Follow Us On Follow us on Facebook Follow us on Twitter Watch us on YouTube
Register
Page 1 of 2 12 LastLast
Results 1 to 10 of 11

Sneaky Microsoft plug-in puts Firefox users at risk

This is a discussion on Sneaky Microsoft plug-in puts Firefox users at risk within the Security Watch forums, part of the Security & Safety category; Computerworld: An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves the browser open to attack, Microsoft's security ...

  1. #1
    ferguj1's Avatar
    Super Moderator

    Status
    Offline
    Join Date
    Apr 2009
    Location
    The Great Beyond
    Age
    33
    Posts
    4,675
    Rep Power
    282

    Default Sneaky Microsoft plug-in puts Firefox users at risk

    Computerworld: An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves the browser open to attack, Microsoft's security engineers acknowledged earlier this week.

    One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made plug-in pushed to Firefox users eight months ago in an update delivered via Windows Update.

    "While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," admitted Microsoft engineers in a post to the company's Security Research & Defense blog on Tuesday. "The reason is that .NET Framework 3.5 SP1 installs a 'Windows Presentation Foundation' plug-in in Firefox."

    The Microsoft engineers described the possible threat as a "browse-and-get-owned" situation that only requires attackers to lure Firefox users to a rigged Web site.

    Numerous users and experts complained when Microsoft pushed the .NET Framework 3.5 Service Pack 1 (SP1) update to users last February, including Susan Bradley, a contributor to the popular Windows Secrets newsletter.

    "The .NET Framework Assistant [the name of the add-on slipped into Firefox] that results can be installed inside Firefox without your approval," Bradley noted in a Feb. 12 story. "Although it was first installed with Microsoft's Visual Studio development program, I've seen this .NET component added to Firefox as part of the .NET Family patch."

    What was particularly galling to users was that once installed, the .NET add-on was virtually impossible to remove from Firefox. The usual "Disable" and "Uninstall" buttons in Firefox's add-on list were grayed out on all versions of Windows except Windows 7, leaving most users no alternative other than to root through the Windows registry, a potentially dangerous chore, since a misstep could cripple the PC. Several sites posted complicated directions on how to scrub the .NET add-on from Firefox, including Annoyances.org.

    Annoyances also said the threat to Firefox users is serious. "This update adds to Firefox one of the most dangerous vulnerabilities present in all versions of Internet Explorer: the ability for Web sites to easily and quietly install software on your PC," said the hints and tips site. "Since this design flaw is one of the reasons [why] you may have originally chosen to abandon IE in favor of a safer browser like Firefox, you may wish to remove this extension with all due haste."

    Specifically, the.NET plug-in switched on a Microsoft technology dubbed ClickOnce, which lets .NET apps automatically download and run inside other browsers.

    Microsoft reacted to criticism about the method it used to install the Firefox add-on by issuing another update in early May that made it possible to uninstall or disable the .NET Framework Assistant. It did not, however, apologize to Firefox users for slipping the add-on into their browsers without their explicit permission -- as generally the procedure for Firefox add-ons or extensions.

    This week, Microsoft did not revisit the origin of the .NET add-on, but simply told Firefox users that they should uninstall the component if they weren't able to deploy the patches provided in the MS09-054 update.

    According to Microsoft, the vulnerability is "critical," and also can be exploited against users running any version of IE, including IE8.

    "Woe to those who are wise in their own eyes and clever in their own sight"

    "Only a fool is never afraid, but never let fear make the decisions for you. Do right, and risk the consequences"


    The Rules: Read and Prosper

    Forum Feedback/Suggestions

  2. Thanks anto1969, wheelo, hadmad, allybird58 thanked for this post

    • Advertising

      advertising
      Techkings.org
      has no influence
      on advertisings
      that are displayed by
      Google Adsense


        
       

  3. #2
    Gman496's Avatar
    Super Moderator

    Status
    Online
    Join Date
    Apr 2009
    Posts
    6,277
    Rep Power
    390

    Default

    Firefox have implemented an automatic notification regarding the culprit ad-don's, so you should be prompted to disable them (if installed)


    -
    HelplineDirect:

    Dropbox: Store, Share and Sync files online and Sync between your computers and mobile devices.

    Get your FREE Dropbox Account:

    A Minute for Madeleine - Please View our message


  4. Thanks wheelo, dan-ger-ous, hadmad, allybird58 thanked for this post
  5. #3
    dan-ger-ous's Avatar
    Gym Freak

    Status
    Offline
    Join Date
    Apr 2009
    Location
    C:\windows\dan-ger-ous
    Posts
    5,749
    Rep Power
    347

    Default

    I noticed this too, and have it disabled.

  6. #4
    hadmad's Avatar
    VIP Member

    Status
    Offline
    Join Date
    Apr 2009
    Location
    dublin
    Age
    47
    Posts
    10,426
    Rep Power
    534

    Default

    i never had it installed

  7. #5
    wheelo's Avatar
    Wii Addict/Tech junkie

    Status
    Offline
    Join Date
    Jun 2009
    Location
    Dublin
    Age
    41
    Posts
    9,046
    Rep Power
    489

    Default

    does the fact that i didn't recieve notification mean that i am ok?

  8. #6
    Gman496's Avatar
    Super Moderator

    Status
    Online
    Join Date
    Apr 2009
    Posts
    6,277
    Rep Power
    390

    Default

    Quote Originally Posted by wheelo View Post
    does the fact that i didn't recieve notification mean that i am ok?
    I would imagine so wheelo.

    You can check by going to
    Tool
    Add-ons

    And look for "Microsoft .NET Framework Assistant 1.1"

    If it's not there you are fine

    If it's there but Disabled you are fine

    If it's there but not Disabled, you should disable it.

    -
    HelplineDirect:

    Dropbox: Store, Share and Sync files online and Sync between your computers and mobile devices.

    Get your FREE Dropbox Account:

    A Minute for Madeleine - Please View our message


  9. Thanks wheelo thanked for this post
  10. #7
    wheelo's Avatar
    Wii Addict/Tech junkie

    Status
    Offline
    Join Date
    Jun 2009
    Location
    Dublin
    Age
    41
    Posts
    9,046
    Rep Power
    489

    Default

    just did that G, it says disabled for your protection, so i am ok?, it also gives me the uninstall option, should i do this?

  11. #8
    Gman496's Avatar
    Super Moderator

    Status
    Online
    Join Date
    Apr 2009
    Posts
    6,277
    Rep Power
    390

    Default

    Quote Originally Posted by wheelo View Post
    just did that G, it says disabled for your protection, so i am ok?, it also gives me the uninstall option, should i do this?
    Eitherway you are OK wheelo as disabled means it can't function.

    If you want to remove it totally you can do so safely but it might try to install again if it sees it's not there.

    -
    HelplineDirect:

    Dropbox: Store, Share and Sync files online and Sync between your computers and mobile devices.

    Get your FREE Dropbox Account:

    A Minute for Madeleine - Please View our message


  12. Thanks wheelo thanked for this post
  13. #9
    anto1969's Avatar
    Super Moderator

    Status
    Offline
    Join Date
    Apr 2009
    Location
    Everywhere
    Posts
    8,193
    Rep Power
    462

    Default

    I had it and it was disabled but am after uninstalling it, if it does reinstall will it be disabled again

    Forum Rules

    ~The wings of angels are often found on the backs of the least likely people.~




  14. #10
    Gman496's Avatar
    Super Moderator

    Status
    Online
    Join Date
    Apr 2009
    Posts
    6,277
    Rep Power
    390

    Default

    Quote Originally Posted by anto1969 View Post
    I had it and it was disabled but am after uninstalling it, if it does reinstall will it be disabled again
    It may do it automatically Anto but in the worst case scenario it will prompt you to disable it. Just keep an eye on it

    -
    HelplineDirect:

    Dropbox: Store, Share and Sync files online and Sync between your computers and mobile devices.

    Get your FREE Dropbox Account:

    A Minute for Madeleine - Please View our message


  15. Thanks anto1969 thanked for this post
 

 
Page 1 of 2 12 LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •