New Firefox Extension Malware

Discussion in 'malware problems & news' started by Magnus Mischel, Sep 25, 2008.

Thread Status:
Not open for further replies.
  1. Magnus Mischel

    Magnus Mischel Security Expert

  2. Arup

    Arup Guest

    Now hopefully all will see the logic of why Opera doesn't use extensions.
     
  3. demonon

    demonon Guest

    And uses widgets?
     
  4. Arup

    Arup Guest


    Opera incorporates most of the features out of the box so neither widgets not user js is needed to make it work and in case a widget is needed, so far no vulnerability has been discovered in the widgets module.
     
  5. yeow

    yeow Registered Member

    So user gets infected (not via browsing, but running an infected file on his pc? article doesn't specify), the malware creates a bad extension in firefox's "extensions" directory?

    If that's how, then it can similarly create a bad widget in opera's widget directory? In that case, it's not abt any vulnerability in firefox's or opera's modules.
     
  6. AKAJohnDoe

    AKAJohnDoe Registered Member

    Simple solution.
     

    Attached Files:

  7. Arup

    Arup Guest


    The Widget follows a different method than FF's extension so it has to be specifically written for Opera.
     
  8. yeow

    yeow Registered Member

    Hi AKAJohnDoe,

    I don't think its abt drivebys. But malware already on infected system, creating new files (bad add-on) inside firefox profile's "extensions" folder.

    Hopefully OP can confirm.
     
  9. yeow

    yeow Registered Member

    Hi Arup :)

    What I meant to point out, is that it may not be due to any browser vulnerability, which u seem to be implying.
     
  10. AKAJohnDoe

    AKAJohnDoe Registered Member

    Regardless, Firefox pauses at startup to inform the user of any new or updated extensions.
     
  11. Magnus Mischel

    Magnus Mischel Security Expert

    Yes, this was installed by a piece of malware downloaded by one of the latest Zlob variants. So it is installed by a malware process directly to the Firefox extensions directory.
     
  12. demonon

    demonon Guest

    Same as I was thinking.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice