Live data from Hacker News

Mozilla patches Firefox zero-day abused in the wild

zdnet.com

51–60 of 111 posts

Re: Mozilla patches Firefox zero-day abused in the wild

#51
post #50

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

wow... so I've had a comment downvoted because I've pointed out the obvious "conspiracy theory" in your comment. Glad you just attributed some random hack to a Firefox zero-day with zero proof and I'm the one told to fuck off. HN... jesus christ... this site.

I don't know why you are addressing me, I can't even downvote. Your "conspiracy theory" comment is certainly valid, unfortunately I'm not willing to provide more information so I suppose it will remain a "conspiracy theory" albeit one I believe is true.

Re: Mozilla patches Firefox zero-day abused in the wild

#52
post #8

Earlier quoted context omitted.

Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.

I get the annoyance with deprecating extensions. But seriously the main person you are harming by running vulnerable un-patched software is yourself. EDIT: s/the only person/the main person/

If only this was true. People with unpatched software running are prime targets for inclusion in a botnet and then they are damaging other with their reckless behavior.

Re: Mozilla patches Firefox zero-day abused in the wild

#53
post #47

Earlier quoted context omitted.

What about mobile versions? What about Beta, Developer, Nightly versions?

Firefox app on my Android phone was updated yesterday to 67.0.3, and the release notes mention the security fix.

There's more than one mobile version.

Latest Android Nightly build is 68.0a1 from 2019-05-04.

Latest Android Beta build is 68.0beta, from May 21, 2019 (actually from APK name it's 68.0b11).

Latest iOS Release build is 16.0, from April 15, 2019.

By the way, latest Desktop Beta build is 68.0beta, from May 22, 2019, and latest Desktop Nightly build is 69.0a1, from May 20, 2019 - and there's no information about whether they affected too.

Re: Mozilla patches Firefox zero-day abused in the wild

#54

Earlier quoted context omitted.

True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.

Mozilla was, Zdnet was not. https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...

The only additional information on that mozilla link is that the issue is "fixed in Firefox 67.0.3 and Firefox ESR 60.7.1". The only information about affected versions is that an unspecified set of "Firefox, Firefox ESR" are vulnerable.

The report doesn't include anything about which version introduced the bug. Is this a recent bug, or has it been around for many years? If it's old, is there any information available that might indicate how long malicious actors have been exploiting this vulnerability? Apparently the answer to the last question is "yes", as Mozilla claims that "We are aware of targeted attacks in the wild abusing this flaw." For how long? How many people might be affected?; "targeted" could mean a single individual or a very large group with some specifically targetable attribute.

There is a lot more to security than "just upgrade to the latest release". Also, while fears about public malicious actors learning from disclosure rarely outweigh the important benefits gained by allowing the public to defend themselves and learn form the incident, in this particular case where malicious actors are already exploiting the bug in the wild, there is little to be gained by keeping information hidden from the public.

Re: Mozilla patches Firefox zero-day abused in the wild

#55
post #10

Let's see how long it takes Fedora to deploy an update...

Being built already: https://koji.fedoraproject.org/koji/buildinfo?buildID=128978...

I'm grateful to QubesOS for being able to easily browse in a disposable VM whilst waiting for the build. Even without QubesOS starting a disposable VM manually is probably worth the effort..

Re: Mozilla patches Firefox zero-day abused in the wild

#56
post #43

The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?

Looks like nightly builds aren't being published. Even if you browse the directories manually, they're not there[1]. On google play[2] it's showing as updated, though.

[1] https://download-installer.cdn.mozilla.net/pub/mobile/nightl... although the ESR builds are coming in fine, so maybe something broke the build script?

[2] https://play.google.com/store/apps/details?id=org.mozilla.fe...

Re: Mozilla patches Firefox zero-day abused in the wild

#57

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..

What about that makes it sound targeted? Seems like standard vulnerabilities chained together, nothing specific to the "target"

Re: Mozilla patches Firefox zero-day abused in the wild

#59
post #43

The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?

I asked on twitter and they said nightly was not affected. https://mobile.twitter.com/FirefoxNightly/status/11411120523...

Re: Mozilla patches Firefox zero-day abused in the wild

#60
post #53

Earlier quoted context omitted.

Firefox app on my Android phone was updated yesterday to 67.0.3, and the release notes mention the security fix.

There's more than one mobile version. Latest Android Nightly build is 68.0a1 from 2019-05-04. Latest Android Beta build is 68.0beta, from May 21, 2019 (actually from APK name it's 68.0b11). Latest iOS Release build is 16.0, from April 15, 2019. By the way, latest Desktop Beta build is 68.0beta, from May 22, 2019, and latest Desktop Nightly build is 69.0a1, from May 20, 2019 - and there's no information about whether…

The iOS version should be unaffected, as Firefox for iOS does not include its own JS engine (it uses the one provided by the system), which is where this vulnerability is.

For the Desktop version at least, if you download the current beta (68.0beta11), you'll notice that it was built two days ago. The latest nightly was built today. The changelog for these is just not kept up to date.

Post reply on HN