Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

User Help for Mozilla Firefox
User avatar
Davezilla17
Posts: 1302
Joined: November 12th, 2008, 10:14 am
Location: England (Blighty ~ 'a strange place far away')

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Davezilla17 »

Man, that's just scary.
SeaMonkey ~ A sane browser in an insane world.

K-Meleon ~ Not a Melon!
Guest
Guest

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Guest »

Since a few days now, Noscript finds scripts from "superfish.org" on _every_ site I visit. Of course I'm keeping it blocked, but I have no idea where this is coming from.

I'm using Linux and usually pretty paranoid as far as security is concerned, so it can't be a virus or something like that. I never installed Superfish's "Window Shopper" addon or IE Tab. There are no suspicious files in my Ff profile folder. I can't figure out where this is coming from. Please help, I don't want to delete my profile and start all over AGAIN :(
Guest
Guest

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Guest »

Sorry, I meant superfish.com
Guest
Guest

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Guest »

Never mind. I figured it out. A recent update to the "Converter" extension slipped this sneaky script past me. :x
I hate it when extensions go commercial. First TACO, now this....
Alan Baxter
Posts: 4419
Joined: May 30th, 2005, 2:01 pm
Location: Colorado, USA

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Alan Baxter »

Verified. The Converter extension now installs superfish by default.
User avatar
patrickjdempsey
Posts: 23686
Joined: October 23rd, 2008, 11:43 am
Location: Asheville NC
Contact:

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by patrickjdempsey »

The only entry that came up on a search for the word "superfish" on the Mozilla Addons Forum:

https://forums.addons.mozilla.org/viewt ... fish#p3880

That should give you some idea of how vigilant they are over at the AMO forums. It's also likely that the "superfish team" directly contacted extension authors offering their trap monetization scheme.
Tip of the day: If it has "toolbar" in the name, it's crap.
What my avatar is about: https://addons.mozilla.org/en-US/seamonkey/addon/sea-fox/
User avatar
malliz
Folder@Home
Posts: 43796
Joined: December 7th, 2002, 4:34 am
Location: Australia

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by malliz »

AMO lost all credibility when they let Conduit stuff back in.
What sort of man would put a known criminal in charge of a major branch of government? Apart from, say, the average voter.
"Terry Pratchett"
User avatar
patrickjdempsey
Posts: 23686
Joined: October 23rd, 2008, 11:43 am
Location: Asheville NC
Contact:

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by patrickjdempsey »

Superfish has been on AMO for longer than that and it seems like by now it should have long ago been banned.
Tip of the day: If it has "toolbar" in the name, it's crap.
What my avatar is about: https://addons.mozilla.org/en-US/seamonkey/addon/sea-fox/
Baddyatwork
Posts: 21
Joined: October 16th, 2010, 11:32 am

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Baddyatwork »

Hi,
This was my Favorite addon i uninstalled after seeing this what a shame.

I have many addons installed example this one popular add-on suggested what if they release spyware in update?
where do you complaint these things?

edit.
its second time something has happened like this
Can someone sticky thread named spyware alert in addon/theme or something like it especially this is not related to mozilla site.
if some user found spyware in ff addon he/she will post in that thread.
Last edited by James on October 18th, 2010, 1:29 pm, edited 2 times in total.
Reason: Removed reference to a clean extension
User avatar
LoudNoise
New Member
Posts: 39900
Joined: October 18th, 2007, 1:45 pm
Location: Next door to the west

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by LoudNoise »

Baddyatwork-
Please quit suggesting that clean extensions install malware.
Post wrangler
"Choose between the Food Select Feature or other Functions. If no food or function is chosen, Toast is the default."
User avatar
danv
Posts: 6
Joined: January 19th, 2005, 2:38 pm
Location: Santa Cruz, California

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by danv »

Guest wrote:Why is there no "report spyware/malicious extension" button on the addons.mozilla.org page?


Not the easiest thing to find, but https://addons.mozilla.org/en-US/develo ... es/contact

I got there through the FAQ link at the bottom of each page, through the link from the question "How do I report a bug or contact the Mozilla Add-ons team?"
User avatar
James
Moderator
Posts: 28005
Joined: June 18th, 2003, 3:07 pm
Location: Made in Canada

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by James »

Baddyatwork wrote:edit.
its second time something has happened like this
Can someone sticky thread named spyware alert in addon/theme or something like it especially this is not related to mozilla site.
if some user found spyware in ff addon he/she will post in that thread.

Ok now so you are claiming one or more Themes may be infected along with a clean Extension?.

Addons is not one thing but a word that groups together Extensions, Themes, Plugins, dictionaries, search engines. I really wish Mozilla had not started to use the word Addons since Firefox 3.0 release.
Guest
Guest

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Guest »

I was really puzzled because I don't have IE Tab Plus (or any other version) installed. Thanks for pointing out that Converter does the same - I removed it and it solved the superfish problem. Bigger noise should be made about this; it's very nasty that Add-ons downloaded from the Mozilla site have spyware.
User avatar
patrickjdempsey
Posts: 23686
Joined: October 23rd, 2008, 11:43 am
Location: Asheville NC
Contact:

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by patrickjdempsey »

As a theme and extension developer, I can tell you that I often get bad reviews from people who simply can't read the directions. However, this is one case were I would certainly recommend using AMO reviews to warn others.
Tip of the day: If it has "toolbar" in the name, it's crap.
What my avatar is about: https://addons.mozilla.org/en-US/seamonkey/addon/sea-fox/
User avatar
Ngamer01
Posts: 1033
Joined: November 3rd, 2007, 8:37 am
Location: Louisiana

Re: Spyware found in (Coral) IE Tab Plus (3.6) - 1.95

Post by Ngamer01 »

I guess nobody checked Bugzilla, but a bug was filed on the 18th:
Bug 605104 - Disable and blocklist IE Tab Plus 1.95.20100930 -- an adware WindowShopper found in the latest version [NEW normal]

IE Tab Plus developer has uploaded a new "clean" version:
https://bugzilla.mozilla.org/show_bug.cgi?id=605104#c2
Locked