<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Mate Varga &#187; Internet</title>
	<atom:link href="http://www.matevarga.com/topics/home/internet/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.matevarga.com</link>
	<description>Words. You are reading them.</description>
	<lastBuildDate>Fri, 16 Sep 2011 11:24:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Firefox Gone Wild</title>
		<link>http://www.matevarga.com/firefox-gone-wild/</link>
		<comments>http://www.matevarga.com/firefox-gone-wild/#comments</comments>
		<pubDate>Mon, 30 Nov 2009 14:08:13 +0000</pubDate>
		<dc:creator>Máté Varga</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Rants]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.matevarga.com/?p=66</guid>
		<description><![CDATA[After spending the better half of two days scraping a rootkit off my fiancee&#8217;s system, I think I need to reevaluate my position on Firefox being the safest browser ever. While browsing some fairly innocuous sites (artsy sites she frequents), she somehow managed to infect her entire system &#8211; in a matter of seconds &#8211; [...]]]></description>
			<content:encoded><![CDATA[<p><img class="size-thumbnail wp-image-67 alignleft" title="Firefox Hurts" src="http://www.matevarga.com/wp-content/uploads/2009/11/firefox_hurts-150x150.png" alt="Firefox Hurts" width="111" height="111" /> After spending the better half of two days scraping a rootkit off my fiancee&#8217;s system, I think I need to reevaluate my position on <em>Firefox being the safest browser ever</em>. While browsing some fairly innocuous sites (artsy sites she frequents), she somehow managed to infect her entire system &#8211; in a matter of seconds &#8211; with some very nasty malware. This is what we call, drive-by-downloading &#8211; simply visiting an infected website and utterly compromising your system.</p>
<p><span id="more-66"></span></p>
<h1>Firefox, Not So Safe</h1>
<p>As Firefox becomes more prevalent, so do the exploits. Going back a few years, it wasn&#8217;t hard to entice us all with a browser that did such nifty tricks as stopping pop-up advertisements, not being so laughably exploitable and just plain performing faster. There were a few performance and security hiccups along the way, but overall, we were happy.</p>
<p>Early on, exploiting Firefox was left to hacker conferences where large bearded men with Linux laptops wrote complex proof-of-concept hacks to break through the boundaries of <strong>Firefox</strong> and <strong>System</strong>. Fundamentally, however, even the average user was safe from himself with Firefox. As popularity grew, malware authors began to take notice.</p>
<p>Browser development is akin to operating system development. It is terribly complex and tedious to develop. Just breaking into the market is difficult enough &#8211; even as I write this, a television somewhere is playing a Google Chrome ad. As complexity grows, so do the vulnerabilities &#8211; and someone, somewhere will have time/incentive/moral ambiguity to find and exploit them. The more eyes you have searching, the faster this process becomes.</p>
<p>Unfortunately, Firefox wasn&#8217;t written by cybernetic foxes from future. No, they were written by fallible humans who have had gone to bed at 5am the previous night because they had ran <a title="Oh Lawl" href="http://www.youtube.com/watch?v=5ilGGP9BDZs">out of coffee</a>. As a result, bugs and vulnerabilities are bound to occur. And while the Mozilla team are very good about releasing frequent patches, there always seem to be something else.</p>
<h1>The Infection</h1>
<p>The latest Firefox exploits I&#8217;ve seen come from JavaScript, Java and sometimes obscure things you wouldn&#8217;t expect like GIFs, PDFs and Flash. The malware my fiancee&#8217;s system encountered, however, likely came from a JavaScript exploit. Although I am uncertain of the exact means her machine became infected, the immediate sign was unmistakable:</p>
<p style="text-align: center;"><img class="size-full wp-image-68  aligncenter" title="ANG Antivirus (Malware)" src="http://www.matevarga.com/wp-content/uploads/2009/11/ang_antivirus.jpg" alt="ANG Antivirus (Malware)" width="520" height="362" /></p>
<p>A program that suddenly appears on the screen claiming to be a virus scanner&#8230;<em>which you didn&#8217;t install</em>&#8230;is a pretty good indication you&#8217;re system has been compromised. But, as it turns out, this was just one of the many <em>friends </em>the original virus invited to join the party. Overall, her system became infected with 18 different virus and virus traces, according to the initial <em><strong>real </strong></em>malware scanner used.</p>
<h1>So, what now?</h1>
<p>Short of ripping out the network card and ceremoniously launching it into the sun, the best thing to do now is to enact some preventive measures. But finding the balance between crippling the user experience and not doing enough is a difficult task indeed. What are the options?</p>
<p>Disable Java. This is simple enough and not all too inconvenient as not too many sites directly use Java to serve content. If there is a site I know that requires it, and it is a site I trust, it is easy enough to turn it back on.</p>
<p>While tempting, disabling JavaScript is out of the picture. Thanks to Web 2.0, there are very few sites (especially community and media-heavy) that will work (properly, if at all) without JavaScript. The alternative is to install the [terribly inconvenient] <a title="No Script Plug-In" href="https://addons.mozilla.org/en-US/firefox/addon/722">NOSCRIPT</a> Firefox plug-in. Even though it is better than nothing, there are still ways around it as it too has vulnerabilities.</p>
<p>If you&#8217;re good at staying away from the seedier parts of the Internet, you still have to worry about well-known sites being compromised either by getting entirely hacked or having one of their ad networks compromised or going rogue. To further secure your browser, <a title="Flash Block Plug-In" href="https://addons.mozilla.org/en-US/firefox/addon/433">Flashblock</a> will disable any Flash animation until you click on it (which is also good for getting rid of some truly annoying and sometimes noisy ads).</p>
<p>With those plug-ins (and some common sense), you&#8217;re likely in good shape. By diminishing the ability for client-side execution of just about <em>anything</em> (which mostly includes Java, JavaScript and Flash), you&#8217;re chances of picking up drive-by-downloaded malware also diminish. If you absolutely must visit a questionable site, use a virtual machine.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.matevarga.com/firefox-gone-wild/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

