Saint_Michael
May 8 2008, 03:07 PM
| | This piece of news only affect Vietnamese users as the Vietnam language package was infected with malware trojan called e Xorer, and so if you downloaded this language pack in the last few weeks run a scan and the trojan should be picked up. Although this trojan is only a couple of months old and so I don't think everyone has something for it, but check at your vendors website and see if they have a solution for it. As for the cause of this infected plugin, they assume the authors computer was infected at the time when they upload this plugin to the mozilla website.
SOURCE |
Reply
Plenoptic
May 8 2008, 03:26 PM
How does a trojan get into a file like that before you upload it? That kind of worries me as to how many other things we download can be infected. That also leaves an excuse for people to get out of blame. Great catch though.
Reply
Saint_Michael
May 8 2008, 03:29 PM
Scary enough all a trojan needs is a single HTML file to work its way through. I should have mention that in the part were they had an idea how the plugin got infected. Thats all it takes for a website to get infected is just a single html file and when that user either goes to the website itself or that page his or her computer will get infected.
Reply
Recent Queries:--
mozilla - 182.75 hr back.
Similar Topics
Keywords : mozilla firefox plugin shipped malicious code- Hackers Focus Efforts On Firefox, Safari, And Office
- (1)
- Malicious Microprocessor Opens New Doors For Attack
- (2)
Since hacking became the power house for the criminal underground, the one thing that most hackers
didn't have was the hardware knowledge to reengineer the hardware to the point that regardless
what they user did the computer would remain open to attacks. Yesterday the first step was taken to
actually hack computer hardware to be completely open to attacks as a team from the University of
Illinois took an altered computer chip in which it would grant back-door access to a computer and
attackers could unleash their havoc. This is a the gist of what they did to make ...
Opera, Firefox Bug Could Reveal Web Travels
- (0)
OH NO!!! (sarcasm there) QUOTE A flaw in the way the Firefox and Opera browsers
handle an image file could allow an attacker to see what Web sites a person has visited. The
problem concerns how the two browsers handle a ".BMP," or bitmap, image file, according to an
advisory written by Gynvael Coldwind of Vexillium.org, who posted a video illustrating the problem.
A malicious bitmap file can be created that pulls other information from the browsers' memory.
Some of the information that can be captured is random, but at other times could be valuable...
Is There An Exploit In Vista Home Premium To Make Firefox Permanant Default Browser?
- (4)
I just got a new laptop, and of course it's loaded with vista. Everything works awesomly!
(my last PC was from 2001, BIG DIFF.) But the damned thing compulsivly and automatically sets
Internet Explorer to my default browser and won't let me change certain things which browsers
will typically handle. 've manually changed it so Firefox handles all the stuff except HTTPS
and what not (CANNOT CHANGE W/O HACK!), but IE just bumps in every time I want to click a link
from a non-browser based file /sad.gif" style="vertical-align:middle" emoid=":(" border="...
Firefox Flaws Galore
- (7)
Well it seems firefox flaws are becoming a popular now, the two flaws that have been reported all
follow the same protocol that had posted about before; QUOTE The flaw lies in Firefox's URL
handler component.. Like the first flaw, this one could be exploited by attackers to launch
programs on the victim's PC without authorization, said Tyler Reguly, a security research
engineer at nCircle Network Security Inc. "They're both related to the URL handling process," he
said "It's just different errors within that handling process." So far it would se...
Interesting New Ie - Firefox Bug ( A Must Read Asap)
- FF 2.0.02 and up users need to know about this (3)
Well it has finally happen and strangely enough I didn't really think about it until now, but it
seems a security team found a very high level bug that requires both Internet Explorer 7 and
Modzilla Fire Fox. This is the jist of the bug; QUOTE The root of the matter is a Firefox
uniform resource identifier (URI) that allows Web sites to force Firefox to launch with the
"firefoxurl://" URI, Secunia reported. The way in which the URI handler is registered by Firefox
causes any parameter to be passed from IE (or another application) to Firefox when the "firefoxurl...
Javascript Botnet Code Leaked To Internet
- Big time warning (1)
Well lets start off by saying these 2 people are complete morons. The first guy who had this thing
loaded up on the internet so it could be shown on how it works and not securing it so it
couldn't be downloaded. Does a home server ring a bell? guess not. second guy for downloading
it and then uploading it to his site with the excuse that "he thought it would be useful to other
security professionals looking for ways to illustrate just how dangerous a scripting attack can be."
Now this code has been found on several websites and now could be use to hijack web brow...
Javascript Postamble(); What Is It?
- when viewing a web source code it appears (5)
I was paranoid! After all that cleaning my computer from spyware I realized the following codes
were showing up constantly (everywhere I go) when I viewed a page source. Just before ends HTML
<script language=' javascript ' src='
http://127.0.0.1:****/js.cgi?pca&r=***** '> /script > And after HTML
<script language=' javascript '>postamble(); /script > WHAT DA HECK IS IT??
It looks like some java script was calling from within my computer and *'s were changing
constantly with each time I refreshe...
Zero-day Firefox Exploit
- (5)
Link to Article: http://news.com.com/Hackers+claim+zero-day..._3-6121608.html Thought this was
interesting. Really caught me offgaurd, didn't expect such a huge flaw on a GPL based program.
Whats even more scary is they said they have about 30 other flaws found......
Windows Crashing. Can't Use Opera Or Firefox
- deleted files in temp folder (3)
Windows has been acting strangely by now, it freezes/clogs badly, I can't use Opera, MF or
continue my tutorials due to this problem. It gets on my nerves as I think it was MY problem because
I deleted MOST of the files in the Temp folder. CODE (Start>Run...>%Temp%)
That folder, most of the files were deleted by me. I consulted my friend by half-screwed MSN, he
said I "effed me up the arse" by doing that. He recommended me backing up and formatting. I never
did that before so I think it will be most-likely half-impossible for me. And as I d...
Microsoft Windows Dhcp Client Service Remote Code Execution Vulnerability
- (0)
What it is A exploit in the buggy OS of XP has been found, this one concering DHCP. OS effected
Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows
2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced
Server SP4 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft
Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Professional Microsof...
Teenager Claims To Find Code Flaw In Gmail
- (23)
QUOTE A teenage blogger claims to have discovered a flaw in Google's Gmail service that
allows JavaScript to run, potentially allowing a malicious hacker to gather e-mail addresses or
compromise an account. The supposed flaw may already have been fixed, however. Advertisement: The
teenager identifies himself in his blog as a 14-year-old named Anthony. His entry about Gmail is
here. He wrote that he was trying to e-mail JavaScript code from a Yahoo account to a G-mail
account. The code will run in a preview pane, he wrote. But if the code is mailed from one Gma...
Firefox Exploit
- (0)
QUOTE Earlier this week, I blogged about a site doing a bunch of different exploits, depending
on what you are running. One of the things the site will do is detect if you have Firefox, and
attempt to exploit it, using the InstallVersion.compareTo() vulnerability. Read More with
images Already found to be copying and pasting. Take this time to review our forum rules. Warning.
...
Firefox 1.5 Flaws
- For Microsoft User (22)
I got this information from mailing list. yesterday I didn't know why my pc always heavy to be
loaded. and now i got the answer read Firefox Flaws For A Simple Way. if you use Mozilla
Firefox 1.5 as your default browser. type Ctrl+Alt+del or open Task Manager. You will see how much
memory being used by firefox. QUOTE(www.informationweek.com) On December 8, 2005, we published
a story that wondered: Firefox 1.5: Not Ready For Prime Time? In response, some 450 (and climbing)
InternetWeek, InformationWeek, TechWeb Pipelines, and Scot's Newsletter readers ha...
Security Issue With Mozilla Based Browsers
- Read the story onAstahost.com (22)
I'm not going to post the same issue / solution on both forums. If you have a Mozilla based
browser it would be in your best interest to read this story. Browsers affected by this exploit
are: Mozilla 1.7.x Mozilla Firefox 0.x Mozilla Firefox 1.x Mozilla Thunderbird 0.x Mozilla
Thunderbird 1.x Security Issue in Mozilla based browsers Thank You Nils...
Mozilla Vs Ie
- The battle of browsers (1)
I thought this is a great place to ask which is more secure and which is better? i like firefox
because eventhough it lkoads slower and somepages dont work you can increase functionability and
theres tabbed browsing so you only nee done window open not like 10...
Firefox 1.0.7
- ... firefox! :D (14)
To some this may seem a bit late. Firefox has released a new version that covers several critical
issues, and adds more stability. It is a wonderful alternative to Internet Exploer, and offers (in
my opinion) more security because it blocks most spyware. Article:
http://www.mozilla.org/products/firefox/releases/1.0.7.html Fixes:
http://www.mozilla.org/projects/security/k...es.html#Firefox Download:
http://download.mozilla.org/?product=firef...=win&lang=en-US ...
[exploit] Phpbb 2.0.15 "viewtopic.php"
- Remote PHP Code Execution Exploit (3)
phpBB 2.0.15 "viewtopic.php" Remote PHP Code Execution Exploit #!/usr/bin/pyth0n print
"\nphpBB 2.0.15 arbitrary command execution eXploit" print " 2005 by rattle@awarenetwork.org"
print " well, just because there is none." import sys from urllib2 import Request, urlopen from
urlparse import urlparse, urlunparse from urllib import quote as quote_plus INITTAG = ' '
ENDTAG = ' ' def makecmd(cmd): return reduce(lambda x,y: x+'.chr(%d)'%ord(y),cmd
,'chr(%d)'%ord(cmd )) _ex = "%sviewtopic.php?t=%s&highlight=%%27." _ex += ...
? Doesn't G-mail Notifier Work Wit Firefox?
- ??Why?? (15)
Does anyone know ? g-mail Notifier doesnt work on Firefox? It doesnt log u in it jus takz u 2 tha
login PG. Do u know ?. I accually work @ Google so its embarrasin askin hre. ...
Critical Firefox Exploits
- How fast can they fix it... (16)
Again 2 critical vulnerabilities where discovered/made public last weekend. Critical because
there's no patch yet.... a workaround is to disable javascript... This will be a nice test...
How fast can they fix it? Greetz, Rik©...
Firefox Has A Big Time Security Flaw
- better get the patch (3)
just found out on yahoo news that firefox just got a nailed with a big security flaw so a new patch
is out right now for so better download or you might get hacked phreaked spammed and juice all at
the same time....
Another Firefox Security Update
- Firefox v1.0.3 (6)
Yes, another update. You can read the fixes at ZDNet or here at the Mozilla Release Notes .
Before installing v1.0.3 make sure that the directory you've chosen to install into is clean and
doesn't contain any previous Firefox installations! (known issue) Greetz, Rik©...
Status Bar Spoofing In Firefox
- (10)
Hi /cool.gif' border='0' style='vertical-align:middle' alt='cool.gif' /> Now that Firefox
get's more popular each day people find more 'bugs' /dry.gif' border='0'
style='vertical-align:middle' alt='dry.gif' /> The next vulnerability was reported yesterday on
SecurityTracker.com: QUOTE A spoofing vulnerability was reported in Firefox. A remote user can
create HTML that, in certain cases, will spoof the status bar. A remote user can create HTML with
an A HREF link in a table, where the table is embedded within an A HREF tag. If the target user ...
Firefox Security Update (firefox 1.0.2)
- Released 23-03-2005 (14)
Yesterday Mozilla (foundation) released another security update for Firefox. QUOTE(Mozilla
Foundation) March 23, 2005, (Mountain View, CA). The Mozilla Foundation, a non-profit organization
dedicated to preserving choice and promoting innovation on the Internet, today announced a security
update for its Firefox Web browser. The update is a proactive security release to patch a bug
identified by Internet Security Systems, a premier security research, products, and services
company. No known exploits of the bug have been reported prior to the update's release. ...
Firefox Content Enabling And Disabling
- Content checking (1)
Where can i find content checking enabling and disabling in firefox like it used to be in Internet
Explorer ? Is there any method to block a particular website by using password? What is the use
of profile setting in firefox. It has shown me only one time, since then I am not able to find
profile setting. Does my problem can be solved by using profile setting?...
Looking for mozilla, firefox, plugin, shipped, malicious, code
|
|
Searching Video's for mozilla, firefox, plugin, shipped, malicious, code
|
advertisement
|
|