Security Surprises On Firefox Quantum
This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
More articles
- Beginner Hacker Tools
- Hacker Tools Online
- Hacker Tools For Windows
- Hacking Tools And Software
- Pentest Tools Alternative
- Hacker Tools For Mac
- Bluetooth Hacking Tools Kali
- Hacking Tools Github
- Pentest Tools Apk
- Hack Tools Mac
- How To Hack
- Hack Tools Download
- Pentest Tools Android
- Hacker Tools Software
- Pentest Tools Port Scanner
- Android Hack Tools Github
- Pentest Tools Open Source
- Pentest Tools Review
- Hackrf Tools
- Pentest Tools Port Scanner
- Pentest Box Tools Download
- New Hack Tools
- Tools For Hacker
- Pentest Tools Url Fuzzer
- Pentest Tools
- Termux Hacking Tools 2019
- Hacker Tools Github
- Hacking Tools For Windows 7
- Hacker Tools Github
- How To Make Hacking Tools
- Hacking Tools Hardware
- Hack Tools Pc
- Hacking Tools Hardware
- Hack Tools Online
- Hack Website Online Tool
- Pentest Tools Open Source
- Hacking Tools For Windows Free Download
- Hacker Tools List
- Easy Hack Tools
- Hak5 Tools
- Hack Tools Mac
- Pentest Tools Review
- Pentest Tools Bluekeep
- Hacking Tools Github
- Pentest Tools Url Fuzzer
- Pentest Tools Apk
- Pentest Tools For Windows
- Hack Tools For Mac
- Hacker Tools 2020
- Hacker Tools Apk Download
- Pentest Tools Website Vulnerability
- Hack Tools Github
- How To Install Pentest Tools In Ubuntu
- Pentest Tools
- Pentest Tools For Mac
- Pentest Tools Windows
- Pentest Tools Github
- Hacking Tools For Mac
- World No 1 Hacker Software
- Hacking Tools
- Hack Rom Tools
- Hacking Tools Name
- Hack Tools For Windows
- How To Install Pentest Tools In Ubuntu
- Hacker Tools Github
- Best Hacking Tools 2020
- Hacker Tools Free Download
- Hacking Tools 2020
- Pentest Tools Online
- What Is Hacking Tools
- Hacks And Tools
- Hacker Techniques Tools And Incident Handling
- Hacking Tools For Windows
- Hacking Tools Usb
- Hackers Toolbox
- Pentest Recon Tools
- Nsa Hacker Tools
- Pentest Tools Alternative
- Hacking Tools Windows 10
- Pentest Tools For Android
- Hack Tools For Windows
- Free Pentest Tools For Windows
- Hacker Tools 2020
- Usb Pentest Tools
- Hacker Tools Windows
- How To Hack
- Hacking Tools For Windows
- Hacker Tools For Mac
- Pentest Tools Framework
- Hacker Techniques Tools And Incident Handling
- Hacker Tools Free Download
- Hacker Security Tools
- Hacker Tools Online
- Pentest Tools Subdomain
- Pentest Tools Free
- Pentest Tools Online
- Hack Tools For Pc
- Usb Pentest Tools
0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home