Author Topic: Critical hole in Firebug!  (Read 1982 times)

0 Members and 1 Guest are viewing this topic.

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33801
  • malware fighter
Critical hole in Firebug!
« on: April 05, 2007, 04:16:54 PM »
Hello malware fighters,

Users of Mozilla browsers are advised to disable the Firebug extension. It has a critical hole through which a third party could inject malicious code into the "zone" of the browser.
Read: http://www.gnucitizen.org/blog/firebug-goes-evil

We expect that when browser code itself is getting more and more secure, malcreants try to seek weak spots in browser extensions, that were not made with secure cosing at heart.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 88438
  • No support PMs thanks
Re: Critical hole in Firebug!
« Reply #1 on: April 05, 2007, 05:01:43 PM »
Amazing that they can turn the very tools to check code against us. Not that I had firebug installed.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 23.10.6086 (build 23.10.8563.800) UI 1.0.784/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33801
  • malware fighter
Re: Critical hole in Firebug!
« Reply #2 on: April 05, 2007, 08:13:23 PM »
Hi DavidR,

It is actually a tool for webdevelopers. I do not have it, and Flock has its own. The security people among the browser developers must look now for methods to protect browser users against malicious code that comes along with the new ways of interoperability. Embedded script is now doing things that were not intended by earlier coders, so there must be found new ways of securing cookies, tags, webbugs etc etc.
With the JIKTO scanner code in the wild, we're in for some new threats in the malware theatre. The Internet has become a more dangerous place than it ever was.

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!