The Register® — Biting the hand that feeds IT

Feeds

Insecure plug-ins pose danger to Firefox users

Add-ons add security threat

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

A security weakness in the update mechanism for third-party add-ons to the Firefox browser could give an attacker the ability to exploit unsecured downloads and install malicious code on the victim's computer, a security researcher warned on Wednesday.

The vulnerability affects any third-party add-ons that use an unsecured download site as part of the update process, according to Indiana University graduate student Christopher Soghoian, who released an advisory on the issue Wednesday.

While using the standard secure communications protocol available in major browsers, known as secure sockets layer (SSL) encryption, could prevent the attacks, many major companies - such as Google, Yahoo!, Facebook, LinkedIn, and AOL - failed to do so, Soghoian said.

"Many companies have world-class in-house security teams, so their worst sin is not consulting their own experts, who would have undoubtedly shot down any attempt to update code over an insecure and untrustworthy connection," Soghoian said in an email interview with SecurityFocus.

Soghoian, who attracted the attention of the US Department of Homeland Security last year when he created an online boarding-pass generator, posted an advisory and video of the attack to his website on Wednesday, a month and a half after notifying Mozilla and Google of the issue.

Vulnerability researchers have increasingly targeted Firefox as the open-source browser's popularity has grown. The group improved the browser's security with its latest version, Firefox 2.0, released last October. Both Microsoft and Mozilla have argued that their own browser protects internet users better.

In April, Soghoian decided to use a network sniffer to capture the data that Firefox sent out over the network as it was starting up. He quickly noticed that several extensions sent requests to check for new updates using plain Hypertext Transfer Protocol (HTTP) packets, without any sort of security.

"The insecure update requests stuck out like a sore thumb, and within a couple of hours, I had a working demo which proved that it was possible to hijack the extension upgrade process," Soghoian said.

Agentless Backup is Not a Myth

Latest Comments
Anonymous Coward

"Insecure" plugins - what next, paranoid add-ons?

As soon as I saw the headline, I had an image of all these video players and PDF viewers huddled in the corner, convinced that they were not any good and that the rest of the applications were laughing at them!

I think "un-secure" would be the correct terminology!

0
0

Plug-ins

You mean plug-ins like the one I use to block all the adverts and distractions from this site?

0
0
Anonymous Coward

Stup1d M1cro$oft

can't write a secure browser LOLOLOL!!!1!!1!1 They should just use Firefox instead 'cos it's OSS and written by proper haxxors not M$ luser programmers and many eyes make all bugs shallow and...

oh...

I'll get me coat then.

0
0

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats