Live data from Hacker News

Mozilla patches Firefox zero-day abused in the wild

zdnet.com

31–40 of 111 posts

Re: Mozilla patches Firefox zero-day abused in the wild

#31

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

The source code for the fix is public. Presumably the bug report includes working exploit code. I don't see how this is "damaging" for forks.

It is important to also understand what causes the issue, how it was exploited, etc. Plus I am pretty sure that they had the bug report before the fix was released.

Re: Mozilla patches Firefox zero-day abused in the wild

#33

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

[deleted]

Re: Mozilla patches Firefox zero-day abused in the wild

#35

Earlier quoted context omitted.

The source code for the fix is public. Presumably the bug report includes working exploit code. I don't see how this is "damaging" for forks.

It is important to also understand what causes the issue, how it was exploited, etc. Plus I am pretty sure that they had the bug report before the fix was released.

Are there any fork that modifies Firefox so thoroughly that one needs a context to patch SpiderMonkey?

Re: Mozilla patches Firefox zero-day abused in the wild

#36

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

It's just hearsay, buddy.

You can't be sure the same bug was exploited.

Re: Mozilla patches Firefox zero-day abused in the wild

#37

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild.

Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..

Re: Mozilla patches Firefox zero-day abused in the wild

#38

It's in moments like this where I really dislike running Ubuntu and having to wait for the new build to be released.

Consider trying the debian package until it is updated in your system.

Currently in incoming btw:

https://incoming.debian.org/debian-buildd/pool/main/f/firefo...

Re: Mozilla patches Firefox zero-day abused in the wild

#39
post #8

Earlier quoted context omitted.

True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.

Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.

If you don't want Firefox Quantum, you should still switch to a supported browser that kept XUL, such as Basilisk.

Also I'm curious, what extensions are missing? Most of my pre-quantum extensions, such as Tree Style Tabs, have been updated now.

Re: Mozilla patches Firefox zero-day abused in the wild

#40

Earlier quoted context omitted.

Mozilla can still give access for the developers of forks without opening it to the public before they (and the forks!) have managed to rollout a full update.

Anyone can run a fork though, I right now might be running my personal fork. This is part of the point of free software. Plus, you assume that the select few developers that are given the exploit information are trustworthy. The exploit being public from the first day is better than if even a single developer is untrustworthy or compromised.

I don't understand this logic. It's better to have everyone see it and to guarantee it is seen by a malicious actor, instead of only a small few seeing it and there being some small potential for it to be seen by a malicious actor?
Post reply on HN