Security Surprises On Firefox Quantum
This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
More information
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
More information
- Tools 4 Hack
- Nsa Hacker Tools
- Pentest Tools Tcp Port Scanner
- World No 1 Hacker Software
- Nsa Hacker Tools
- Termux Hacking Tools 2019
- Hacker Tools Windows
- Best Hacking Tools 2020
- Hacker Tools List
- Hacking Tools For Kali Linux
- Hacking Tools For Kali Linux
- How To Make Hacking Tools
- Hacking Tools For Games
- Hacking Tools Windows 10
- Hacker Hardware Tools
- Pentest Tools Open Source
- Hackrf Tools
- Hack Tool Apk
- Hacking Apps
- Free Pentest Tools For Windows
- Nsa Hack Tools Download
- Hacking Tools Online
- Hacking Tools For Games
- How To Make Hacking Tools
- Pentest Tools For Ubuntu
- Hack And Tools
- Hack Tools Download
- Android Hack Tools Github
- Hacker Security Tools
- Hacker Tools For Windows
- What Is Hacking Tools
- Hacker Tools Online
- Hacker Tools For Windows
- Hacking Tools 2020
- Kik Hack Tools
- Hack Tools 2019
- Hacker Tools 2019
- Pentest Tools Find Subdomains
- Pentest Reporting Tools
- Hacking Tools Software
- How To Make Hacking Tools
- Hack Tools Download
- Tools 4 Hack
- Hacker Tools For Mac
- Hak5 Tools
- Hacker
- Hack Tools For Windows
- Pentest Tools Nmap
- Pentest Tools For Windows
- Hack Tools Download
- Hacking Tools Free Download
- Pentest Tools Open Source
- Tools For Hacker
- Pentest Tools Kali Linux
- Hacker Search Tools
- Pentest Tools For Android
- Hacker Tools Software
- Blackhat Hacker Tools
- Hacking Tools For Pc
- Hacks And Tools
- Hack And Tools
- Hacking Tools Kit
- Pentest Tools Kali Linux
- Hacking Tools And Software
- New Hack Tools
- Pentest Tools Alternative
- Hacking Tools Name
- Hacking Tools
- Hacker Hardware Tools
- What Is Hacking Tools
- Hackers Toolbox
- Hacker Tools Github
- Underground Hacker Sites
- Pentest Tools Website
- Hacker Tool Kit
- Hacking Tools Name
- Hacking Tools Download
- Easy Hack Tools
- Hack Tool Apk
- Easy Hack Tools
- Pentest Automation Tools
- Hack Tools For Mac
- Hacker Tools Apk
- Pentest Tools Kali Linux
- Beginner Hacker Tools
- Hacking Tools For Kali Linux
- Hacker Tools
- Best Hacking Tools 2019
- Pentest Tools For Android
- Hacker
- Hacker Tools Software
- Hacking Tools For Windows Free Download
- Hackrf Tools
- Pentest Tools Url Fuzzer
- Pentest Tools
- Hacker Tools Online
- Underground Hacker Sites
- Pentest Reporting Tools
- Hack Apps
- Hackers Toolbox
- Usb Pentest Tools
- Hacker Tools Hardware
- Hackrf Tools
- Hacker Tools 2020
- Hack Tools
- New Hack Tools
- Pentest Tools For Ubuntu
- Hack Tools Online
- Pentest Tools For Ubuntu
- Hacker Tools Github
- World No 1 Hacker Software
- Hacker Tools Apk
- Hacker Tools Linux
- Underground Hacker Sites
- Pentest Tools List
- Pentest Tools Github
- Blackhat Hacker Tools
- Hacker Tools
- Hackrf Tools
- Hacking Tools Hardware
- Hacking Tools For Kali Linux
Comments
Post a Comment