Showing posts with label Browser Extensions. Show all posts
Showing posts with label Browser Extensions. Show all posts

Wednesday, 4 November 2015

MacUpdate.com Provides Downloads Of Adware


A download site where Mac users can download software shows offered all kinds of apps like Skype, Firefox and 1Password to provide adware. The adware is in an installer. It is includes a "wrapper" that other apps in addition to the required software.

Users can be allowed to see the user agreement, but will ignore most users, says Thomas Reed of anti-malware company Malwarebytes. If it is for the "Quick" system chosen by the user in addition to the software you also get a browser extension and the browser settings are adjusted. According to Reed let many adware installers today see this behavior.

MacUpdate also the wrapper would install a program called MacBooster. Reed says that other download sites such as Download.com and Softonic exhibit this kind of behavior and Mac experts therefore advise you to avoid these types of websites. Mac users are therefore advised only apps from the Mac App Store, or the official website to download from the supplier, and to avoid external download sites.

Saturday, 10 October 2015

Firefox Stops Java Support, But Flash Continues To Support


Like Google and Microsoft will also stop supporting Mozilla based on NPAPI plug-ins, but for Adobe Flash Player is an exception. According to Mozilla are plug-ins that the old Netscape Plug-in API (NPAPI) use responsible for performance issues, crashes and security incidents.

End 2016 Mozilla also wants to stop the support for most NPAPI plugins in Firefox. A process that was initiated some years ago, by letting users activate these plug-ins manually. In addition, the new 64-bit Firefox for Windows platform will be launched entirely without support plug-ins, because it is no longer needed by the browser developer.

Because Adobe Flash Player on so many websites use Mozilla continues this plug-in, as an exception to the rule, do support. "Mozilla and Adobe will continue to work to make improvements to the Flash experience within Firefox, among others in terms of stability and performance, and security features," said Mozilla's Benjamin Smedberg.

Java

He advises websites that use plugins such as Silverlight and Oracle Java to switch to web technologies. These plug-ins will be late next year would no longer supported. In the event websites can not be without, for example Java advised to develop the required features as a Firefox extension. In order to end of Java within Firefox run smoothly cooperates with Oracle there. So advises Oracle now on websites instead of Java applets, plug-in free solution such as Java Web Start to use.

Saturday, 22 August 2015

Mozilla's Chrome Extensions Support In Firefox


Mozilla has announced major changes to the operation of add-ons in Firefox, including the possibility of later extensions for Google Chrome and Opera and possibly Microsoft Edge will work in the browser. In addition, measures are being taken against spyware, adware and other malicious add-ons.

According to Mozilla developers have much of a Firefox add-on also similar extensions for Chrome, Safari, Opera or developed. "We want the development of add-ons is more like web development, that same code using a set of standards across multiple browsers running," said Mozilla's Kev Needham. That is why Mozilla is working on a new API called Firefox WebExtensions.

Extensions for Chrome, Opera and possibly in the future, Microsoft Edge will therefore run in Firefox as Webex Tension.According to Needham, the API a number of advantages, such as supporting multiple processes and reducing the risk of malicious add-ons and malware. WebExtensions will like other Firefox add-ons work with Mozilla are signed and via addons.mozilla.org to find. A test version of WebExtensions is already available in the test version of Firefox 42.

Signings

To protect users from malicious add-ons from Firefox 42 will all extensions must be checked by Mozilla and signed. Unsigned extensions will not work in Firefox. From 41 unsigned Firefox extensions will be automatically disabled, but users still have the ability to turn back.

According to Needham, the strategy of Mozilla advantages and disadvantages. Developers who already support Chrome extension will benefit from it, because they now have only one code base support instead of two. For developers who develop only Firefox add-ons adjustment will be greater. "But we think that the end result for both users and developers of Firefox it will be worth it," said Needham.

Friday, 21 August 2015

Adware Changing Settings Adblock Plus For Mac OS X



Adblock Plus is the most installed browser extension the world, with tens of millions of users. All of these users will not see ads, something that adware developers now have gotten through. Security company Webroot recently discovered copies of the VSearch- and adware Genieo for Mac OS X that adjust settings Adblock Plus.

For this, the Mac user, the first adware already installed on your system. Once active monitors adware or a AdBlocker the system is present and then add an exception, so the ads from adware still be displayed. According to Webroot's most malware for Mac OS X which it encounters adware, which displays all kinds of ads. Earlier this year, Mac users were already adware warned. Users become infected mainly because software outside the site of the supplier or downloading illegal software use.

Saturday, 8 August 2015

Chrome Will Block Deceptive Inline Installations



To protect Chrome users from unwanted extensions, Google has announced a new measure. From September, the browser inline installations of extensions that originate block of misleading websites and advertisements.

Inline systems were introduced in 2011 as a way to easily install extensions from the website of a developer. The mechanism is now used by Web sites to trick users into installing unwanted extensions. So users can get a pop-up stating that they need to update their Flash Player to view the video. However, the pop-up does not point to Flash Player, but an inline installation of another extension.

According to Google unwanted extensions are a major annoyance for users and a major source of complaints. In recent years, the company decided to take several measures. Blocking of inline installations, there is one of them. The blockade starts on September 3rd. In this case, Chrome will block the installation and users can now send it to the Chrome Web Store, so they can decide as to whether or not to install the extension. The new measure would affect less than 0.2% of all extensions, but it is an important measure to keep the extension ecosystem healthy, says Andrew Kim from Google.

Friday, 10 July 2015

LastPass For Firefox Vulnerable To Password Theft



A vulnerability in the popular online password manager LastPass allows attackers to steal passwords. The problem was present in LastPass for Google Chrome and Internet Explorer, but it is solved. Only the Firefox version is currently still leak.

LastPass is a popular cloud service where users their passwords for various websites and services in a "safe" to store. The software comes in the form of an add-on for the browser. Security Researcher Matthew Bryant discovered that the browser extension is vulnerable to clickjacking. These attackers can "click" by a user hijack and use it for other purposes.

A malicious website can the window to automatically fill in passwords from an "overlay" feature and thus steal the password of users and which may be tempted to copy and paste their passwords. The attack only works on sites that do not use the X-Frame-Options header. This header can be used to determine whether a browser a page in a frame, iframe, and may display object. Websites can use the header to prevent their content on other websites is embedded, and prevent clickjacking attacks.

Warning

Bryant warned LastPass on April 3 this year. On April 22, the Chrome version of LastPass patched. Eventually there appeared an update for the IE version. Although LastPass developers also developed a patch for the Firefox version and put it to Mozilla, the patch is still not verified by Mozilla. Something that, according Bryant is the scariest of the leak. "It is worrying that require security updates for Mozilla add-ons months to reach the user. It has definitely changed my view on Firefox from a security perspective," he notes. For demonstration made the researcher video below.

Update

The criticism of Bryant seems on reflection unfounded as there is on 24 April this year published an update to the Firefox version that measures have been taken to prevent the attack which the researcher describes. We've Bryant asked for comment that the problem is indeed in this version, with the number 1.3.95 is resolved.

Bryant states that the version offered by LastPass on the website is patched, but the version offered is still vulnerable through addons.mozilla.org. Users would then have to manually install the new version to be protected.

Bryant says that Mozilla Firefox approved the final version July 6, after his revelation and criticism had revealed the slow approval process on 1 July. In addition, it logs erroneously that the version would be available since April 24, while the end of June is still vulnerable version was offered.