This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
Related links
- Hacking Tools For Games
- Pentest Tools
- Pentest Tools Download
- Pentest Tools Apk
- Hacker Tools For Windows
- Hacking Tools Free Download
- Hacker Tools Github
- Pentest Tools Subdomain
- Hacker Tool Kit
- Hacker Tools Linux
- Pentest Tools Find Subdomains
- Hacking Tools Name
- Pentest Tools Github
- Pentest Tools Windows
- Hackrf Tools
- Hack Tools
- Hack Tools 2019
- Pentest Reporting Tools
- Hacking Tools 2019
- Pentest Tools Find Subdomains
- Hacker Tools Free
- Hack Tools For Windows
- Hack Apps
- Hacking Tools For Games
- Hack Tools
- Pentest Tools Linux
- Hacker
- Hacking Tools 2019
- Pentest Tools Free
- Wifi Hacker Tools For Windows
- What Are Hacking Tools
- Hack Website Online Tool
- Hacking Tools Windows 10
- Hacker
- Hacker Tools List
- Hacker Tools Mac
- Hack App
- Hacking Tools And Software
- Hacking Tools For Windows Free Download
- Hack Tools
- Pentest Tools Subdomain
- Hak5 Tools
- Game Hacking
- Hacking Tools For Mac
- Hacker Tools For Mac
- Best Hacking Tools 2019
- Tools Used For Hacking
- Hacking Tools 2019
- Pentest Tools Online
- Hack Tools Pc
- Hacker Tools List
- Free Pentest Tools For Windows
- Computer Hacker
- Hacker Tool Kit
- Hacking Tools For Beginners
- Pentest Tools Alternative
- Hack Tools For Games
- Top Pentest Tools
- Pentest Tools Framework
- Hacker Tools List
- Pentest Tools Online
- Pentest Tools Github
- Underground Hacker Sites
- Pentest Tools Website Vulnerability
- Pentest Tools
- Hacker Tools For Mac
- Pentest Tools Review
- Hacker Tool Kit
- Pentest Tools Alternative
- Github Hacking Tools
- Hacker Tools Free Download
- Hacker Tools Software
- Kik Hack Tools
- Hacking Tools Github
- Hacking Tools 2019
- Hacking Tools Github
- Hack Apps
- What Are Hacking Tools
- Hacker Tools For Windows
- Pentest Tools Website
- Pentest Tools Online
- Termux Hacking Tools 2019
- Hack Tools
- Hacker Tools For Windows
- Hacking Tools Usb
- Hacker Tools Apk Download
- Hacking Tools Download
- Usb Pentest Tools
- Pentest Tools Windows
- Pentest Tools Download
- Hacker Tools Hardware
- Hacking Tools Software
- Hacking Apps
- Hacking Apps
- Hacking Tools Name
- Hacker Tools
- Hack Tools Github
- Hacker Tools Apk
- Computer Hacker
- Kik Hack Tools
- Hack Apps
- Pentest Tools Subdomain
- Hacking Tools
- Hack Tools For Windows
- Hacking Tools Online
- Pentest Tools Review
- Hacking Tools For Windows 7
- Install Pentest Tools Ubuntu
- Hacking Tools For Pc
- How To Hack
0 comments:
Post a Comment