M$ FF .NET sneak causes security breach

Viruses, hackers and crackers
Post Reply
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

M$ FF .NET sneak causes security breach

Post by jee »

Remember that Microsoft .NET Framework Assistant add-on that Microsoft sneaked into Firefox without explicit permission from end users?

Well, the code in that add-on has a serious code execution vulnerability that exposes Firefox users to the “browse and you’re owned” attacks that are typically used in drive-by malware downloads.
Now, Microsoft’s security folks are actually recommending that Firefox users uninstall the buggy add-on:

For Firefox users with .NET Framework 3.5 installed, you may use “Tools”-> “Add-ons” -> “Plugins”, select “Windows Presentation Foundation”, and click “Disable”.
http://blogs.zdnet.com/security/?p=4614&tag=nl.e589
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
WiK1d
Registered User
Posts: 20732
Joined: 13 Sep 2004, 02:00
Location: Cruising the streets of Pretoria
Contact:

Re: M$ FF .NET sneak causes security breach

Post by WiK1d »

Oooh, so this is what the popup I got yesterday is about. Firefox automatically asked if I wanted to disable it, and I was like, uh, okay..
SykomantiS
Registered User
Posts: 14085
Joined: 06 Oct 2004, 02:00
Location: Location, Location...
Contact:

Re: M$ FF .NET sneak causes security breach

Post by SykomantiS »

WiK1d wrote:Oooh, so this is what the popup I got yesterday is about. Firefox automatically asked if I wanted to disable it, and I was like, uh, okay..
++ Last night FF asked me if I want to disable the callamawatchit. Haven't had a problem since.
jee
Registered User
Posts: 19336
Joined: 03 Jun 2003, 02:00
Location: a hole so deep...

Re: M$ FF .NET sneak causes security breach

Post by jee »

yeah, fortunately FF is on the ball :)
"Integrity" and "integer" both contain a Latin root meaning "whole; complete." The root sense, then, is that people may be said to be acting with integrity when their beliefs, words, and actions have a sense of unity or wholeness.
DarkStar
Registered User
Posts: 2701
Joined: 17 Aug 2004, 02:00
Location: What? You mean you can't see me?
Contact:

Re: M$ FF .NET sneak causes security breach

Post by DarkStar »

Firefox didn't even ask me. I just checked now and it was disabled :roll:
Last edited by DarkStar on 18 Oct 2009, 20:13, edited 1 time in total.
If I can't find a friendship problem...I'll make a friendship problem!
http://www.youtube.com/watch?v=Lxo1qlk6gEI
StarBound
Registered Pervert
Posts: 6879
Joined: 30 Jul 2004, 02:00
Processor: Intel i7 4790k
Motherboard: MSI Z97 Gaming 7
Graphics card: MSI GTX780Ti Gaming
Memory: G.Skill Sniper 1866mhz 16GB
Location: The Greater Unknown
Contact:

Re: M$ FF .NET sneak causes security breach

Post by StarBound »

Yeah FF was screaming at me this morning too.
My Steam Screenshots

I lived the dream ...then my PC died.
User avatar
Prime
Registered User
Posts: 27729
Joined: 01 Mar 2004, 02:00
Location: Getting into trouble
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Prime »

And I use Opera 10 :twisted:
User avatar
Stuart
Lead Forum Administrator
Posts: 38503
Joined: 19 May 2005, 02:00
Location: Home

Re: M$ FF .NET sneak causes security breach

Post by Stuart »

I had to disable mine manually. :?
Image
Monty
Forum Moderator
Posts: 10000
Joined: 05 Feb 2004, 02:00
Processor: Intel i5-4690K @ 4.5GHZ
Motherboard: ASUS Maximus VII Formula
Graphics card: ASUS GTX970 Strix
Memory: 4 x 4GB Corsair Dominators
Location: Messing with your Mind
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Monty »

Prime wrote:And I use Opera 10 :twisted:
Poor Prime. We'll pray for you and hope you see the light that is FireFox.
Art Williams wrote:I'm not telling you it is going to be easy, I'm telling you it's going to be worth it.
User avatar
Prime
Registered User
Posts: 27729
Joined: 01 Mar 2004, 02:00
Location: Getting into trouble
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Prime »

Monty wrote:
Prime wrote:And I use Opera 10 :twisted:
Poor Prime. We'll pray for you and hope you see the light that is FireFox.
The lightening while strike you the day you pray :tongue:
DarkStar
Registered User
Posts: 2701
Joined: 17 Aug 2004, 02:00
Location: What? You mean you can't see me?
Contact:

Re: M$ FF .NET sneak causes security breach

Post by DarkStar »

I tried Opera 10 once, but was put off it as there was no simple and obvious way to transfer all my Firefox settings.
If I can't find a friendship problem...I'll make a friendship problem!
http://www.youtube.com/watch?v=Lxo1qlk6gEI
Monty
Forum Moderator
Posts: 10000
Joined: 05 Feb 2004, 02:00
Processor: Intel i5-4690K @ 4.5GHZ
Motherboard: ASUS Maximus VII Formula
Graphics card: ASUS GTX970 Strix
Memory: 4 x 4GB Corsair Dominators
Location: Messing with your Mind
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Monty »

Prime wrote:
Monty wrote:
Prime wrote:And I use Opera 10 :twisted:
Poor Prime. We'll pray for you and hope you see the light that is FireFox.
The lightening while strike you the day you pray :tongue:
Sweet! I've got my radioactive spider and kryptonite ready for it!
Art Williams wrote:I'm not telling you it is going to be easy, I'm telling you it's going to be worth it.
User avatar
rustypup
Registered User
Posts: 8872
Joined: 13 Dec 2004, 02:00
Location: nullus pixius demonica
Contact:

Re: M$ FF .NET sneak causes security breach

Post by rustypup »

<ridiculously off-topic>
DarkStar wrote:but was put off it as there was no simple and obvious way to transfer all my Firefox settings.
this is either the most profound, or most twilight-fan'ish, reason ever presented... :P i'm guessing the File->Import and Export option was somehow missing from the menu?
</ridiculously off-topic>

this is pretty much SOP for microsoft.... :/
Most people would sooner die than think; in fact, they do so - Bertrand Russel
User avatar
hamin_aus
Forum Moderator
Posts: 18363
Joined: 28 Aug 2003, 02:00
Processor: Intel i7 3770K
Motherboard: GA-Z77X-UP4 TH
Graphics card: Galax GTX1080
Memory: 32GB G.Skill Ripjaws
Location: Where beer does flow and men chunder
Contact:

Re: M$ FF .NET sneak causes security breach

Post by hamin_aus »

Brilliant move by Microsoft IMO.
We'll prove FF isn't as secure as people think by releasing a "plug-in" that creates a vulnerability on ti.

Genius!

Shame on the whistle-blower who let everyone in on this...
Image
User avatar
Ron2K
Forum Technical Administrator
Posts: 9050
Joined: 04 Jul 2006, 16:45
Location: Upper Hutt, New Zealand
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Ron2K »

Prime wrote:And I use Opera 10 :twisted:
This isn't a Firefox vs Opera debate, please don't turn it into one.

In any case, the fault here lies with Microsoft. One would expect a major software company not to release this kind of thing, but no. What makes it worse is the fact that it affects a product that's a major threat to their browser dominance - one wonders if this is a new mutation on their "Embrace, extend, extinguish" strategy? (Wiki link for those who don't know about that.)
Kia kaha, Kia māia, Kia manawanui.
User avatar
Ron2K
Forum Technical Administrator
Posts: 9050
Joined: 04 Jul 2006, 16:45
Location: Upper Hutt, New Zealand
Contact:

Re: M$ FF .NET sneak causes security breach

Post by Ron2K »

Update on this one: Microsoft and Mozilla have been working on the issue, with the result that the plugin has now been unblocked. See this blog post for more info.
Kia kaha, Kia māia, Kia manawanui.
Post Reply