May 16, 2008

Mozilla: Firefox Plugin Shipped With Malicious Code

Free Web Hosting, No Ads > CONTRIBUTE > Computers > Computer Security Issues & Exploits

free web hosting

Mozilla: Firefox Plugin Shipped With Malicious Code

Saint_Michael
This piece of news only affect Vietnamese users as the Vietnam language package was infected with malware trojan called e Xorer, and so if you downloaded this language pack in the last few weeks run a scan and the trojan should be picked up. Although this trojan is only a couple of months old and so I don't think everyone has something for it, but check at your vendors website and see if they have a solution for it. As for the cause of this infected plugin, they assume the authors computer was infected at the time when they upload this plugin to the mozilla website.

SOURCE

Reply

Plenoptic
How does a trojan get into a file like that before you upload it? That kind of worries me as to how many other things we download can be infected. That also leaves an excuse for people to get out of blame. Great catch though.

Reply

Saint_Michael
Scary enough all a trojan needs is a single HTML file to work its way through. I should have mention that in the part were they had an idea how the plugin got infected. Thats all it takes for a website to get infected is just a single html file and when that user either goes to the website itself or that page his or her computer will get infected.

Reply



Got an Opinion! Express your Views! (no registration):-
Add your Reply/ Opinion/ Views/ Comments/ Suggestion/ Questions/ Queries etc.
Posts with decent grammar & English will be accepted and please refrain from profanities.
For asking a Question, We recommend you to sign-up (for free) so that you can track the topic easily.

Nature of your Post*: Opinion/ Reply/ Comments
Question/Query
Feedback to us.
       
Name   Email
Title/Question*

(Maximum characters: 10,000)
You have characters left.
Confirm Code:

Recent Queries:-
  1. mozilla - 182.75 hr back.
Similar Topics

Keywords : mozilla firefox plugin shipped malicious code

  1. Hackers Focus Efforts On Firefox, Safari, And Office - (1)
  2. Malicious Microprocessor Opens New Doors For Attack - (2)
    Since hacking became the power house for the criminal underground, the one thing that most hackers
    didn't have was the hardware knowledge to reengineer the hardware to the point that regardless
    what they user did the computer would remain open to attacks. Yesterday the first step was taken to
    actually hack computer hardware to be completely open to attacks as a team from the University of
    Illinois took an altered computer chip in which it would grant back-door access to a computer and
    attackers could unleash their havoc. This is a the gist of what they did to make ...
  3. Opera, Firefox Bug Could Reveal Web Travels - (0)
    OH NO!!! (sarcasm there) QUOTE A flaw in the way the Firefox and Opera browsers
    handle an image file could allow an attacker to see what Web sites a person has visited. The
    problem concerns how the two browsers handle a ".BMP," or bitmap, image file, according to an
    advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem.
    A malicious bitmap file can be created that pulls other information from the browsers' memory.
    Some of the information that can be captured is random, but at other times could be valuable...
  4. Is There An Exploit In Vista Home Premium To Make Firefox Permanant Default Browser? - (4)
    I just got a new laptop, and of course it's loaded with vista. Everything works awesomly!
    (my last PC was from 2001, BIG DIFF.) But the damned thing compulsivly and automatically sets
    Internet Explorer to my default browser and won't let me change certain things which browsers
    will typically handle. 've manually changed it so Firefox handles all the stuff except HTTPS
    and what not (CANNOT CHANGE W/O HACK!), but IE just bumps in every time I want to click a link
    from a non-browser based file /sad.gif" style="vertical-align:middle" emoid=":(" border="...
  5. Firefox Flaws Galore - (7)
    Well it seems firefox flaws are becoming a popular now, the two flaws that have been reported all
    follow the same protocol that had posted about before; QUOTE The flaw lies in Firefox's URL
    handler component.. Like the first flaw, this one could be exploited by attackers to launch
    programs on the victim's PC without authorization, said Tyler Reguly, a security research
    engineer at nCircle Network Security Inc. "They're both related to the URL handling process," he
    said "It's just different errors within that handling process." So far it would se...
  6. Interesting New Ie - Firefox Bug ( A Must Read Asap) - FF 2.0.02 and up users need to know about this (3)
    Well it has finally happen and strangely enough I didn't really think about it until now, but it
    seems a security team found a very high level bug that requires both Internet Explorer 7 and
    Modzilla Fire Fox. This is the jist of the bug; QUOTE The root of the matter is a Firefox
    uniform resource identifier (URI) that allows Web sites to force Firefox to launch with the
    "firefoxurl://" URI, Secunia reported. The way in which the URI handler is registered by Firefox
    causes any parameter to be passed from IE (or another application) to Firefox when the "firefoxurl...
  7. Javascript Botnet Code Leaked To Internet - Big time warning (1)
    Well lets start off by saying these 2 people are complete morons. The first guy who had this thing
    loaded up on the internet so it could be shown on how it works and not securing it so it
    couldn't be downloaded. Does a home server ring a bell? guess not. second guy for downloading
    it and then uploading it to his site with the excuse that "he thought it would be useful to other
    security professionals looking for ways to illustrate just how dangerous a scripting attack can be."
    Now this code has been found on several websites and now could be use to hijack web brow...
  8. Javascript Postamble(); What Is It? - when viewing a web source code it appears (5)
    I was paranoid! After all that cleaning my computer from spyware I realized the following codes
    were showing up constantly (everywhere I go) when I viewed a page source. Just before ends HTML
    <script language=' javascript ' src='
    http://127.0.0.1:****/js.cgi?pca&r=***** '> /script > And after HTML
    <script language=' javascript '>postamble(); /script > WHAT DA HECK IS IT??
    It looks like some java script was calling from within my computer and *'s were changing
    constantly with each time I refreshe...
  9. Zero-day Firefox Exploit - (5)
    Link to Article: http://news.com.com/Hackers+claim+zero-day..._3-6121608.html Thought this was
    interesting. Really caught me offgaurd, didn't expect such a huge flaw on a GPL based program.
    Whats even more scary is they said they have about 30 other flaws found......
  10. Windows Crashing. Can't Use Opera Or Firefox - deleted files in temp folder (3)
    Windows has been acting strangely by now, it freezes/clogs badly, I can't use Opera, MF or
    continue my tutorials due to this problem. It gets on my nerves as I think it was MY problem because
    I deleted MOST of the files in the Temp folder. CODE (Start>Run...>%Temp%)
    That folder, most of the files were deleted by me. I consulted my friend by half-screwed MSN, he
    said I "effed me up the arse" by doing that. He recommended me backing up and formatting. I never
    did that before so I think it will be most-likely half-impossible for me. And as I d...
  11. Microsoft Windows Dhcp Client Service Remote Code Execution Vulnerability - (0)
    What it is A exploit in the buggy OS of XP has been found, this one concering DHCP. OS effected
    Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows
    2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced
    Server SP4 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Datacenter Server SP1
    Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft
    Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Professional Microsof...
  12. Teenager Claims To Find Code Flaw In Gmail - (23)
    QUOTE A teenage blogger claims to have discovered a flaw in Google's Gmail service that
    allows JavaScript to run, potentially allowing a malicious hacker to gather e-mail addresses or
    compromise an account. The supposed flaw may already have been fixed, however. Advertisement: The
    teenager identifies himself in his blog as a 14-year-old named Anthony. His entry about Gmail is
    here. He wrote that he was trying to e-mail JavaScript code from a Yahoo account to a G-mail
    account. The code will run in a preview pane, he wrote. But if the code is mailed from one Gma...
  13. Firefox Exploit - (0)
    QUOTE Earlier this week, I blogged about a site doing a bunch of different exploits, depending
    on what you are running. One of the things the site will do is detect if you have Firefox, and
    attempt to exploit it, using the InstallVersion.compareTo() vulnerability. Read More with
    images Already found to be copying and pasting. Take this time to review our forum rules. Warning.
    ...
  14. Firefox 1.5 Flaws - For Microsoft User (22)
    I got this information from mailing list. yesterday I didn't know why my pc always heavy to be
    loaded. and now i got the answer read Firefox Flaws For A Simple Way. if you use Mozilla
    Firefox 1.5 as your default browser. type Ctrl+Alt+del or open Task Manager. You will see how much
    memory being used by firefox. QUOTE(www.informationweek.com) On December 8, 2005, we published
    a story that wondered: Firefox 1.5: Not Ready For Prime Time? In response, some 450 (and climbing)
    InternetWeek, InformationWeek, TechWeb Pipelines, and Scot's Newsletter readers ha...
  15. Security Issue With Mozilla Based Browsers - Read the story onAstahost.com (22)
    I'm not going to post the same issue / solution on both forums. If you have a Mozilla based
    browser it would be in your best interest to read this story. Browsers affected by this exploit
    are: Mozilla 1.7.x Mozilla Firefox 0.x Mozilla Firefox 1.x Mozilla Thunderbird 0.x Mozilla
    Thunderbird 1.x Security Issue in Mozilla based browsers Thank You Nils...
  16. Mozilla Vs Ie - The battle of browsers (1)
    I thought this is a great place to ask which is more secure and which is better? i like firefox
    because eventhough it lkoads slower and somepages dont work you can increase functionability and
    theres tabbed browsing so you only nee done window open not like 10...
  17. Firefox 1.0.7 - ... firefox! :D (14)
    To some this may seem a bit late. Firefox has released a new version that covers several critical
    issues, and adds more stability. It is a wonderful alternative to Internet Exploer, and offers (in
    my opinion) more security because it blocks most spyware. Article:
    http://www.mozilla.org/products/firefox/releases/1.0.7.html Fixes:
    http://www.mozilla.org/projects/security/k...es.html#Firefox Download:
    http://download.mozilla.org/?product=firef...=win&lang=en-US ...
  18. [exploit] Phpbb 2.0.15 "viewtopic.php" - Remote PHP Code Execution Exploit (3)
    phpBB 2.0.15 "viewtopic.php" Remote PHP Code Execution Exploit #!/usr/bin/pyth0n print
    "\nphpBB 2.0.15 arbitrary command execution eXploit" print " 2005 by rattle@awarenetwork.org"
    print " well, just because there is none." import sys from urllib2 import Request, urlopen from
    urlparse import urlparse, urlunparse from urllib import quote as quote_plus INITTAG = ' '
    ENDTAG = ' ' def makecmd(cmd): return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd
    ,'chr(%d)'%ord(cmd )) _ex = "%sviewtopic.php?t=%s&highlight=%%27." _ex += ...
  19. ? Doesn't G-mail Notifier Work Wit Firefox? - ??Why?? (15)
    Does anyone know ? g-mail Notifier doesnt work on Firefox? It doesnt log u in it jus takz u 2 tha
    login PG. Do u know ?. I accually work @ Google so its embarrasin askin hre. ...
  20. Critical Firefox Exploits - How fast can they fix it... (16)
    Again 2 critical vulnerabilities where discovered/made public last weekend. Critical because
    there's no patch yet.... a workaround is to disable javascript... This will be a nice test...
    How fast can they fix it? Greetz, Rik©...
  21. Firefox Has A Big Time Security Flaw - better get the patch (3)
    just found out on yahoo news that firefox just got a nailed with a big security flaw so a new patch
    is out right now for so better download or you might get hacked phreaked spammed and juice all at
    the same time....
  22. Another Firefox Security Update - Firefox v1.0.3 (6)
    Yes, another update. You can read the fixes at ZDNet or here at the Mozilla Release Notes .
    Before installing v1.0.3 make sure that the directory you've chosen to install into is clean and
    doesn't contain any previous Firefox installations! (known issue) Greetz, Rik©...
  23. Status Bar Spoofing In Firefox - (10)
    Hi /cool.gif' border='0' style='vertical-align:middle' alt='cool.gif' /> Now that Firefox
    get's more popular each day people find more 'bugs' /dry.gif' border='0'
    style='vertical-align:middle' alt='dry.gif' /> The next vulnerability was reported yesterday on
    SecurityTracker.com: QUOTE A spoofing vulnerability was reported in Firefox. A remote user can
    create HTML that, in certain cases, will spoof the status bar. A remote user can create HTML with
    an A HREF link in a table, where the table is embedded within an A HREF tag. If the target user ...
  24. Firefox Security Update (firefox 1.0.2) - Released 23-03-2005 (14)
    Yesterday Mozilla (foundation) released another security update for Firefox. QUOTE(Mozilla
    Foundation) March 23, 2005, (Mountain View, CA). The Mozilla Foundation, a non-profit organization
    dedicated to preserving choice and promoting innovation on the Internet, today announced a security
    update for its Firefox Web browser. The update is a proactive security release to patch a bug
    identified by Internet Security Systems, a premier security research, products, and services
    company. No known exploits of the bug have been reported prior to the update's release. ...
  25. Firefox Content Enabling And Disabling - Content checking (1)
    Where can i find content checking enabling and disabling in firefox like it used to be in Internet
    Explorer ? Is there any method to block a particular website by using password? What is the use
    of profile setting in firefox. It has shown me only one time, since then I am not able to find
    profile setting. Does my problem can be solved by using profile setting?...



Looking for mozilla, firefox, plugin, shipped, malicious, code

Searching Video's for mozilla, firefox, plugin, shipped, malicious, code
advertisement



Mozilla: Firefox Plugin Shipped With Malicious Code



 

 

 

 

ADD REPLY / Got an Opinion! Remove these ADs! RAPID SEARCH! Free Web Hosting [X]
Express your Opinions, Thoughts or Contribute more info. to help others.
Ask your Doubts & Queries to get answers, So that "Together We can help others!"
Register FREE for AD-FREE forum, Create your own topics, Ask Questions, track topics, setup subscriptions & notifications and Get a Free Website w/ Email and FTP.
500MB Space *No Ads*, CPanel, FTP, PHP, MySQL, EMails - 100% FREE