<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
><channel><title>M32 Security &#187; mozilla</title> <atom:link href="http://m32consulting.com/tag/mozilla/feed/" rel="self" type="application/rss+xml" /><link>http://m32consulting.com</link> <description>Network Security Info, News, and Resources</description> <lastBuildDate>Sun, 22 Jan 2012 23:37:02 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <item><title>New rogue AV targets Firefox users as bogus Flash update</title><link>http://m32consulting.com/2010/07/new-rogue-av-targets-firefox-users-as-bogus-flash-update/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=new-rogue-av-targets-firefox-users-as-bogus-flash-update</link> <comments>http://m32consulting.com/2010/07/new-rogue-av-targets-firefox-users-as-bogus-flash-update/#comments</comments> <pubDate>Thu, 29 Jul 2010 04:31:36 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Uncategorized]]></category> <category><![CDATA[firefox]]></category> <category><![CDATA[flash update]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[mozilla]]></category> <category><![CDATA[rogue av]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=111</guid> <description><![CDATA[It seems the makers of the all-too-familiar-now rogue AV are now targeting the more web-saavy of users; those who use Mozilla Firefox. Recent versions of Firefox have been taking a more proactive approach to keeping Adobe Flash secure by checking the version of Flash installed and informing users that they need to upgrade Flash to [...]]]></description> <content:encoded><![CDATA[<p>It seems the makers of the all-too-familiar-now rogue AV are now targeting the more web-saavy of users; those who use Mozilla Firefox.</p><p>Recent versions of Firefox have been taking a more proactive approach to keeping Adobe Flash secure by checking the version of Flash installed and informing users that they need to upgrade Flash to a newer version if it is outdated. Simple enough. Perhaps too simple.</p><p>Now the makers of the familiar fake Windows Security Alert con and the bogus Anti-Virus malware have begun to craft webpages that look identical to the page that appears after users have started a freshly-upgraded version of Firefox, except they now have to upgrade Adobe Flash. It doesn&#8217;t require the user to click on a download link; it tries to start a download immediately upon page load.</p><p>Naturally users will download the legitimate looking executable and run it upon completion. In all, it is a very convincing tactic with a pretty flawlessly executed plan besides the URL being not that of a Mozilla Firefox owned domain. Of course, it isn&#8217;t a newer version of Flash. It&#8217;s the good &#8216;ol rogue AV that has been creeping into every corner of the web by any means possible, doing all the nasty things it always does. Security vendors are already aware of the threat and rolling out definition updates to detect and thwart this attack.</p><p><a
href="http://www.f-secure.com/weblog/archives/00001997.html" target="_blank">More on it over at F-Secure with screenshots</a></p>Tags: <a
href="http://m32consulting.com/tag/firefox/" title="firefox" rel="tag">firefox</a>, <a
href="http://m32consulting.com/tag/flash-update/" title="flash update" rel="tag">flash update</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/mozilla/" title="mozilla" rel="tag">mozilla</a>, <a
href="http://m32consulting.com/tag/rogue-av/" title="rogue av" rel="tag">rogue av</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2010/07/new-rogue-av-targets-firefox-users-as-bogus-flash-update/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>When security software becomes the malware itself</title><link>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=when-security-software-becomes-the-malware-itself</link> <comments>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/#comments</comments> <pubDate>Sat, 02 May 2009 08:19:20 +0000</pubDate> <dc:creator>Kyle</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Software]]></category> <category><![CDATA[blocking software]]></category> <category><![CDATA[bug reports]]></category> <category><![CDATA[developers]]></category> <category><![CDATA[faithful users]]></category> <category><![CDATA[friedrich nietzsche]]></category> <category><![CDATA[malware]]></category> <category><![CDATA[mozilla]]></category> <category><![CDATA[noscript]]></category> <category><![CDATA[outrage]]></category> <category><![CDATA[security software]]></category> <category><![CDATA[self interest]]></category> <category><![CDATA[viruses]]></category><guid
isPermaLink="false">http://m32consulting.com/?p=17</guid> <description><![CDATA[&#8220;Be careful when you fight the monsters, lest you become one.&#8221; -Friedrich Nietzsche The developers of popular Mozilla extension AdBlock Plus had been receiving bug reports of &#8220;issues&#8221; with another popular extension, NoScript, after an update was issued by the developer of the script-blocking software. The AdBlock Plus developers decided to take a look into [...]]]></description> <content:encoded><![CDATA[<blockquote><p>&#8220;Be careful when  you fight the monsters, lest you become one.&#8221; -<strong>Friedrich Nietzsche</strong></p></blockquote><p>The developers of popular Mozilla extension AdBlock Plus had been receiving bug reports of &#8220;issues&#8221; with another popular extension, NoScript, after an update was issued by the developer of the script-blocking software. The AdBlock Plus developers decided to take a look into what was wrong and found something extremely disturbing. The 1.9.2 update of NoScript had incorporated an obfuscated piece of code that actually made changes to AdBlock Plus to allow for ads on the NoScipt and related sites to be shown. In otherwords, it does what a viruses and other malware does to antivirus software only in reverse; instead of blocking access to update sites, it forced AdBlock Plus to allow ads to be shown for the developer&#8217;s site explicitly. This most likely would have flown under the radar had it not completely broken Adblock Plus and get caught doing unethical things to other software for self-interest. The issue snowballed when the issue made it to Reddit and caused an outrage amongst faithful users of both extensions. To make things worse, the developer only slightly backtracked; allowing the user to allow or disallow the code modification upon installation of NoScript. The developer eventually removed the code completely in version 1.9.2.6, but not without severely impacting user opinion of the software and spurring discussion of a policy change regarding Mozilla Extensions.</p><p>More after the jump.</p><p><a
href="http://adblockplus.org/blog/attention-noscript-users" target="_blank" class="broken_link">http://adblockplus.org/blog/attention-noscript-users</a></p>Tags: <a
href="http://m32consulting.com/tag/blocking-software/" title="blocking software" rel="tag">blocking software</a>, <a
href="http://m32consulting.com/tag/bug-reports/" title="bug reports" rel="tag">bug reports</a>, <a
href="http://m32consulting.com/tag/developers/" title="developers" rel="tag">developers</a>, <a
href="http://m32consulting.com/tag/faithful-users/" title="faithful users" rel="tag">faithful users</a>, <a
href="http://m32consulting.com/tag/friedrich-nietzsche/" title="friedrich nietzsche" rel="tag">friedrich nietzsche</a>, <a
href="http://m32consulting.com/tag/malware/" title="malware" rel="tag">malware</a>, <a
href="http://m32consulting.com/tag/mozilla/" title="mozilla" rel="tag">mozilla</a>, <a
href="http://m32consulting.com/tag/noscript/" title="noscript" rel="tag">noscript</a>, <a
href="http://m32consulting.com/tag/outrage/" title="outrage" rel="tag">outrage</a>, <a
href="http://m32consulting.com/tag/security/" title="Security" rel="tag">Security</a>, <a
href="http://m32consulting.com/tag/security-software/" title="security software" rel="tag">security software</a>, <a
href="http://m32consulting.com/tag/self-interest/" title="self interest" rel="tag">self interest</a>, <a
href="http://m32consulting.com/tag/viruses/" title="viruses" rel="tag">viruses</a><br
/> ]]></content:encoded> <wfw:commentRss>http://m32consulting.com/2009/05/when-security-software-becomes-the-malware-itself/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced
Database Caching 7/24 queries in 0.019 seconds using disk: basic
Object Caching 1054/1088 objects using disk: basic

Served from: m32consulting.com @ 2012-02-11 17:10:15 -->
