ghacks Technology News

0-Day Firefox 3.6 Vulnerability Emerges

The official Nobel Prize website was hacked yesterday, and for some time ran an exploit targeting a new 0-day vulnerability in the Firefox browser. According to our information, the exploit was used to install a backdoor on the user’s computer system without notifications or warning messages.

The backdoor tries to retrieve the path of the Windows directory to copy the file symantec.exe to %WINDIR%\temp\symantec.exe. Once the file is created there, autostart keys are added to the Windows Registry to load the file on system startup. The keys are added both to the user and local machine parts of the Registry, and the reg command is used to add them.

The program then tries to create two connections to Internet servers, namely to nobel..mooo.com and update.microsoft.com. After these initial connections it tries to connect to two additional servers, both of which appear to be offline currently. If they are offline, the malware stops executing and exits.

On a successful connection, the malware opens a shell and the attacker can access the local computer with the same rights the malware was executed with.

Mozilla appears to be aware of the vulnerability and is developing a patch to protect the browser from the vulnerability. (via)

Update: Office Mozilla Response Up, suggest to disable JavaScript to protect the browser from the vulnerability.

Related Articles:

Another Critical Firefox Vulnerability Emerges
Here We Go Again: Yet Another Flash 0-day Vulnerability Emerges
Windows 7 64-bit And Windows Server 2008 R2 Vulnerability Emerges
Another Adobe Reader Zero-Day Vulnerability Emerges
New Google Mail Security Vulnerability Emerges

Enjoyed the article?: Then sign-up for our free newsletter or RSS feed to kick off your day with the latest technology news and tips, or share the article with your friends and contacts on Facebook, Twitter or Google+ using the icons below.



About the Author:Martin Brinkmann is a journalist from Germany who founded Ghacks Technology News Back in 2005. He is passionate about all things tech and knows the Internet and computers like the back of his hand. You can follow Martin on Facebook or Twitter.

Author: , Wednesday October 27, 2010 -
Tags:, , ,


Responses so far:

  1. Transcontinental says:

    Thanks for following developments of this new intruder and letting us know what the malware scheme is like. Internet a 24/7/365 combat, but worth it.

  2. Jojo says:

    Mike Lin’s old (free) Startup Monitor would seem to be of help here. It monitors attempts to add entries to the run/start keys and allows you to say yes or no.

    IMO, this is an essential program to run:
    http://www.mlin.net/StartupMonitor.shtml

  3. B. Moore says:

    if wan’t to know more about it listen to Securrity Now with Steve Gibson & Leo Laporte.

    http://Twit.tv/sn Episode 272: Firesheep

    They are recording the show live as I type this, it should be available to download later tonight.

  4. Anonymous says:

    Versions 3.5.15/3.6.12 are out.

  5. Transcontinental says:

    The Firefox team made it fast ‘n’ clear! – Nice job.

Leave a Reply   Follow Ghacks   Subscribe To Comment Rss

Subscribe without commenting

© 2005-2012 Ghacks.net. All Rights Reserved. Privacy Policy - About Us