/03/06
Journalism 101  dgtruckses | 10/03/06
Because the source told me off the record  georgeou | 10/03/06
And we're supposed to believe that?  StevoCJ | 10/04/06
You can believe what you want steve  georgeou | 10/04/06
Where do you draw the line?  scott.kent | 10/04/06
scott.kent: good post, there are a lot of Dan Quayle idiot bloggers out  DonnieBoy | 10/04/06
I think there have been plenty of fireworks  Cayble | 10/03/06
Since when?  jragosta | 10/04/06
No, you didn't....  techboy_z | 10/04/06
News as you saw it?  jasonp@... | 10/05/06
Thinking about it more, perhaps the lesson here is for us readers  tic swayback | 10/03/06
Yet there is Wikipedia  nucrash | 10/03/06
Look in the mirror  georgeou | 10/03/06
Okay, will do  tic swayback | 10/03/06
I see you know how to use bookmarks.  georgeou | 10/03/06
ZDNet's search function, actually  tic swayback | 10/03/06
Let's get a few things clear  georgeou | 10/03/06
Try THIS one George  Robert Crocker | 10/03/06
I don't have to do any such thing  georgeou | 10/03/06
What about this mistake, George?  V-Train | 10/04/06
Atheros had nothing to do with the orchestrated assault  georgeou | 10/04/06
Bzzzzzzzz. Try again, George.  V-Train | 10/04/06
A vocabulary lesson and specific examples  tic swayback | 10/04/06
"off the record"?  Robert Crocker | 10/04/06
George, get your story straight  dgtruckses | 10/04/06
And Sam Leffler never worked on the Atheros OSX driver?  GW Mahoney | 10/04/06
you're pretty bad George  Monkey_MCSE | 10/04/06
hey Monkey, where did you learn to BS  BrutalTruth | 10/04/06
i guess with brutaltruth  Monkey_MCSE | 10/04/06
what about 2 exploits  bkwatch | 10/03/06
Your poor interpretation  georgeou | 10/04/06
No one believes....  jragosta | 10/05/06
Ok, no more hiding...  jasonp@... | 10/05/06
Fool me  D-T-Schmitz | 10/03/06
Rise above it Dietrich  georgeou | 10/03/06
Give George some credit here  tic swayback | 10/03/06
agreed  D-T-Schmitz | 10/03/06
bloggers vs. journalists  bkwatch | 10/03/06
Krebs has only reported what he was shown and was told  georgeou | 10/03/06
Why did Maynor demo 3rd party card?  dgtruckses | 10/03/06
That was off-the-record  georgeou | 10/03/06
You just said Maynor supports Krebs' story  dgtruckses | 10/04/06
Hey tic.. Generally I agree with you...  ju1ce | 10/04/06
If you're going to publish something...  tic swayback | 10/04/06
Integrity  D-T-Schmitz | 10/04/06
Well, of course he will...  techboy_z | 10/04/06
Easy answer...  ju1ce | 10/04/06
ZDNet doesn't care  jragosta | 10/04/06
Allright  D-T-Schmitz | 10/03/06
Going up in arms everytime is bad news about Mozilla  georgeou | 10/04/06
i like this George...  Monkey_MCSE | 10/04/06
Objectivity  D-T-Schmitz | 10/04/06
Not really fair  tic swayback | 10/04/06
To Dietrich  georgeou | 10/04/06
To George  D-T-Schmitz | 10/04/06
Thank you Dietrich  georgeou | 10/04/06
No, because you are not supposed to take a blog like news  Cayble | 10/03/06
Editorial columns require trust and accuracy as well  tic swayback | 10/04/06
ALL the editorials, news stories, and chief of Mozilla security  georgeou | 10/04/06
And they should all be faulted for their reporting  tic swayback | 10/04/06
You can't be serious  georgeou | 10/04/06
Hey, George....  jragosta | 10/05/06
What part of Mozilla taking this seriously do you not understand?  georgeou | 10/05/06
Maybe I just have higher standards than you  tic swayback | 10/05/06
The media did thier job here. The just reported the news. The news was  DonnieBoy | 10/04/06
Not only did we say they were credible, but low lifes  georgeou | 10/04/06
agree  rwahrens1952 | 10/04/06
That's a dirty and ignorant accusation  georgeou | 10/04/06
Accusations  jragosta | 10/04/06
It's obvious what you want to believe  georgeou | 10/04/06
Grade School Reading Lesson 103  DavidBurke | 10/04/06
Thank you  rwahrens1952 | 10/04/06
Nice try George  jragosta | 10/04/06
No one should be proud here  tic swayback | 10/05/06
Taken? So Mozilla was taken too?  georgeou | 10/05/06
Try to do better next time  tic swayback | 10/05/06
I know you get paid to do this, George,  JetJaguar | 10/05/06
Intention is irrelevant  tic swayback | 10/05/06
Bravo Mozilla...  timyu | 10/03/06
Interesting point  dgtruckses | 10/03/06
Bravo Apple...  GW Mahoney | 10/03/06
Exactly  jragosta | 10/04/06
Big difference you're too blind to see  georgeou | 10/04/06
Calling Apple and Lynn Fox liars again?  tic swayback | 10/04/06
Are you losing it?  georgeou | 10/04/06
Did you reply to the correct post?  tic swayback | 10/04/06
Yes, wrong thread  georgeou | 10/04/06
Irrelevant  jragosta | 10/04/06
Yes, I'm seriously questioning it  georgeou | 10/04/06
It's hard to judge  tic swayback | 10/04/06
To live and die in PR  JetJaguar | 10/04/06
I'm rolling on the ground laughing  georgeou | 10/04/06
Incredible?  jragosta | 10/04/06
Are you changing your argument here?  GW Mahoney | 10/04/06
Yes, but you don't give non-Apple crash dumps unless you are a retard  georgeou | 10/05/06
Have a nice roll  tic swayback | 10/05/06
Okay, fine  gskiii | 10/05/06
To Gskii  georgeou | 10/05/06
Why?  jragosta | 10/05/06
Given that there are no facts...  jragosta | 10/05/06
the problem is Maynor  bkwatch | 10/05/06
Clarification: Fox said nothing of the sort  timyu | 10/04/06
You're simply denying what's on the record  georgeou | 10/04/06
Record demonstrates public speculation re: meaning of Fox's words (NT)  timyu | 10/04/06
So full of it.  Cayble | 02/05/08
not even close...  doh123 | 10/04/06
wrong  rwahrens1952 | 10/04/06
Nope, she even pointed to the FreeBSD CVE  georgeou | 10/04/06
speaking of learning to read....  richvball44 | 10/05/06
Thank you for confirming your logic comprehension level Rich  georgeou | 10/05/06
And, Mozilla is still diligently working on the problem in case there is  DonnieBoy | 10/04/06
Big difference here  georgeou | 10/04/06
Clarification: Fox said nothing of the sort  timyu | 10/04/06
Yes she did, it's in public record  georgeou | 10/04/06
here is where you are wrong...  doh123 | 10/04/06
Doesn't change the facts one bit  georgeou | 10/04/06
Grade Scool Reading Lesson 102  DavidBurke | 10/04/06
Grade School Reading lesson 101  DavidBurke | 10/04/06
Primers?  timyu | 10/06/06
Fox didn't "accuse". She stated by default.  Cayble | 02/05/08
analogy  richvball44 | 10/05/06
Better analogy  georgeou | 10/05/06
Huh?  jragosta | 10/05/06
Your reading comprehension is beyond hope  georgeou | 10/05/06
Are you really this stupid, George?  jragosta | 10/05/06
You've just been shot down and name calling doesn't help  georgeou | 10/05/06
Show us, George  jragosta | 10/06/06
Good post, if by "better" you meant "worse"  timyu | 10/05/06
How did people fall for this...  GW Mahoney | 10/03/06
Stupid  opensourcepro | 10/04/06
Error Not Corrected  1macgeek | 10/04/06
Maynor: "Krebs did nothing wrong"  dgtruckses | 10/04/06
So George contradicts himself  V-Train | 10/04/06
Story seems staraight, you just do not want to see it that way.  DavidBurke | 10/04/06
Learn to read better  V-Train | 10/04/06
failure of basic logic on your part  georgeou | 10/04/06
Sure George  V-Train | 10/04/06
Responsible disclosure, followed by purposeful leak  dgtruckses | 10/05/06
Definition of responsible disclosure  georgeou | 10/05/06
Maynor a victim? Hardly.  dgtruckses | 10/05/06
George, why did Maynor demo to Krebs?  dgtruckses | 10/05/06
I just told you  georgeou | 10/05/06
Real definition of responsible disclosure, which M & E DID NOT follow  V-Train | 10/06/06
You're a hypocrite, George  jragosta | 10/06/06
Maynor works for secureworks, right?  dgtruckses | 10/06/06
George, you're a Maynor lackey  dgtruckses | 10/06/06
Burkian logic on "Krebs did nothing wrong"  dgtruckses | 10/05/06
ask Krebs tomorrow  bkwatch | 10/05/06
I have to wonder  Shelendrea | 10/04/06
Well, George did bring it up  tic swayback | 10/04/06
Unsubstantiated Reports  D-T-Schmitz | 10/04/06
Once  jragosta | 10/04/06
Wow David, you are pathetically stubborn  V-Train | 10/09/06
I agree, he did change his story..  Monkey_MCSE | 10/04/06
Kill them all, let God sort them out  tic swayback | 10/04/06
They are far more likely to be liable for monetary damages.  DavidBurke | 10/04/06
How about being evenhanded?  jragosta | 10/05/06
Correct, except for a couple of things  DavidBurke | 10/05/06
You're pretending to be a laegal professional?  jragosta | 10/06/06
You need to learn how to spell! ( laegal )??  DavidBurke | 12/30/06
because George...  doh123 | 10/04/06
protecting sources vs. protecting your readers  bkwatch | 10/05/06
This is the source of George's dilemma -  gskiii | 10/05/06
Burke  jragosta | 10/06/06
That's my approach -  gskiii | 10/06/06
If you write it often enough I'm betting you will believe it.  DavidBurke | 10/06/06
I had to double check  gskiii | 10/06/06
hahaha  richvball44 | 10/07/06
Sorry, you lose  jragosta | 10/07/06
I find your methods quite irrational  DavidBurke | 10/07/06
LOL! You think Sophos is an unbiased source?!  V-Train | 10/08/06
Misinformation alert!  GW Mahoney | 10/08/06
David manages to find a clueless journalist.  jragosta | 10/08/06
you're confusing trojans and worms  JetJaguar | 10/08/06
According to your own definition, JetJaguar, it is not a worm  V-Train | 10/08/06
Nice job, JetJaguar  jragosta | 10/08/06
Let's see you defend your own errors  JetJaguar | 10/08/06
Let's see you defend your own errors (with italics corrected)  JetJaguar | 10/08/06
Sorry, you lose jragosta  DavidBurke | 10/08/06
David, what a pathetic attempt to weasel out of your words  V-Train | 10/08/06
Show me the claim mvora  DavidBurke | 10/08/06
You stated: "there have been at least a couple (viruses) I am aware of"  V-Train | 10/08/06
Why it's imposissible to have a discussion with David  jragosta | 10/09/06
Still think worms aren't viruses?  JetJaguar | 10/09/06
You just keep losing over and over again jragosta  DavidBurke | 10/09/06
Clueless David  jragosta | 10/09/06
Virus vs Worm  jragosta | 10/09/06
Congrats jragosta, you've CLEARLY checkmated Mr. Burke...  thelemite | 10/09/06
btw Davie, please explain to everyone....  thelemite | 10/09/06
Ha! jragosta, why do you insist on talking nonsense?  DavidBurke | 10/09/06
Wow David, you are pathetically stubborn  V-Train | 10/09/06
And you mvora are nauseatingly obtuse  DavidBurke | 10/09/06
You wouldn't know the truth if it bit you in the...  V-Train | 10/09/06
You wouldn?t admit the truth mvora even if it would save your shattered rep  DavidBurke | 10/09/06
Can't be settled here...  GW Mahoney | 10/10/06
Sophos doesn't agree with you  jragosta | 10/10/06
Don't waste your time, jragosta  V-Train | 10/10/06
Time to end this sillyness anyway.  DavidBurke | 10/10/06
Ha, an attempt to claim the high ground?  timyu | 10/10/06
Yes, we know, David  jragosta | 10/10/06
Give it a rest, trust me, its over....  DavidBurke | 10/11/06
Another biased article  jragosta | 10/11/06
A worm is a virus  JetJaguar | 10/13/06
Timeline  bkwatch | 10/06/06
Timeline is odd, agreed  dgtruckses | 10/08/06
Explanation  jragosta | 10/09/06
a very logical explanation  bkwatch | 10/09/06
Evidence?  jragosta | 10/09/06
no evidence -- speculation  bkwatch | 10/09/06
I don't think Maynor knew  jragosta | 10/09/06
this is interesting....  bkwatch | 10/09/06
Secureworks keeping it alive?  dgtruckses | 10/10/06
SecureWorks keeping it alive?  jragosta | 10/11/06
They are keeping it alive --in a strange fashion  bkwatch | 10/12/06
Paid trolls  doctordawg | 10/04/06
They were lying IDIOTS who cried "wolf" and who should be SPANKED!!!  rh0 | 10/04/06
Parallel story  tic swayback | 10/06/06
You wouldn't need a 'parallel' story  JetJaguar | 10/06/06
Was it stained any more than the players?  tic swayback | 10/06/06
Fill in the blanks, please.  timyu | 10/07/06

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    SmartPlanet

    Click Here