Oh Fun: 2 Firefox Add-Ons Contain Trojans

Page 2 - Seeking answers? Join the Tom's Guide community: where nearly two million members share solutions and discuss the latest tech.
Status
Not open for further replies.

rbarone69

Distinguished
Aug 16, 2006
86
0
18,580
Is it just me or did the title of the article make others think of sex and not viruses or horses filled with stinky men...
 

SininStyle

Distinguished
Dec 15, 2009
15
0
18,560
Microsoft Patching 17-year-old Windows/DOS Bug

A vulnerability found in Internet Explorer could expose your files to the Internet.

Microsoft Patches IE Flaw Used in Google Hacking
OR
Mozilla's malware scan failed to detect Trojans found in two Firefox add-ons.

 

Onus

Distinguished
Jan 27, 2006
724
0
19,210
No, you don't take "legal action" against the malware writers. You identify them, prove them guilty (need not be in court), and put them down. GAME OVER.
 

steiner666

Distinguished
Jul 30, 2008
117
0
18,630
lol who would want either of those shitty add-ons to begin with? Most ppl i know who use FF have a selected handful of add-ons which they always use/trust and only add new ones if they hear a ton of positive opinions about them and actually need the added functionality that they offer.

Anyways, this is the inherent drawback to having a program compatible with user-made add-ons, you run the risk of the creators of the add-ons being total malware asshats. Much better than IE and Chrome still though, in stability, security and usability.

I clean infected PCs every day at work and there are countless, horribly infected computers with IE or Chrome as the default browser, but the number of horribly infected computers i've cleaned with FF as the default in the past 6 months, i could probably count on one hand.

I install FF with adblock on the PCs i repair, and some ppl just refuse to switch from IE, why i have no idea, but they end up coming back in a few months. It also doesn't help matters that ppl still think that just because their PCs came with norton/mcafee installed on them that they'll actually have active (or even passive) protection against malware and such. Eset/NOD32 with spybot+teatimer (set for auto nightly updates/scans) has been the only combination of protection software that I've found to protect these customers from their own poor browsing habits (btw, malwarebytes pro has failed to detect/block numerous things that SB does). A bit of an off topic rant, but i'm waiting for this spybot scan to finish anyways lol.
 

_Cubase_

Distinguished
Jun 18, 2009
207
0
18,830
Well now that the malware targeted for Firefox is rolling in it's time people got back to doing what they should always be doing: keeping their anti-malwayre/spyware software up-to-date, instead of bitching about which browser is more secure.
 

mitch074

Distinguished
Mar 17, 2006
139
0
18,630
Well, that was bound to happen - a server is a server, and a binary file is a binary file. It is not the first time, and it won't be the last time, that a publicly accessible repository sees some undetected malware in.

Who is to blame here? Mozilla for not having used enough antivirus solutions stacked one on top of the other to scan third party additions (remember that IE doesn't list unsponsored add-ons that never get updated, don't often work and are almost never free), add-on writers for not scanning their files (it seems that in Master Filer's case at least, it was detected but the writer thought it was a false positive), or users for downloading and not scanning a piece of software they were about to use - as prompted (and forced to wait) on every Firefox add-on install?

Next, Firefox add-ons don't require system-wide install on any OS of any version (including Windows XP). Whoever was dumb enough to install them on an administrator account, thus allowing them to install their payloads?

Oh. Right. We're talking Windows users here. People that think that browsing the Web with administrator rights is pretty nifty.
 

qvnguyen

Distinguished
Jan 5, 2006
4
0
18,510
Who cares, Firefox still rocks. If you're so inept as to download these add-ons without checking them first then you deserve to get infected.

I'm not bashing Internet Explorer because I still use it from time to time for certain websites. Sh.it happens. Deal with it.
 

r3t4rd

Distinguished
Aug 13, 2009
165
0
18,630
Really people? Does it really matter what browser you use? AGAIN - no matter how much security software/hardware you have on your PC, it doesn't help the fact if you have morons infront of the PC.

That is why this is a perfect example. FF was safe until idiots installed the addons. IE was safe until idiots visited unsecure websites.
 
Status
Not open for further replies.