Web Search

Custom Search

Search Results

Monday, April 13, 2020

Security Surprises On Firefox Quantum

This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser  was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.

This means two things

1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.


Ubuntu Version:


Firefox Quantum version:



The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip




The zip contains these two files:
  3f201a8984d6d765bc81966842294611  libgmpopenh264.so
  44aef3cd6b755fa5f6968725b67fd3b8  gmpopenh264.info

The info file:
  Name: gmpopenh264
  Description: GMP Plugin for OpenH264.
  Version: 1.6.0
  APIs: encode-video[h264], decode-video[h264]

So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.

In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.




Continue reading
  1. Hacker Tools For Mac
  2. Hacker Tools Free Download
  3. Tools For Hacker
  4. Pentest Reporting Tools
  5. Pentest Tools Download
  6. Hacker Tools Free Download
  7. Hacker Techniques Tools And Incident Handling
  8. Hacker Security Tools
  9. Underground Hacker Sites
  10. Pentest Tools Subdomain
  11. Hacker Hardware Tools
  12. Hack Tools For Ubuntu
  13. Blackhat Hacker Tools
  14. Hack Tools Github
  15. Pentest Box Tools Download
  16. Usb Pentest Tools
  17. Hacking App
  18. Hacking Tools Online
  19. Usb Pentest Tools
  20. Pentest Tools Download
  21. Hacker Tools
  22. Hack Tools
  23. Hack Apps
  24. Hacker Tool Kit
  25. Pentest Tools Free

No comments: