This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
Read more
- Pentest Tools Review
- Computer Hacker
- Bluetooth Hacking Tools Kali
- Hacker Hardware Tools
- Pentest Tools Tcp Port Scanner
- Hacking Tools Github
- Hacking Tools For Windows 7
- Pentest Reporting Tools
- Hacker Tools List
- Tools 4 Hack
- Pentest Tools For Mac
- Hacking Tools Github
- Hacker Search Tools
- Hacking Tools For Pc
- Tools Used For Hacking
- Hacking Tools Software
- Best Pentesting Tools 2018
- Hack Tools Pc
- Pentest Tools Tcp Port Scanner
- What Are Hacking Tools
- Best Hacking Tools 2020
- Hacking Tools For Kali Linux
- Pentest Tools Website Vulnerability
- Hackers Toolbox
- Hack Tools Github
- Pentest Reporting Tools
- Hacking Tools For Windows Free Download
- Ethical Hacker Tools
- Hacking Tools Usb
- Pentest Tools Apk
- Hacking Tools Windows 10
- Hack Tools Github
- Tools Used For Hacking
- Tools 4 Hack
- Pentest Tools For Mac
- Hack Tools For Pc
- Pentest Tools Nmap
- Hack Rom Tools
- Nsa Hack Tools Download
- Hacker Tools For Pc
- Hacker Tools Mac
- Hacker Tools For Pc
- Pentest Tools Find Subdomains
- Wifi Hacker Tools For Windows
- How To Hack
- Pentest Tools For Ubuntu
- Hacking Tools For Beginners
- Kik Hack Tools
- Pentest Box Tools Download
- Underground Hacker Sites
- Hacker Tools Free
- Pentest Tools Windows
- Pentest Tools Free
- Hack Tools For Pc
- Hack Website Online Tool
- Growth Hacker Tools
- Hacking Tools Free Download
- Hacker Search Tools
- Hack Tools Online
- Free Pentest Tools For Windows
- Hacking Tools For Windows 7
- Pentest Tools Android
- Physical Pentest Tools
- Hack Rom Tools
- Pentest Tools Tcp Port Scanner
- World No 1 Hacker Software
- Termux Hacking Tools 2019
- Pentest Tools Review
- Hacker Tools List
- Pentest Tools Apk
- Hacker Tools Hardware
- Android Hack Tools Github
- Hacker Tools For Ios
- Hacker Tools Windows
- Hacking Tools For Games
- Physical Pentest Tools
- Pentest Tools Kali Linux
- Hack And Tools
- Blackhat Hacker Tools
- Hacks And Tools
- Nsa Hack Tools
- Tools 4 Hack
- New Hacker Tools
- Hacker Tools Free
- Pentest Tools For Windows
- Hacker Tools Linux
- Hacking Tools Name
- Hacking Tools For Games
- Ethical Hacker Tools
- Pentest Tools Subdomain
- Hack Tools
- Hacking Tools 2020
- Pentest Tools Apk
- Best Pentesting Tools 2018
- Hacking Tools For Windows
- Hacker Security Tools
- Hack Tools For Windows
- Hack App
- Hacker Tools
- Kik Hack Tools
- Hacking Tools Software
- Nsa Hacker Tools
- Physical Pentest Tools
- Hacking Tools 2020
- Hacking Tools Name
- Hacker Tools Online
- Pentest Tools Open Source
- Pentest Tools Android
- Hacker Tools Hardware
- Android Hack Tools Github
- What Is Hacking Tools
- What Are Hacking Tools
- Top Pentest Tools
- Pentest Box Tools Download
- Pentest Tools Windows
- Best Hacking Tools 2020
- Hack Tools For Games
- Hacking Tools
- Wifi Hacker Tools For Windows
- Hacking Tools Free Download
- Hacking Tools Usb
- What Is Hacking Tools
- How To Make Hacking Tools
- Hak5 Tools
- Growth Hacker Tools
- How To Install Pentest Tools In Ubuntu
- Pentest Tools Alternative
- Hacking Tools For Beginners
- Hackers Toolbox
- Pentest Tools Open Source
- How To Hack
- Hacking Tools Kit
- Pentest Tools List
- World No 1 Hacker Software
- Hacker Tools Mac
- Hack Tools For Windows
- Hacking Tools Windows
- Hacker Tools
- Nsa Hacker Tools
- Kik Hack Tools
- Hack Tools Pc
- Hacking Tools For Windows
- Free Pentest Tools For Windows
- How To Make Hacking Tools
- Hack And Tools
- Pentest Tools Online
- Hack Tools For Mac
No comments:
Post a Comment