Live data from Hacker News

Mozilla patches Firefox zero-day abused in the wild

zdnet.com

91–100 of 111 posts

Re: Mozilla patches Firefox zero-day abused in the wild

#91

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

Mozilla used to open up the security bugs after the fix is out for a while.

I say used to because I notice that the security issues fixed in Firefox 66.0 (released in March according to the release notes) still appear to be private. I suspect the internal people that cared about it have left, and their process is now broken. Somebody might read this thread and poke people to open access, but it would have to be done as an exceptional step (given that it hasn't been the first time I've noticed this happening).

Re: Mozilla patches Firefox zero-day abused in the wild

#92

Someone I know was hit by this in a very targeted attack on June 6th. They managed to capture the binary it dropped on their mac with some other gatekeeper bypass vulnerability (perhaps https://www.bleepingcomputer.com/news/security/new-unpatched... ). It is a mac port of the binary discussed in this research paper by Exatel: https://exatel.pl/advisory/paranoicy-raport-socexatel.pdf

Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..

if an attacker is porting the attack to Macs (presumably a lot of work)

It's worth noting that a professional security and pentest company I know of had a Python-based exploit authoring DSL that automatically generated exploit code across a very wide range of processor architectures and OSes. This was about fifteen years ago.

Re: Mozilla patches Firefox zero-day abused in the wild

#93
post #54

Earlier quoted context omitted.

Mozilla was, Zdnet was not. https://www.mozilla.org/en-US/security/advisories/mfsa2019-1...

The only additional information on that mozilla link is that the issue is "fixed in Firefox 67.0.3 and Firefox ESR 60.7.1". The only information about affected versions is that an unspecified set of "Firefox, Firefox ESR" are vulnerable. The report doesn't include anything about which version introduced the bug. Is this a recent bug, or has it been around for many years? If it's old, is there any information availabl…

What right would the Firefox team have to invade the privacy of the "target" to detail who they are to the Internet as a whole?

HN users frequently complain that "automatically check for updates" is somehow an invasion of privacy. Meeting your demand, revealing the target of an attack publicly, would certainly be an invasion of privacy — one a thousand times more trust-violating than any auto-update check could be.

What of your needs is met by making such a request? What is your direct and personal benefit from knowing the target of the attack? Why are you willing to sacrifice the privacy of that target for that personal benefit?

Re: Mozilla patches Firefox zero-day abused in the wild

#94
post #10

Let's see how long it takes Fedora to deploy an update...

Are you implying that Fedora has some history of being slow to update security vulnerabilities?

No, just genuine curiosity since I use Fedora systems and updating manually is much more work.

Re: Mozilla patches Firefox zero-day abused in the wild

#95
post #89

Earlier quoted context omitted.

Can't really test from my phone, but isn't pressing and releasing the Alt key still a shortcut for displaying a menu bar if one exists?

Yes, on Windows.

Are there not comparable or identical shortcuts for keyboard users on most nix boxes and Macs? I admit to not being up to speed on Command/Option/Splat Mac shortcuts, but I wouldn't have expected the chrome to diverge that much between systems from a common code base.

Re: Mozilla patches Firefox zero-day abused in the wild

#96
post #45

Earlier quoted context omitted.

$ snap info firefox ... channels: stable: 67.0.3-1 2019-06-18 (230) 221MB - It is already available to use.

I've looked at moving to the snap before but last I heard there's no way to import your current profile? And netflix doesn't work? If those two things are fixed I'd happily change over!

For the former, I would imagine `rsync -Pav $whatever_old_ff_profile/ $HOME/snap/firefox/whatever/` would do that, since AFAIK snaps store user-specific persistent state outside of privileged directories

The alternative, and likely why no one has applied a great deal of pressure to that workflow, is to use the Firefox Sync account they've been pushing so hard

Re: Mozilla patches Firefox zero-day abused in the wild

#97

Earlier quoted context omitted.

Sounds extremely targeted, if an attacker is porting the attack to Macs (presumably a lot of work), and combining it with other loaders... I wonder how long this 0-day was in the wild. Your friend should probably be browsing as a non-admin in a continuously-reimaged VM, separate from an air-gapped machine, if you have those kinds of attackers after you. Spooky..

if an attacker is porting the attack to Macs (presumably a lot of work) It's worth noting that a professional security and pentest company I know of had a Python-based exploit authoring DSL that automatically generated exploit code across a very wide range of processor architectures and OSes. This was about fifteen years ago.

It's worth noting that a professional security and pentest company I know of had a Python-based exploit authoring DSL that automatically generated exploit code across a very wide range of processor architectures and OSes.

Makes sense. If entire OSes can be written in an intermediate representation, then exploits can be as well.

Re: Mozilla patches Firefox zero-day abused in the wild

#98
post #45

Earlier quoted context omitted.

$ snap info firefox ... channels: stable: 67.0.3-1 2019-06-18 (230) 221MB - It is already available to use.

I've looked at moving to the snap before but last I heard there's no way to import your current profile? And netflix doesn't work? If those two things are fixed I'd happily change over!

Netflix for me works fine. You just need to tick the 'Play DRM content' setting.

My personal reason to use the snap is because it limits access to the home directory. So I can disconnect my home directory, camera and microphone and have a second layer of confidence that my browser won't leak any personal data.

That and it avoids Firefox leaking config files in my home directory.

If I want to upload a file, I simply move the file into a Downloads folder in it's SNAP home directory. This way, Im in control of what the browser can access.

Re: Mozilla patches Firefox zero-day abused in the wild

#99
post #91

https://bugzilla.mozilla.org/show_bug.cgi?id=1544386 I find it really gross that they do not allow others to access it. This behavior damages the forks.

Mozilla used to open up the security bugs after the fix is out for a while. I say used to because I notice that the security issues fixed in Firefox 66.0 (released in March according to the release notes) still appear to be private. I suspect the internal people that cared about it have left, and their process is now broken. Somebody might read this thread and poke people to open access, but it would have to be done…

The same people who were in charge of opening up security bugs are still around and still in charge of it.

Security bugs are opened up once in-the-wild usage of affected versions is low enough, if I recall correctly. This usually takes a while after the fix is shipped. At no point were bugs opened up immediately after the Firefox release with the fix shipped. It's usually a year or so between the fix being shipped and the bug getting opened up, in my experience.

Re: Mozilla patches Firefox zero-day abused in the wild

#100
post #10

Let's see how long it takes Fedora to deploy an update...

It's easy to get mad at Fedora when we don't have the latest-greatest at the time the announcement drops. But they hold the packages so that they can do additional QA beyond what Mozilla has already done and protect their users. I'm sometimes disappointed, but after seeing some of the bugs they've caught during the Fedora-specific testing/QA builds, I can understand why they do it.

Delaying zero-day security patches for any length of time doesn't protect users.
Post reply on HN