BleepingComputer.com: Sneaky Microsoft plug-in puts Firefox users at risk

Jump to content


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Sneaky Microsoft plug-in puts Firefox users at risk Mozilla Blacklists Plug-in, Microsoft Advises Complete Removal

#1 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,329
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 17 October 2009 - 01:11 PM

Quote

An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves the browser open to attack, Microsoft's security engineers acknowledged earlier this week...
This week, Microsoft did not revisit the origin of the .NET add-on, but simply told Firefox users that they should uninstall the component if they weren't able to deploy the patches provided in the MS09-054 update.


Quote

the code in that add-on has a serious code execution vulnerability that exposes Firefox users to the “browse and you’re owned” attacks that are typically used in drive-by malware downloads.


Mozilla added the addon to their default blocklist.

Sources:
http://www.computerworld.com/s/article/913...x_users_at_risk
http://blogs.zdnet.com/security/?p=4614&am...g=trunk;content
https://www.mozilla.com/en-US/blocklist/
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#2 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,490
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 17 October 2009 - 03:03 PM

To add to what AA posted:

Mozilla now has a site you can check your plugins for security updates. Just click and it is pretty darn fast.
http://www.mozilla.com/en-US/plugincheck/


And This:
To protect users who may not have installed Microsoft's patch, Mozilla is automatically blocking two add-ons: the Microsoft .Net Framework Assistant and a related plugin called the Windows Presentation Foundation. The open-source browser started blocking the software late Friday night.

"Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today to indicate that we were looking to disable the extension and plugin for all users via our blocklisting mechanism," wrote Mozilla Vice President of Engineering Mike Shaver in a blog posting. "Microsoft agreed with the plan, and we put the blocklist entry live immediately."

Buggy plugins are a growing problem, as cyber criminals have increasingly leveraged flaws in products such as Adobe Flash Player and QuickTime to launch browser-based attacks. Earlier this week, Mozilla launched a Plugin Check site where Firefox users can see if their plugins are up-to-date.

#3 User is offline   scff249 

  • Indecisive Lurker
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 1,319
  • Joined: 14-February 08
  • Gender:Male
  • Location:A galaxy far, far away...

Posted 17 October 2009 - 03:05 PM

Idiot Microsoft....were they given permission to put that plug-in into the Firefox Browser? Kinda sounds fishy to me in the fact that there was a problem with it in the first place.
"Ototo'i wa usagi o mita no...Kino wa shika...Kyo wa anata." -Kotomi Ichinose (Clannad) [see below for translation]
"Day before yesterday I saw a rabbit, and yesterday a deer, and today, you." -The Dandelion Girl
"You are not alone, and you are not strange. You are you, and everyone has damage. Be the better person." -Katawa Shoujo

#4 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,329
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 17 October 2009 - 03:23 PM

View Postscff249, on Oct 17 2009, 01:05 PM, said:

Idiot Microsoft....were they given permission to put that plug-in into the Firefox Browser? Kinda sounds fishy to me in the fact that there was a problem with it in the first place.

No. No permission is requested. It's installed automatically when you update the .Net Framework runtime.
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#5 User is offline   tug 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 61
  • Joined: 22-July 09

Posted 17 October 2009 - 05:03 PM

I wonder why it was blocked if MS patched it which they did on 14-10-09 this tuesday. Though that was a .NET patch and I seem to have WPF which I know is connected to .NET but I do not seem to have the .NET itself.

#6 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 17 October 2009 - 08:56 PM

Posted Image

#7 User is offline   Andrew 

  • Bleepin' Night Watchman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 7,329
  • Joined: 05-December 05
  • Gender:Not Telling
  • Location:Right behind you

Posted 17 October 2009 - 09:02 PM

samuel3... Windows Genuine Advantage? Really?
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Posted Image
Boredom Software Stop Highlighting Things

#8 User is offline   Romeo29 

  • Learning To Bleep
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 2,814
  • Joined: 06-July 08
  • Gender:Not Telling
  • Location:127.0.0.1

Posted 17 October 2009 - 09:47 PM

.NET framework assistant was added to blocklist a long time ago. But after updating Windows with MS hotfixes released on 14th October, Firefox warned about the WPF plugin and disabled it.

See Firefox addons blocklist : https://www.mozilla.com/en-US/blocklist/
[url="http://www.avast.com/"]avast! free antivirus[/url]

#9 User is offline   tug 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 61
  • Joined: 22-July 09

Posted 18 October 2009 - 12:02 PM

I don't have the .NET ext anymore just the WPF, I presumed .NET had changed into WPF :thumbsup: I must have been wrong but I never uninstalled it maybe its a vista thing?

#10 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 18 October 2009 - 05:19 PM

View PostAmazing Andrew, on Oct 18 2009, 03:02 AM, said:

samuel3... Windows Genuine Advantage? Really?

What about it?

I don't even know what it is lol.

Explain please.

EDIT: If i can no longer use it and its no use - How do i remove it?

This post has been edited by samuel3: 18 October 2009 - 05:22 PM


#11 User is offline   buddy215 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 4,490
  • Joined: 14-April 06
  • Gender:Male
  • Location:West Tennessee

Posted 18 October 2009 - 08:52 PM


#12 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 19 October 2009 - 10:27 AM

Ok.. thanks what was it anyway?

And how do i delete the disabled ones in there that are greyed out? I don't need them anymore?

#13 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 22 October 2009 - 05:52 PM

Bumping. Anyone know from my question above?

Bumping.

This post has been edited by Amazing Andrew: 24 October 2009 - 07:03 PM
Reason for edit: Mod Edit: Merged, please don't bump; you'll get more responses if you post in one of the help forums


#14 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 25 October 2009 - 05:37 PM

Dam, anyone???

#15 User is offline   samuel3 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 2,217
  • Joined: 13-June 08
  • Gender:Male

Posted 26 October 2009 - 09:02 AM

Quote

samuel3... Windows Genuine Advantage? Really?


What about it?


Explain please.

This post has been edited by samuel3: 26 October 2009 - 09:04 AM


Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users