Page 1 of 2 12 LastLast
Results 1 to 10 of 14

Thread: Firefox At Risk Due to Sneaky Microsoft Plug-In

  1. #1
    Rart's Avatar Hold The Line
    Join Date
    Jul 2009
    Posts
    3,826
    Firefox At Risk Due to Sneaky Microsoft Plug-In
    October 16, 2009

    " A secret plug-in installed by Microsoft puts Firefox users at risk of a malicious attack.

    Remember how Microsoft reacted to Google inserting Chrome into Internet Explorer? The company wasn't happy, essentially telling the search engine giant to "get out." Now it looks as if the pot is calling the kettle black, as the latest Microsoft "Patch Tuesday" reveals that the company silently slipped in a plug-in for Mozilla's Firefox browser called Windows Presentation Foundation.

    According to Computerworld, Microsoft's security engineers acknowledged the plug-in earlier this week (obviously), and said that the plug-in was pushed onto consumers through a Windows Update. Thanks to the plug-in, Firefox users were susceptible to an attack vector until it was addressed on Tuesday.

    "While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," the company said in this security blog. "The reason is that .NET Framework 3.5 SP1 installs a “Windows Presentation Foundation” plug-in in Firefox. Via this plug-in it is possible to launch XBAP (XAML Browser Application), and reach this vulnerability, from within Firefox."

    The blog describes the attack as a "browse-and-get-owned" scenario. Firefox users need only to be lured to a malicious website set up for the attack. Unfortunately, Firefox users can't simply remove the plug-in: the "Disable" and "Uninstall" buttons are grayed out on all versions of Windows save for Windows 7. "

    Source: http://www.tomsguide.com/us/Firefox-...news-4888.html Homepage: http://www.tomsguide.com

  2. News (Archive)   -   #2
    darkstate01's Avatar Poster
    Join Date
    Oct 2007
    Location
    manc
    Posts
    438
    I've just disabled it in xp sp3 firefox 3.5.3
    PAIN is just WEAKNESS leaving the body

  3. News (Archive)   -   #3
    Takoom's Avatar Poster BT Rep: +22BT Rep +22BT Rep +22BT Rep +22BT Rep +22
    Join Date
    Sep 2009
    Posts
    334
    thanks bro.

  4. News (Archive)   -   #4
    Rart's Avatar Hold The Line
    Join Date
    Jul 2009
    Posts
    3,826
    Currently, FireFox is marking the plugin for causing issues, and is disabling it by default. Good move by FF.

  5. News (Archive)   -   #5
    Firefox should atomatically prompt you to disable them, it did for me

  6. News (Archive)   -   #6
    Thanks for the heads up! I've disabled this add-on now

  7. News (Archive)   -   #7
    beansis's Avatar Pussy Liquor
    Join Date
    Jul 2009
    Location
    on the toilet
    Age
    83
    Posts
    255
    those motherfuckers . . .

    *disables plugin

  8. News (Archive)   -   #8
    megabyteme's Avatar RASPBERRY RIPPLE BT Rep: +19BT Rep +19BT Rep +19BT Rep +19
    Join Date
    Apr 2009
    Location
    Using Mrs. Nussbaum's CC#
    Posts
    17,364
    I got a notification from FF this morning. I claim damages against M$ in the amount of $200- now we can call it even on Win7. No hard feelings this time, just don't do it again, Bill!
    Quote Originally Posted by IdolEyes787 View Post
    Ghey lumberjacks, wolverines, blackflies in the summer, polar bears in the winter, that's basically Canada in a nutshell.

  9. News (Archive)   -   #9
    Poster BT Rep: +1
    Join Date
    Feb 2009
    Location
    Mumbai
    Posts
    20
    The same is done by Google and Apple. Try installing Google Earth or iTunes and you'll see new extensions added in Firefox.

  10. News (Archive)   -   #10
    kooltilldend's Avatar One n Only BT Rep: +2
    Join Date
    May 2008
    Location
    BKK
    Posts
    900
    yup just got it blocked today...good riddance!

Page 1 of 2 12 LastLast

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •