Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
wow... so I've had a comment downvoted because I've pointed out the obvious "conspiracy theory" in your comment. Glad you just attributed some random hack to a Firefox zero-day with zero proof and I'm the one told to fuck off. HN... jesus christ... this site.
Mozilla patches Firefox zero-day abused in the wild
51–60 of 111 posts
Re: Mozilla patches Firefox zero-day abused in the wild
#52Earlier quoted context omitted.
Please do not assume people are not running current release just because they are lazy and have not upgraded. The user experience was degraded at FF57 for many individuals who need extensions that will not work with ff>56 or that developers have abandoned out of frustration with Mozilla. When all the extensions I find necessary are functional (or with suitable replacements) I will switch.
I get the annoyance with deprecating extensions. But seriously the main person you are harming by running vulnerable un-patched software is yourself. EDIT: s/the only person/the main person/
Re: Mozilla patches Firefox zero-day abused in the wild
#53Earlier quoted context omitted.
What about mobile versions? What about Beta, Developer, Nightly versions?
Firefox app on my Android phone was updated yesterday to 67.0.3, and the release notes mention the security fix.
Latest Android Nightly build is 68.0a1 from 2019-05-04.
Latest Android Beta build is 68.0beta, from May 21, 2019 (actually from APK name it's 68.0b11).
Latest iOS Release build is 16.0, from April 15, 2019.
By the way, latest Desktop Beta build is 68.0beta, from May 22, 2019, and latest Desktop Nightly build is 69.0a1, from May 20, 2019 - and there's no information about whether they affected too.
Re: Mozilla patches Firefox zero-day abused in the wild
#54Earlier quoted context omitted.
True they could have been clearer on the versions affected, but tbh you should keep with the latest supported anyway. Security bug reports are often restricted for some time after a new release to help prevent reverse engineering to find the bug.
Mozilla was, Zdnet was not. https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...
The report doesn't include anything about which version introduced the bug. Is this a recent bug, or has it been around for many years? If it's old, is there any information available that might indicate how long malicious actors have been exploiting this vulnerability? Apparently the answer to the last question is "yes", as Mozilla claims that "We are aware of targeted attacks in the wild abusing this flaw." For how long? How many people might be affected?; "targeted" could mean a single individual or a very large group with some specifically targetable attribute.
There is a lot more to security than "just upgrade to the latest release". Also, while fears about public malicious actors learning from disclosure rarely outweigh the important benefits gained by allowing the public to defend themselves and learn form the incident, in this particular case where malicious actors are already exploiting the bug in the wild, there is little to be gained by keeping information hidden from the public.
Re: Mozilla patches Firefox zero-day abused in the wild
#55Let's see how long it takes Fedora to deploy an update...
Being built already: https://koji.fedoraproject.org/koji/buildinfo?buildID=128978...
Re: Mozilla patches Firefox zero-day abused in the wild
#56The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?
[1] https://download-installer.cdn.mozilla.net/pub/mobile/nightl... although the ESR builds are coming in fine, so maybe something broke the build script?
[2] https://play.google.com/store/apps/details?id=org.mozilla.fe...
Re: Mozilla patches Firefox zero-day abused in the wild
#57Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf
Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..
Re: Mozilla patches Firefox zero-day abused in the wild
#58Re: Mozilla patches Firefox zero-day abused in the wild
#59The last Nightly Firefox build for Android to date is 68.0.a1 from 2019-05-04. https://www.mozilla.org/en-US/firefox/android/nightly/all/ Does it contain the fix?
Re: Mozilla patches Firefox zero-day abused in the wild
#60Earlier quoted context omitted.
Firefox app on my Android phone was updated yesterday to 67.0.3, and the release notes mention the security fix.
There's more than one mobile version. Latest Android Nightly build is 68.0a1 from 2019-05-04. Latest Android Beta build is 68.0beta, from May 21, 2019 (actually from APK name it's 68.0b11). Latest iOS Release build is 16.0, from April 15, 2019. By the way, latest Desktop Beta build is 68.0beta, from May 22, 2019, and latest Desktop Nightly build is 69.0a1, from May 20, 2019 - and there's no information about whether…
For the Desktop version at least, if you download the current beta (68.0beta11), you'll notice that it was built two days ago. The latest nightly was built today. The changelog for these is just not kept up to date.