Security Surprises On Firefox Quantum
Wednesday, May 31, 2023
0
comments
This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
More articles
- Growth Hacker Tools
- Pentest Tools Android
- Hacking Tools And Software
- Hacks And Tools
- Pentest Tools Website Vulnerability
- Hacking Tools For Kali Linux
- What Is Hacking Tools
- Pentest Tools Kali Linux
- Pentest Tools Github
- Pentest Tools Download
- Pentest Tools Linux
- Pentest Automation Tools
- Pentest Tools Kali Linux
- Pentest Tools Bluekeep
- Tools 4 Hack
- Hack Tool Apk No Root
- Pentest Tools Tcp Port Scanner
- Hacker Search Tools
- Hacking Tools Mac
- Hack Tools Pc
- Hacker Tools Online
- Hack Tools Online
- Hack Tools
- Hacking Tools For Windows 7
- Pentest Box Tools Download
- Blackhat Hacker Tools
- Hacker Tools Free Download
- Hacking Tools 2020
- Pentest Tools Download
- How To Hack
- Pentest Tools Alternative
- Usb Pentest Tools
- Hacker Tools For Pc
- Hacking Apps
- Hacker Techniques Tools And Incident Handling
- Pentest Tools List
- Pentest Tools Windows
- Hacking Tools Pc
- Beginner Hacker Tools
- Hacking Tools For Windows 7
- Bluetooth Hacking Tools Kali
- Pentest Tools Review
- Pentest Tools Review
- Best Pentesting Tools 2018
- Best Hacking Tools 2020
- Hackers Toolbox
- Pentest Tools For Android
- Top Pentest Tools
- Hacking Tools Pc
- Hacker Tools Online
- Physical Pentest Tools
- Hacking Apps
- Hacking Tools For Windows 7
- Hacker Tools Online
- Hacker Tools Hardware
- Top Pentest Tools
- Easy Hack Tools
- Physical Pentest Tools
- What Are Hacking Tools
- Hacking Tools Download
- Hacking Tools For Games
- Hacker Tools Software
- Hackers Toolbox
- Top Pentest Tools
- Hacking Tools Download
- Hacker Security Tools
- Pentest Tools Tcp Port Scanner
- Hack Tools For Windows
- Hacking Tools Pc
- Hack Tool Apk No Root
- Pentest Tools Alternative
- Hak5 Tools
- Hacking Tools Mac
- Pentest Tools For Mac
- Hack Tools Pc
- Hack Tools
- Install Pentest Tools Ubuntu
- Pentest Tools Online
- Hacking Apps
- Hack App
- Computer Hacker
- Hack Tools For Windows
- Hacker Tools 2020
- Wifi Hacker Tools For Windows
- Ethical Hacker Tools
- Nsa Hack Tools
- Nsa Hack Tools
- Hacking Tools For Windows
- Nsa Hacker Tools
- Hack Tools Github
- Install Pentest Tools Ubuntu
- Hacker Tools For Pc
- Tools 4 Hack
- Hacking Tools For Games
- Pentest Tools Find Subdomains
- Free Pentest Tools For Windows
- Easy Hack Tools
- Hack Tools Pc
- Hacker Tools 2019
- Pentest Tools Windows
- Hacking Tools Usb
- Usb Pentest Tools
- Bluetooth Hacking Tools Kali
- Hacker
- Hack Tools Online
- Hacker Tools 2020
- Hack Tools Download
- Hacker Tools Github
- Hacker Tools Software
- Game Hacking
- Game Hacking
- Hacking Tools Usb
- Hacks And Tools
- Pentest Tools Linux
- Hack Tools For Games
- Hacker Tools Linux
- Pentest Tools Framework
- Pentest Tools List
- Hacking Tools For Windows 7
- Tools For Hacker
- Hacker Tools Free Download
- Hak5 Tools
- Tools For Hacker
- Pentest Tools Free
- Hacking Tools And Software
- Wifi Hacker Tools For Windows
- Hacker Techniques Tools And Incident Handling
- Hack Tool Apk
- Hacking Tools Hardware
- Hacker Tools Apk
- Hacker Tools Linux
- Hack App
- Hacking Tools Windows
- Easy Hack Tools
- Hacking Tools And Software
- Hacking Tools And Software
- Hackrf Tools
- Hacking Tools Online
- Hacking Tools For Kali Linux
- Hacking Tools For Windows Free Download
- New Hack Tools
- Hack Tool Apk
- Hacker Security Tools