Security Surprises On Firefox Quantum
This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
Related word
- Hack Apps
- Hacking Tools For Windows
- Hackrf Tools
- Hack Tools Pc
- Hacker Tool Kit
- Black Hat Hacker Tools
- Ethical Hacker Tools
- Hacker Hardware Tools
- Hacking Tools For Games
- Hacking Tools Windows 10
- Tools Used For Hacking
- Hacker Tools For Ios
- Hacking Tools And Software
- Hacking Tools Hardware
- Pentest Tools Port Scanner
- Pentest Tools List
- Hackers Toolbox
- Hacker Search Tools
- Pentest Recon Tools
- Pentest Tools For Android
- Hack Apps
- Hacking Tools For Mac
- Hacker Security Tools
- Pentest Tools Tcp Port Scanner
- Nsa Hacker Tools
- Blackhat Hacker Tools
- Tools For Hacker
- Hack Tools Pc
- Hacking Tools For Beginners
- Hacker Tools Hardware
- Pentest Tools List
- Hacking Tools Pc
- Pentest Automation Tools
- Pentest Tools Url Fuzzer
- Hacker Tools Software
- Hacker Hardware Tools
- Nsa Hacker Tools
- Hacking Tools Software
- Hack Tools Github
- Hack Tools For Games
- Hacker Tools Free Download
- Hacks And Tools
- Pentest Tools For Mac
- Hacking Tools Kit
- Hack Tools For Ubuntu
- Hacking Tools And Software
- Pentest Tools Website
- How To Install Pentest Tools In Ubuntu
- Free Pentest Tools For Windows
- Blackhat Hacker Tools
- Hacking Tools For Mac
- Hacking Tools Free Download
- Hacker Techniques Tools And Incident Handling
- Hacking Tools Pc
- Underground Hacker Sites
- Hack Tools
- How To Hack
- Hacking Tools Hardware
- Pentest Tools Nmap
- Hacker Tool Kit
- Hacking Tools Hardware
- Hacking Tools Pc
- Best Hacking Tools 2019
- Hacker Tools Windows
- Hacking Tools For Windows 7
- Hackers Toolbox
- What Is Hacking Tools
- Hacker Tools For Windows
- Github Hacking Tools
- Pentest Tools Online
- Hacker Tools Windows
- Hacking Tools For Windows 7
- Hacking Tools For Windows Free Download
- Hacker Security Tools
- Hacking Tools 2019
- Hacker Tools Apk Download
- Pentest Tools List
- Pentest Tools Alternative
- Hacking Tools For Kali Linux
- Hacking Tools Windows 10
- Hacker Tools Hardware
- Hacking Tools
- Hak5 Tools
- Hacker Tools Free Download
- Hacker Tools Windows
- Hack Tools Download
- Hacker Tools Free
- Hacker Tool Kit
- Best Hacking Tools 2020
- Nsa Hack Tools Download
- Pentest Tools Windows
- Pentest Tools Android
- Hacking Tools Mac
- Pentest Tools Bluekeep
- Game Hacking
- Pentest Tools Framework
- Pentest Tools For Android
- Hacker Tool Kit
- New Hack Tools
- Hacking Tools For Beginners
- Hacker Tools
- Hacker Tools For Windows
- Hacking Tools Download
- Hack Tools For Games
- Hacking Tools For Mac
- Hacker Tools Windows




Yorumlar