Is Your Browser Extension a Botnet Backdoor?

Discussion in 'other security issues & news' started by ronjor, Mar 1, 2021.

  1. ronjor

    ronjor Global Moderator

    https://krebsonsecurity.com/2021/03/is-your-browser-extension-a-botnet-backdoor/
     
  2. EASTER

    EASTER Registered Member

    Good article. Thanks
     
  3. wat0114

    wat0114 Registered Member

    Good article, thanks ronjor. I only use three extensions in Firefox, and they are in the "Recommended" category.
     
  4. Rasheed187

    Rasheed187 Registered Member

    Can you perhaps explain what this Infatica company exactly did? How did they use extensions for malicious purposes?
     
  5. wat0114

    wat0114 Registered Member

    From what I can gather, they pay extension authors to insert their code into the extension, so infatica customers who browse to a web site using the modified extension will look like the traffic is coming from an extension user, and not from the customer. A sort of anonymizing tool, I guess.

    In this case it's not malicious use, but because of the power that so many extensions have, a malicious author could re-code it for malicious purposes.
     
  6. Rasheed187

    Rasheed187 Registered Member

    Thanks, I still don't get it to be honest. But yes, a malicious browser extension is always a risk, it's best to limit the amount of them as much as possible. Here's an interesting article:

    https://medium.com/redmorph/malicious-browser-extensions-what-you-should-know-cb7ecb477dbc
     
  7. wat0114

    wat0114 Registered Member

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice