New Firefox Attack

New Firefox based attack.

Meanwhile back in IE land, same ol’ same ol’. The never ending story.

Just some news.


Thats why you need to have your browser sandboxed ;D No matter what the browser.

Thanks for the news (bad news :D)


I am not sure that any SandBoxing may help here 88)

That is about accessing ports
You are using browser and “going out”
How SandBox can prevent from joining networks and flooding /spamming channels?


Mitigated by NoScript extension.

Or if you use Linux, via iptables as discussed in the following article.

This is far different to Internet Explorer, where an exploit there leads to a system compromise!

Yup No-Script is one of the best, if not the best thing to use along with Firefox. Either way, I never use IRC anyway.

As it was pointed in some discussions in this forum and in “other places” - all of the existing browsers have security holes that can be found and exploited
at the same time if you compare the the frequency; severity of those and time it takes to respond I cannot imagine how some users are considering IE being safe (I’ve even seen the the remark in the forum - “the safest browser” :o)

As far as I got it you should not necessarily use IRC - you are joining… unwillingly, and after that you are not chatting per se …

Please correct me if I’m wrong


If I understand correctly, using the Comodo Firewall and configuring Firefox’s Network Security Policy as “web browser” prevents Firefox from access ports other than HTTP, FTP and DNS.

I also like NoScript


But instead of NoScript i prefer

psexec.exe -l -d "C:\Program Files\Mozilla Firefox\firefox.exe"

to drop admin privileges of Ff on admin account in order to prevent more serious malicious scripts doing harm to the system (as Ff is trusted by Defense+ it will allow it to do anything in Safe mode).

You should specify, everyone does not know about it, that psexec is not a windows default executable but part of the sysinternal pstools.

I see no reason to use it in such a situation, as everyone should run everything under limited account.

And i don’t see either why Firefox should be globally trusted by defense+.

I’ve uploaded the attack code for the firefox attack( To comodo) a while ago. If your using Comodo’s anti-virus then your safe. If firefox finally fixed it that would even be better

I also remove the link to the code in malware research group here (for those that have access to it) after comodo got the copy of it. So please don’t ask me for it :slight_smile: