MozillaZine

First piece of spyware made for mozilla browsers

Discussion of general topics about Mozilla Firefox
fosterr
 
Posts: 10
Joined: February 28th, 2004, 2:07 am
April 20th, 2004, 9:49 am

Post Posted April 20th, 2004, 9:49 am

Today I went to animewallpapers.com and got this popup which tried to install
what has to be the first web page hijacker made for mozilla based browsers.
I do not know if this is the first ever spyware for mozilla browers but it is the first
time I have have seen any. It is also a virus.

Image

When I visited the url that is there it takes you too a License Agreement,
when you read it it confirms that it is a web page hijacker.

http://www.blazefind.com/license.html

old Neil Parks
Moderator
 
Posts: 0
Joined: December 31st, 1969, 5:00 pm
April 20th, 2004, 10:03 am

Post Posted April 20th, 2004, 10:03 am

Defense:

http://accs-net.com/hosts/

"blazefind.com" is one of the hosts blocked by this excellent file.

John Liebson
 
Posts: 5941
Joined: July 29th, 2003, 1:09 pm
April 20th, 2004, 11:12 am

Post Posted April 20th, 2004, 11:12 am

Hardly the first; see, for example, http://forums.mozillazine.org/viewtopic.php?t=66531

shadytrees
Moderator

User avatar
 
Posts: 11742
Joined: November 30th, 2002, 6:41 am
Location: Where hugs are plentiful,
April 20th, 2004, 1:38 pm

Post Posted April 20th, 2004, 1:38 pm

There seems to have been a surge of the first batch of spyware XPIs this month. There's around five or six of these circulating now.
Once upon a time, in a land far far away, there lived a grove of oranges. These oranges lived contentedly until one day when they were harvested and used in a salad.
wog | hug me

TheOneKEA

User avatar
 
Posts: 4860
Joined: October 16th, 2003, 5:47 am
Location: Somewhere in London, riding the Underground
April 20th, 2004, 2:20 pm

Post Posted April 20th, 2004, 2:20 pm

Bug 238684 is on its way to being RESOLVED FIXED, which will prevent this from happening in Firefox 0.9.
Proud user of teh Fox of Fire
Registered Linux User #289618

c0Ld

User avatar
 
Posts: 384
Joined: March 6th, 2004, 5:28 pm
April 20th, 2004, 2:20 pm

Post Posted April 20th, 2004, 2:20 pm

hopefully .9 will resolve this :)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041107 Firefox/1.0
+AdBlock
+ChatZilla
+Download Manager Tweak

Xe
 
Posts: 86
Joined: March 2nd, 2004, 5:21 pm
April 20th, 2004, 3:28 pm

Post Posted April 20th, 2004, 3:28 pm

I have also seen this on a couple of other sites...

BenBasson
Moderator

User avatar
 
Posts: 13654
Joined: February 13th, 2004, 5:49 am
Location: Guildford, UK
April 20th, 2004, 4:26 pm

Post Posted April 20th, 2004, 4:26 pm

The install trigger can no longer be opened by an onload event, the code was just checked in. See Bug 238684 for details.

[ Apocalipsis ]

User avatar
 
Posts: 711
Joined: March 23rd, 2004, 6:29 pm
Location: Somewhere In Hell, Mexico*
April 20th, 2004, 6:31 pm

Post Posted April 20th, 2004, 6:31 pm

just gessing....is there any aprox date to 0.9 be released??
..:: [ No God No Master* ] ::..
Soporte Tecnico en Español:
Informatica XP | SOS Virtual | Foros SOS Virtual

soccer_dude182

User avatar
 
Posts: 720
Joined: July 11th, 2003, 10:50 pm
Location: Waco, TX
April 20th, 2004, 7:23 pm

Post Posted April 20th, 2004, 7:23 pm

So, there won't ever be any popups like these when .9 rolls around?

Thesh

User avatar
 
Posts: 370
Joined: October 15th, 2003, 12:30 am
April 20th, 2004, 8:04 pm

Post Posted April 20th, 2004, 8:04 pm

soccer_dude182 wrote:So, there won't ever be any popups like these when .9 rolls around?


Not done the same way you saw there. Most likely they will just start putting these in onClick events in regular links...

soccer_dude182

User avatar
 
Posts: 720
Joined: July 11th, 2003, 10:50 pm
Location: Waco, TX
April 20th, 2004, 11:10 pm

Post Posted April 20th, 2004, 11:10 pm

Does that mean we'll see them less often? ... I guess what I'm asking is.. what difference will it make from changing the onload event if they'll just change the way the spyware comes up?

jason2584

User avatar
 
Posts: 111
Joined: April 20th, 2004, 11:05 am
Location: Indianapolis, IN
April 20th, 2004, 11:28 pm

Post Posted April 20th, 2004, 11:28 pm

If they don't allow the XPInstaller to be called onLoad, and only onClick, then you won't see these installation prompts ("popups") unless you click on something. That solves the problem, unless of course the site author puts a call to XPInstall in a link's OnClick event and calls the link something misleading. That's similar to sites that have links that execute an ActiveX module (in IE) or initiate a file download that you weren't expecting. The *bad*ware won't go away, but at least the installation prompt will only come up if you click on something, instead of just popping up when the page loads. Not much more you can do, really. Educate the masses...teach them to read message boxes before automatically clicking "Yes" or "OK".
Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0

d_g

User avatar
 
Posts: 519
Joined: July 24th, 2003, 3:50 pm
April 21st, 2004, 3:36 am

Post Posted April 21st, 2004, 3:36 am

I've always noticed that XPI install windows have 'unsigned' in them. Presumebly this hints that there might be some kind of signing method for approved extensions. Anyone know any more about this?

d_g

User avatar
 
Posts: 519
Joined: July 24th, 2003, 3:50 pm
April 21st, 2004, 3:38 am

Post Posted April 21st, 2004, 3:38 am


Return to Firefox General


Who is online

Users browsing this forum: Bluefang, Gort, Miccovin and 9 guests