The Active Network
ActiveMac Anonymous | Create a User | Reviews | News | Forums | Advertise  
 

  *  

  Mozilla shipped worm with Firefox add-on
Time: 09:07 EST/14:07 GMT | News Source: ComputerWorld | Posted By: Jonathan Tigner

Mozilla Corp. yesterday warned users about a worm that slipped into Firefox's Vietnamese language add-on and went undetected for months.

The malware-infected file has been pulled from Mozilla's servers.

"The Vietnamese language pack for Firefox 2 contains inserted code to load remote content," Window Snyder, Mozilla's chief security executive, confirmed in a post to the company's blog on Wednesday. "Everyone who downloaded the most recent Vietnamese language pack since Feb. 18, 2008, got an infected copy."

According to Snyder, the download count for the add-on since last November has been 16,667. "So we anticipate the impact on users to be limited," she said.

Write Comment
Return to News

  Displaying 1 through 25 of 329
Last | Next
  The time now is 5:48:11 PM ET.
Any comment problems? E-mail us
#1 By 23603 (74.57.49.167) at 5/9/2008 10:22:52 AM
Glad I don't use FireFox...

That is and always will be the problem with open source software... you never exactly what you are downloading.

Long live IE8 (beta1 :-)

#2 By 7797 (72.229.133.104) at 5/9/2008 10:45:55 AM
You have lots to learn Grasshopper:

http://windowsitpro.com/article/articleid/20864/funlove-virus-infects-microsoft-hotfixes.html

http://amcptwo.blogspot.com/2006/10/apple-ships-virus-infected-ipods.html

http://news.zdnet.co.uk/security/0,1000000189,39290782,00.htm

#3 By 2960 (72.196.195.185) at 5/9/2008 10:50:56 AM
Old news. Was reported days ago.

#4 By 92283 (142.25.203.200) at 5/9/2008 12:28:44 PM
"Snyder said that Mozilla would boost the number of times it scanned files for malware. "We are also adding after-the-fact scans of everything to address this sort of case in the future," she said.

Developers on Bugzilla, however, argued whether that was feasible. "Ideally, yes, except that we get new definitions on average every six hours or so and it takes over a week to virus-scan the entire FTP server," said Mozilla's Miller as he replied to a proposal to rescan after every signature update. "

They need to get a faster ftp server.

#5 By 15406 (216.191.227.68) at 5/9/2008 1:02:26 PM
#1: That is and always will be the problem with open source software... you never exactly what you are downloading.

That's got to be about the silliest comment I've read on ActiveWin in a while. With closed source, you have no idea what you're getting. With open source, you have the option of viewing & compiling the code yourself instead of trusting the binaries provided.

#2: Good reply.

#6 By 92283 (142.32.208.233) at 5/9/2008 1:22:21 PM
"With open source, you have the option of viewing & compiling the code yourself instead of trusting the binaries provided"

But clearly no one did.

#7 By 92283 (142.32.208.233) at 5/9/2008 1:22:25 PM
...

This post was edited by NotParkerToo on Friday, May 09, 2008 at 13:22.

#8 By 23275 (68.186.182.236) at 5/9/2008 2:05:28 PM
Clearly Moz/Ff is not the secure wunderkind it was held out to be, and this last business is but one example.

For my money, I would prefer to stick with "a plan" - that being executed under the SDL and manifest in the effective layered approach Microsoft has adopted.

Similarly, and with equal clarity, the Internet evolved and the companies serving it have evolved with it - threats matured and so now have the methods used to deal with them.

FOSS/OSS has one way and it has proven to be at least as porous as MS was pre 2004 - before the SDL and Trustworthy Computing Initiative first began to show some teeth. Four years later, Microsoft is exactly where they should be, leading from the front and setting a good example for all.

Now... Moz/FF get back with MS and enabled securable objects, the UIPI and bake them into FF as your own version of Protected MODE - it alongside UAC and ASLR in x64 Vista simply work!

And don't even get me started on the dated and overly simple read, write execute BS security in the *nix - it simply does not compare to the model found in Windows Vista - most especially x64

*Happy Mother's Day!*

#9 By 23603 (69.70.34.2) at 5/9/2008 2:52:04 PM
@tgnb

2 years old article...come on.. You can do better then that.

@latch

Read my comment again blindy "you never exactly what you are downloading". I did not mentionned anything about viewing and recompiling.


#10 By 143 (65.221.158.226) at 5/9/2008 4:26:15 PM
You think that's bad wait when apps start running in FF. It will be like the old days when ActiveX first came out.

#11 By 7797 (72.229.133.104) at 5/9/2008 5:01:12 PM
@EQ23 I don't have to do better than that for the point i made!

#12 By 20505 (216.102.144.11) at 5/9/2008 8:06:56 PM
Hey ya'll,

I'll give you one of my philosophies of life.

At some point you must trust someone, otherwise you end up like Howard Hughes.

So the question is... who do you really trust (the evening news? ms? your doctor? your mom?)?

#13 By 143 (74.129.194.180) at 5/10/2008 2:18:12 PM
@#12
Give me your credit card number and we'll talk about trust. ;)

#14 By 15406 (216.191.227.68) at 5/12/2008 8:34:18 AM
#8: Yep, gotta love that MS security:

http://www.activewin.com/awin/comments.asp?HeadlineIndex=43653&Group=1

http://www.activewin.com/awin/comments.asp?HeadlineIndex=43672&Group=1

But I must agree with you. Having a web browser language pack infected by a Windows virus MUST mean that the entire security model for Unix and FOSS in general is completely invalid. Good thing that this kind of thing has never happened to Microsoft or you would have to judge them the same way, right?

#15 By 829540 (88.190.242.107) at 10/6/2012 6:04:27 AM
<a href=http://acquistocialisgarantito.com/#zwww.activewin.com>cialis italia gratis</a>, <a href=http://acquistocialisgarantito.com/#qwww.activewin.com>cialis tadalafil 20mg</a>, http://acquistocialisgarantito.com/#swww.activewin.com cialis italia gratis

#16 By 829540 (88.190.242.107) at 10/6/2012 6:04:27 AM
<a href=http://acquistocialisgarantito.com/#xwww.activewin.com>comprare cialis dove</a>, <a href=http://acquistocialisgarantito.com/#ywww.activewin.com>cialis italiano</a>, http://acquistocialisgarantito.com/#fwww.activewin.com acquisto cialis senza ricetta

#17 By 822056 (199.15.234.134) at 10/9/2012 12:10:20 PM
BkoxKVIY <a href=http://cheap-nike-nfl-jerseys.webgarden.com/>cheap nike nfl jerseys</a>
dnejQIFay http://cheap-nfljerseys.webgarden.com/
wvirleozrx <a href=http://cheap-nikenfljerseys.webgarden.com/#5654>cheap nike nfl jerseys</a>
LSRlRieqd ckmujw <a href=http://cheap-nfljerseys.webgarden.com/>cheap nfl jerseys</a>
IycNCICZxxl

#18 By 962952 (58.22.10.90) at 12/22/2012 11:56:58 PM
HonAtopeweere <a href=http://www.nikeredskinsjerseystore.com>Robert Griffin III Authentic Jersey</a>
HoryCryhona <a href=http://www.officialpredatorsauthentic.com/mike-fisher-authentic-jersey.html>Mike Fisher Authentic Jersey</a>
seigobremoima <a href=http://www.nikesteelersjerseyshop.com>Troy Polamalu Jersey</a>

#19 By 969185 (58.22.3.53) at 12/23/2012 11:13:02 PM
<a href=http://www.officialnikeVikingsjersey.com>Matt Kalil Jersey</a> claidsimise
<a href=http://www.torontomapleleafsjerseyshop.com/colby-armstrong-authentic-jersey>Colby Armstrong Jersey Cheap</a> AddimiArodype
<a href=http://www.officialpredatorsauthentic.com/pekka-rinne-authentic-jersey.html>Pekka Rinne Authentic Jersey</a> Petapewen

#20 By 1045383 (120.43.22.202) at 3/3/2013 2:50:24 AM
TreadayCreeve <a href=http://www.redbottomshoesmartusa.com/>red bottom shoes for men</a>

TreadayCreeveOM <a href=http://www.redbottomshoesmartusa.com/>red bottom shoes for women</a>

Roreadorm <a href=http://www.authenticcheapjordans.com/>authentic jordans</a>

#21 By 1047191 (120.43.22.202) at 3/5/2013 3:00:41 AM
TreadayCreeve <a href=http://www.wholesalerjerseysfromchina.com/>wholesale nfl jerseys</a>

TreadayCreeveOM <a href=http://www.houstonrocketsprostore.com/womens-jeremy-lin-jersey>Authentic Jeremy Lin jersey</a>

Roreadorm <a href=http://www.cheaperjerseysus.com/>cheap nike nfl jerseys</a>

#22 By 1059863 (27.153.229.117) at 3/15/2013 1:50:10 PM
<a href=http://www.viplouboutinsale.net>louboutin on sale</a>
<a href=http://www.louboutinoutletmartus.net>christian louboutin sandals</a>
<a href=http://www.michaelkorsoutletmartus.com/>michael kors purses outlet</a>

#23 By 1061082 (27.153.228.52) at 3/16/2013 12:51:34 AM
<a href=http://www.michaelkorsoutletmartus.com/>michael kors outlet online</a>
<a href=http://www.viplouboutinsale.net>louboutin for sale</a>
<a href=http://www.michaelkorsoutletmartus.com/>michael kors purses</a>

#24 By 899255 (216.152.251.6) at 3/26/2013 1:01:57 PM
At the like metre the wagers or baccarat, Snake eyes, roulette, But go to the sites that have these free one-armed bandit auto games and you precisely Snap and act as. http://www.tasty-onlinecasino.co.uk/ - online casino <a href="http://www.onlinecasinotaste.co.uk/">online casino</a> multitude with a pure sake in this cattle farm the dearest of gaming among the the great unwashed about. http://www.onlinecasinoburger.co.uk/

#25 By 1107599 (213.170.84.210) at 2/28/2014 3:15:38 AM
ООО «Престиж» осуществляет вывоз мусора в любых объемах по низким ценам и в кратчайшие сроки.
Вывоз мусора в СПб производится различными машинами ,исходя из ваших потребностей.
Работаем за наличный и безналичный расчет.
Заключаем договора, с предоставлением полного комплекта документов на вывоз и утилизацию мусора на полигонах.

Предлагаем вывоз мусора :
Вывоз мусора после замены окон (от 500 руб с услугами грузчиков)

Наша компания всегда готова к взаимовыгодному сотрудничеству.
Рассмотрим ваши пожелания и предложения.
Мы любим свою работу и ценим каждого клиента!

по тел +7(921)921-741-54-58
(812)959-88-19

Наш сайт <a href=http://www.zxcars.ru> http://www.zxcars.ru</a>

Write Comment
Return to News
  Displaying 1 through 25 of 329
Last | Next
  The time now is 5:48:11 PM ET.
Any comment problems? E-mail us
User name and password:

 

  *  
  *   *