3 ms·
"Firefox forces you to download an executable and then manually run it, so a user would be conscious that he or she is installing a program." Unfortunately not
by bd 17y ago
"Firefox forces you to download an executable and then manually run it, so a user would be conscious that he or she is installing a program."
Unfortunately not. I already encountered malware specifically targeted to Firefox that was fully automatic.
It used some Mozilla specific JS hooks to launch Acrobat plugin. This in turn loaded tiny infected PDF that exploited some Acrobat security hole which allowed to directly execute code on your machine.
It was enough to visit a compromised website, no further user action required. All was happening automatically, practically invisible to the user. I only noticed it because Acrobat plugin is a massive resource hog, so I managed to kill it in time before it could execute a payload.
- ars 17y agoWhat you wrote is not a firefox attack, it's acrobat attack. You don't need Mozilla specific JS hooks to launch an Acrobat plugin - I don't even think there is such a thing. Acrobat plugin opens automatically if you embed a pdf.
- bd 17y agoI don't remember details, it happened already some time ago. It was actually quite sophisticated malware - heavily obfuscated, assembling itself from pieces spread all around the world, jumping through several hoops of compromised servers. When I finally managed to reverse engineer to JS code that carried the infection, it was full of functions I didn't even know existed. Not usual JS, more like API hooks to the underlying platform, with special prefixed names. These names indicated it was about plugins. BTW it was multiplatform, attacking not just Firefox, there was a browser detection and browser specific code paths for several popular browser. I remember there was also something trying to use Silverlight. Oh, and it was multipurpose. Besides trying to infect your PC with a malware, it was also earning money. Some parts of JS were loading ads in invisible frames, presumably to be part of some distributed click farm.