4 ms·
It's awesome that Mozilla detailed exactly what the exploit did, even which file paths it searched for.
by callum85 11y ago
It's awesome that Mozilla detailed exactly what the exploit did, even which file paths it searched for.
- fukusa 11y agoThe exploit basically uploaded the contents of a bunch of sensitive files to some server. Besides uploading the full list of files in the User directory (not the contents of the files) it uploaded the contents of the following files: Linux: /etc/passwd, /etc/hosts, /etc/hostname, /etc/issue, .bash_history, .mysql_history, .pgsql_history, .ssh/known_hosts, .ssh/authorized_keys, .ssh/id_sa, .remmina/.remmina, .remmina/.pref, .config/filezilla/.xml, .filezilla/.xml, pass.txt, access.txt, .sh, .config/psi+/profiles/default/accounts.xml Windows (in the User directories AppData/Roaming and Application Data): Subversion: config, servers, auth/svn.simple/* , auth/svn.simple/* .* SmartFTP: Client 2.0/Favorites/Quick Connect/* .xml Psi+: profiles/default/accounts.xml Notepad++: plugins/config/NppFTP/NppFTP.xml .purple: accounts.xml s3browser: * .xml, * .settings FileZilla: filezilla.xml, sitemanager.xml, recentservers.xml FTP Explorer: profiles.xml FTPRush: RushSite.xml FTPGetter: servers.xml FTP Now: sites.xml FTPInfo: ServerList.cfg, ServerList.xml GHISLER: wcx_ftp.ini Ipswitch: WS_FTP/Sites/ws_ftp.ini VanDyke: Config/Sessions/* .ini
- cozzyd 11y agoSounds like SELinux would have helped
- andy112 11y agoHi, I run the site https://scriptobservatory.org https://scriptobservatory.org, which scans the internet and keeps track of what JavaScript people are sent as they browse the internet. Could you drop me an email with a copy of the exploit script (OR a list of a few unique strings found in the exploit script)? With that, I can search the history of what we've been sent to get a list of all webpages that this exploit has been seen on. Email is scriptobservatory -at- gmail -dot- com or you can input it in the "Do you have a list of websites you want to be scanned regularly?" text box.
- fukusa 11y agoCool, done!
- a_cherepanov 11y agoHi. I work as malware researcher in ESET. Could you please share sample and malicious URL? email: cherepanov [at] eset [dot] sk
- fukusa 11y agoDone.
- Kadilov 11y agoHi fukusa, I know a Russian website (not a news site, it is webdev oriented) that triggers some PDF error in Firefox 35 and does not do that with latest Firefox 39.0.3. I sent a bug report to owners 6 days ago (just because PDF errors on a webpage are strange) and they have not fixed it yet. Could you check this website? I can send you an URL the way you prefer.
- fukusa 11y agoI'm not a security expert. If you have a bug report you'd better report it to Mozilla here: https://bugzilla.mozilla.org/ https://bugzilla.mozilla.org/
- Skalman 11y agoTo people helping others on the internet who claim to be security professionals, remember to make sure that the person is actually trustworthy, so you're not helping criminals. Even though a_cherepanov is a new account with only this comment, I suppose their email domain makes them trustworthy enough: ESET is a Slovakian security company that's had a Wikipedia page for 5+ years.
- andy112 11y ago