Spyware Takes Aim At Mozilla Browsers

MonsieurEvilMonsieurEvil Join Date: 2002-01-22 Member: 4Members, Retired Developer, NS1 Playtester, Contributor
<a href='http://news.com.com/Spyware+takes+aim+at+Mozilla+browsers/2100-7349_3-5569635.html?part=rss&tag=5569635&subj=news.7349.5' target='_blank'>http://news.com.com/Spyware+takes+aim+at+M...ubj=news.7349.5</a>

<!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->Security experts are advising that spyware that targets browsers from the Mozilla Foundation has been spotted--a threat that could worsen as its Firefox browser takes market share from Microsoft.

Stu Sjouwerman, the founder of Sunbelt Software, said on Tuesday that the anti-spyware company has discovered what it believes is the first spyware to take aim at surfers using Mozilla browsers.

Richard Stiennon, vice president of threat research at Webroot Software, which also develops anti-spyware tools, said that the malicious software does not target Firefox specifically.

"According to my research team, this site does not target Firefox, but it does target Mozilla," Stiennon said. "(It's) only a matter of time now until a Firefox spy is discovered."

Although the spyware is only installed if users agree to download a certain file, many users are likely to click through, as the download's dialogue box gives no indication of the file's malicious payload, Sjouwerman said.

"It's done in a way that people might not recognize as a normal install, and will work in Firefox," Sjouwerman said. "It's not a full-fledged spyware attack yet, but it definitely shows where it's going."

Experts believe that Mozilla-based browsers such as Firefox have become a greater target for spyware as their market share has rapidly increased over the last six months--from 2.4 percent in May to 7.4 percent in November, according to Web traffic measurement company OneStat.com. Firefox has said that it is aiming for 10 percent of Web surfers by the end of 2005.

Writers of viruses and spyware for browsers have typically concentrated on Internet Explorer, because of its near-total market dominance. But that could be changing now that Firefox is making gains at the expense of Microsoft's browser.

Sjouwerman said that "stealth spyware" targeted at Firefox is "bound to happen" as hackers are currently working hard trying to find security holes in the open-source browser. "There's a small army of rogue programmers that are tearing Firefox apart," he said.

But Graham Cluley, a senior technology consultant at security company Sophos, said he is not sure what type of spyware will target Firefox.

"It's hard to predict precisely what form spyware for Firefox may take, as it will depend in part on what security flaws may be found in the Firefox code in the future, and how quickly the community responds to patch those vulnerabilities," Cluley said.

David McGuinness, a Mozilla contributor, said Firefox protects PC users by displaying a yellow information bar if a site that is not Update.mozilla.org tries to automatically install code. But he warned that it will be more difficult to protect systems against a stealth install.

"It all boils down to user education. People can install applications with variable amounts of effort from all browsers. It's the stealth attacks that are the problem, where people get infected without running anything themselves," McGuinness said.

Ingrid Marson of ZDNet UK reported from London.

<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->

As always, downloading strange files is bad, no matter what your browser. BAD I SAY!!!

Comments

  • EpidemicEpidemic Dark Force Gorge Join Date: 2003-06-29 Member: 17781Members
    Heh, funny it should come from you <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • AlignAlign Remain Calm Join Date: 2002-11-02 Member: 5216Forum Moderators, Constellation
    Not surprised. But it's still less than the default browser gets, so...

    Plus I like my plugins!
  • lolfighterlolfighter Snark, Dire Join Date: 2003-04-20 Member: 15693Members
    Can't say I didn't see this one coming. Still, gotta agree with Align: FF is probably still the safer bet. Total safety is an illusion anyway.
  • ThansalThansal The New Scum Join Date: 2002-08-22 Member: 1215Members, Constellation
    w00t

    all you ff fanboys can look at this as a GOOD thing.

    it showes that FF/Moz have finaly become real contenders!


    <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo--> (yes I use FF)

    I wonder if the msoft spyware thing will fight these (MonsE?)
  • MonsieurEvilMonsieurEvil Join Date: 2002-01-22 Member: 4Members, Retired Developer, NS1 Playtester, Contributor
    Should, if the spyware is reported and added to the database. If it's full-blown spyware, it's installed binaries on the system. The browser is just the delivery mechanism.
  • TychoCelchuuuTychoCelchuuu Anememone Join Date: 2002-03-23 Member: 345Members
    Yeah, you know what MS Spyware doesn't fight? That worm someone wrote that deletes the entire MS Anti Spyware folder. It's true!
  • SkulkBaitSkulkBait Join Date: 2003-02-11 Member: 13423Members
    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin-->As always, downloading strange files is bad, no matter what your browser. BAD I SAY!!!<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    Damn straight.

    <!--QuoteBegin--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> </td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Yeah, you know what MS Spyware doesn't fight? That worm someone wrote that deletes the entire MS Anti Spyware folder. It's true!<!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    If Im not mistaken, thats actually a tojan. Which means that a user would have to be terminally stupid to get infected with it. Not running strange programs you get in your e-mail is just one of those "duh!" security measures.
  • PetcoPetco Join Date: 2003-07-27 Member: 18478Members, Constellation
    Yep, as more people use firefox, people think, "Hey I heard more and more people are using firefox now, lets start making spyware and stuff for firefox users <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile-fix.gif' border='0' style='vertical-align:middle' alt='smile-fix.gif' /><!--endemo-->".
  • ZaggyZaggy NullPointerException The Netherlands Join Date: 2003-12-10 Member: 24214Forum Moderators, NS2 Playtester, Reinforced - Onos, Subnautica Playtester
    Would running in a User account instead of an Administrator account stop it all?
  • Invader_ScootInvader_Scoot Join Date: 2003-10-13 Member: 21669Members, Constellation, Reinforced - Shadow
    <!--QuoteBegin-Petco+Feb 12 2005, 01:06 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Petco @ Feb 12 2005, 01:06 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Yep, as more people use firefox, people think, "Hey I heard more and more people are using firefox now, lets start making spyware and stuff for firefox users <!--emo&:)--><img src='http://www.unknownworlds.com/forums/html/emoticons/smile-fix.gif' border='0' style='vertical-align:middle' alt='smile-fix.gif' /><!--endemo-->". <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    But still, only like 5% of the people out there right now use FireFox, and Internet Explorer still has the largest user base by an enormous jump. I don't think you should be worried about Spyware for FireFox as of yet.
  • TommyVercettiTommyVercetti Join Date: 2003-02-10 Member: 13390Members, Constellation, Reinforced - Shadow
    If you run Windows, you have spyware. It's a fact of life.
  • DragonMechDragonMech Join Date: 2003-09-19 Member: 21023Members, Constellation, Reinforced - Shadow
    <!--QuoteBegin-Zaggy+Feb 12 2005, 02:14 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Zaggy @ Feb 12 2005, 02:14 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Would running in a User account instead of an Administrator account stop it all? <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    If the user can't install software, then it could help against <i>some</i> spyware, methinks. Especially the kind that is packaged with other legitimate software and only mentioned in the EULA.
  • SkySky Join Date: 2004-04-23 Member: 28131Members
    Who wants to bet that the guy who made this spyware for mozilla is a disgruntled IE user who's tired of hearing how much safer firefox is? <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • MonsieurEvilMonsieurEvil Join Date: 2002-01-22 Member: 4Members, Retired Developer, NS1 Playtester, Contributor
    <!--QuoteBegin-TommyVercetti+Feb 12 2005, 12:32 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ Feb 12 2005, 12:32 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you run Windows, you have spyware. It's a fact of life. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    I run Windows, and I do not have spyware. Interesting...
  • Seph_KimaraSeph_Kimara Join Date: 2003-08-10 Member: 19359Members
    Most i ever get are tracking cookies. Which really aren't too huge a deal to get rid of.
  • SkulkBaitSkulkBait Join Date: 2003-02-11 Member: 13423Members
    <!--QuoteBegin-MonsieurEvil+Feb 12 2005, 02:27 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (MonsieurEvil @ Feb 12 2005, 02:27 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-TommyVercetti+Feb 12 2005, 12:32 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ Feb 12 2005, 12:32 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you run Windows, you have spyware. It's a fact of life. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I run Windows, and I do not have spyware. Interesting... <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Same here, and I have nowhere near the leet windoze skillz MonsE has
  • ThansalThansal The New Scum Join Date: 2002-08-22 Member: 1215Members, Constellation
    <!--QuoteBegin-MonsieurEvil+Feb 12 2005, 02:27 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (MonsieurEvil @ Feb 12 2005, 02:27 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-TommyVercetti+Feb 12 2005, 12:32 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ Feb 12 2005, 12:32 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you run Windows, you have spyware. It's a fact of life. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I run Windows, and I do not have spyware. Interesting... <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    well yah, but don't they give you the special non broken version of windows for working for them?


    (<!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->)

    and yah, a lettle bit of intelegence and you don't get spy ware (or virii)

    After installing the MSoft spyware killer I havn't gotten anytihng (doubl checks with adaware and S&D)
  • BlackMageBlackMage [citation needed] Join Date: 2003-06-18 Member: 17474Members, Constellation
    edited February 2005
    <!--QuoteBegin-MonsieurEvil+Feb 12 2005, 02:27 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (MonsieurEvil @ Feb 12 2005, 02:27 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-TommyVercetti+Feb 12 2005, 12:32 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ Feb 12 2005, 12:32 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you run Windows, you have spyware. It's a fact of life. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I run Windows, and I do not have spyware. Interesting... <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    that's because it's scared of you

    ps: GET TEH DEE ENN ESS MOVED OGMWTHJ00NUBZ ^^ (i kid ... do you know what's up with it? it seems that the SOA/NS records are all right but it's not resolving right ... meh, i'll check my end again)

    edit: microsoft antispy works. it gets mage approval.
  • DefianceDefiance Join Date: 2003-12-01 Member: 23847Members
    <!--QuoteBegin-MonsieurEvil+Feb 12 2005, 11:27 AM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (MonsieurEvil @ Feb 12 2005, 11:27 AM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> <!--QuoteBegin-TommyVercetti+Feb 12 2005, 12:32 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (TommyVercetti @ Feb 12 2005, 12:32 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> If you run Windows, you have spyware. It's a fact of life. <!--QuoteEnd--></td></tr></table><div class='postcolor'><!--QuoteEEnd-->
    I run Windows, and I do not have spyware. Interesting... <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Same, I haven't had a virus in nearly 2 years, and as for spyware, just tracking cookies Ad-Aware finds, and this "DXO" Exploit SpyBot finds. They don't seem to be doing anything harmful.

    I got rid of FireFox anyway, I got sick of all my webpages loading really slow.
  • DragonMechDragonMech Join Date: 2003-09-19 Member: 21023Members, Constellation, Reinforced - Shadow
    <!--QuoteBegin-Defiance+Feb 12 2005, 10:02 PM--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td><b>QUOTE</b> (Defiance @ Feb 12 2005, 10:02 PM)</td></tr><tr><td id='QUOTE'><!--QuoteEBegin--> Same, I haven't had a virus in nearly 2 years, and as for spyware, just tracking cookies Ad-Aware finds, and this "DXO" Exploit SpyBot finds. They don't seem to be doing anything harmful.

    I got rid of FireFox anyway, I got sick of all my webpages loading really slow. <!--QuoteEnd--> </td></tr></table><div class='postcolor'> <!--QuoteEEnd-->
    Just FYI - the DXO exploit is a bug with SS&D - there is nothing to be worried about. ^_^
  • BobTheJanitorBobTheJanitor Join Date: 2003-12-10 Member: 24228Members, NS1 Playtester
    I still have yet to see how spyware could get installed with ff, barring complete idiocy. You'd have to do it as an extension, and there are so many built in barriers to accidentally installing an extension that you'd really have to want to install it for it to work. It's not like other browser security holes that I won't name but which start with 'active' and end with 'x'. <!--emo&:p--><img src='http://www.unknownworlds.com/forums/html/emoticons/tounge.gif' border='0' style='vertical-align:middle' alt='tounge.gif' /><!--endemo-->
  • Seph_KimaraSeph_Kimara Join Date: 2003-08-10 Member: 19359Members
    edited February 2005
    ...Wasn't there already an XPI "spyware" extension one floating aboutmany a month ago? (which was likely the cause for so much security when installing plugins...you know, needing to tell the browser the source site is safe before you can even think of getting the plugin install prompt which has the 2 second delay to stop people clicking yes instantly)
  • lolfighterlolfighter Snark, Dire Join Date: 2003-04-20 Member: 15693Members
    90% of all spyware comes from excessive-compulsive yes-button-clicking. If you have spyware, you have most likely clicked yes-buttons. <span style='font-size:7pt;line-height:100%'>And surfed pr0n sites...</span>

    Yes, I made that stat up on the spot.
  • VenmochVenmoch Join Date: 2002-08-07 Member: 1093Members
    Man! The MS Spyware utility rocks!

    I like Microsoft even more now <!--emo&:D--><img src='http://www.unknownworlds.com/forums/html/emoticons/biggrin-fix.gif' border='0' style='vertical-align:middle' alt='biggrin-fix.gif' /><!--endemo-->
Sign In or Register to comment.