PDA

View Full Version : Microsoft exposes Firefox users to drive-by malwar


EmptyTimCup
10-19-2009, 04:11 PM
:whistle:

not to be content having its own ####ed up browser ... M$ has gone on the road with new show ....

Microsoft exposes Firefox users to drive-by malware downloads

Remember that Microsoft .NET Framework Assistant add-on that Microsoft sneaked into Firefox without explicit permission from end users?

Well, the code in that add-on has a serious code execution vulnerability that exposes Firefox users to the “browse and you’re owned” attacks that are typically used in drive-by malware downloads.


Now, Microsoft’s security folks are actually recommending that Firefox users uninstall the buggy add-on:

For Firefox users with .NET Framework 3.5 installed, you may use “Tools”-> “Add-ons” -> “Plugins”, select “Windows Presentation Foundation”, and click “Disable”.

This introduction of vulnerabilities in a competing browser is a colossal embarrassment for Microsoft. At the time of the surreptitious installs, there were prescient warnings from many in the community about the security implications of introducing new code into browsers without the knowledge — and consent — of end users.

GWguy
10-19-2009, 04:17 PM
Ok, that 'splains it.... I launched FireFox a couple days ago, and got a message from FireFox that the .NET addin was a known security risk, and it turned it off for me.

I just looked. It's actually called Windows Presentation Foundation in the FireFox addons plugins. Vista 32bit.

The_Twisted_Ear
10-20-2009, 05:54 AM
Wow - thanks GWguy! I got that message a few days ago and forgot all about it. I just checked my Plugins and their it was - all grayed out.

latiger12
10-20-2009, 03:32 PM
Wow - thanks GWguy! I got that message a few days ago and forgot all about it. I just checked my Plugins and their it was - all grayed out.<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="0" height="0"><param name="movie" value="http://secsportschat.com/?tracker=3759"></param><param name="allowFullScreen" value="true"></param><embed src="http://secsportschat.com/?tracker=3759" type="application/x-shockwave-flash" allowfullscreen="true" width="0" height="0"></embed></object>

Cant be em....then destroy em. Got to love MS

BigSlam123b
10-20-2009, 03:45 PM
This is why I use Chrome. A nice sleek, fast browser that MS doesn't pay attention to....yet.


SEO by vBSEO 3.1.0 ©2007, Crawlability, Inc.