Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 59 guests and 4 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow Mozilla Says 2 Firefox Plug-ins Contain Trojan
EH-Net
February 09, 2012, 12:28:01 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Mozilla Says 2 Firefox Plug-ins Contain Trojan  (Read 1773 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 3843


Editor-In-Chief


View Profile WWW
« on: February 09, 2010, 10:20:42 AM »

Quote

Mozilla is warning that two "experimental" plug-ins for its Firefox web browser contain malware.

Version 4.0 of the Sothink Web Video Downloader and all editions of Master Filer — both of which have since been removed from Mozilla's archive of add-ons — contain a trojan that targets Windows computers, according to a Mozilla blog post posted Friday. Users who have downloaded the add-ons are advised to uninstall them and run an anti-virus scan to clean up any infection on their PCs.

"If a user installs one of these infected add-ons, the trojan would be executed when Firefox starts and the host computer would be infected by the trojan," according to the post.

But on Monday, the maker of the Sothink add-on denied that its product contained malicious code.

"To respond to the recent negative information about Sothink Web Video Downloader for Firefox, Sothink Media announced that the latest version of this program is 100 percent clean and safe for our users," the company said in a blog post. "It has already passed the detection of the authority third party."

The company included a link to a VirusTotal analysis, which turned up zero infections when the add-on was tested against 40 commonly used anti-virus products.

Contact information for the maker of Master Filer could not be obtained.

Mozilla does look for malware on add-ons uploaded to its site. When the company realized that its current scanning engine did not detect the trojan in Master Filer, it added two more tools to its testing mechanism, which discovered the malicious Sothink add-on. No other rogue add-ons were found.

"Experimental add-ons are newer add-ons which have not yet undergone our public review process," Mozilla advised in a Firefox FAQ section on its web site. "Many of these add-ons may be in prototype form...Caution should be used when installing experimental add-ons, as they have not been tested by an editor and may harm your computer configuration."

Mozilla said the Sothink plug-in was downloaded an estimated 4,000 times from February 2008 to May 2008, while the Master Filer was installed some 600 times from September 2009 to January 2010.


Original story:
http://www.scmagazineus.com/mozilla-says-two-firefox-browser-plug-ins-contain-trojan/article/163344/

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.454 seconds with 23 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.