Security Surprises On Firefox Quantum
This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
Related word
- Game Hacking
- What Is Hacking Tools
- Pentest Tools For Windows
- Hacker Tools Hardware
- Pentest Tools Linux
- Pentest Tools Download
- Hack Apps
- Hacker Tools 2020
- Hacking Tools For Windows 7
- Hack Tools Github
- Hackrf Tools
- Pentest Tools
- Pentest Tools Kali Linux
- Pentest Automation Tools
- Pentest Tools Find Subdomains
- Nsa Hack Tools
- Hacker Techniques Tools And Incident Handling
- How To Install Pentest Tools In Ubuntu
- Pentest Tools For Windows
- Hacking Tools Pc
- Tools For Hacker
- Hackrf Tools
- How To Hack
- Hacker Techniques Tools And Incident Handling
- Usb Pentest Tools
- Hacker Tools For Pc
- Hacker Search Tools
- Hacking Tools Hardware
- Pentest Tools Download
- Nsa Hack Tools Download
- Usb Pentest Tools
- Hacking Tools Download
- Hack Tools For Windows
- Termux Hacking Tools 2019
- Hack Tools For Pc
- Hacking Tools Software
- Hack Website Online Tool
- Top Pentest Tools
- What Is Hacking Tools
- Pentest Tools Nmap
- Pentest Automation Tools
- Hack Tools Github
- How To Install Pentest Tools In Ubuntu
- Hak5 Tools
- New Hack Tools
- Hacker Tools Apk Download
- Hacker Tools Apk Download
- Hacker Tools For Pc
- Hacking Tools Usb
- Kik Hack Tools
- Pentest Recon Tools
- Game Hacking
- Hack Tools For Ubuntu
- Pentest Tools Apk
- Best Hacking Tools 2020
- Hak5 Tools
- Pentest Tools Website
- Pentest Tools Url Fuzzer
- Hacking App
- Hacker Tools 2019
- Pentest Tools For Mac
- Hacker
- Hack Tools
- Hacks And Tools
- Pentest Tools Tcp Port Scanner
- Hack Tools Online
- How To Make Hacking Tools
- Termux Hacking Tools 2019
- Pentest Automation Tools
- Pentest Tools Download
- Nsa Hacker Tools
- Best Hacking Tools 2019
- Hacking Tools Download
- Pentest Tools Android
- Pentest Tools Port Scanner
- Hack Tools
0 Comments:
Publicar un comentario
<< Home