Recommended Posts

Well...

 

To sum up the above considerations: the Maxthon browser is not secure. It allows conducting the targeted attack on a selected user by revealing the browser authors the complete list of exact versions of programms, some of which may be vulnerable, also providing them with user’s browsing history and Google searches.

 

Beware.

I will need more than this random very poorly written "advisory" with few details. Why a PDF? The title is strange and not professional -->“I will be very surprised if this comes to light”

On 7/15/2016 at 8:37 AM, oldtimefighter said:

I will need more than this random very poorly written "advisory" with few details. Why a PDF? The title is strange and not professional -->“I will be very surprised if this comes to light”

This a better source?  This was one of quite a few that popped up with a simple google search for maxthon and spyware 

 

https://news.ycombinator.com/item?id=12094930

 

3 hours ago, Anibal P said:

This a better source?  This was one of quite a few that popped up with a simple google search for maxthon and spyware 

 

https://news.ycombinator.com/item?id=12094930

 

I don't use the Maxthon Browser so it's of little interest to me. I wonder when a English speaking security or tech site is going to pick up this "story". What I didn't know is Maxthon is a browser from a Chinese company based in Beijing. This is a surprise? LOL No one should be using software from a Chinese or Russian company (or hardware for that matter).

Just to add ...

 

From ThreatGeek ... which is a branch(?) off of Fidelis Cybersecurity 

 

Quote

One of our trusted partners from Poland, Exatel S.A., has discovered that a web browser developed by Maxthon, a company from China, has been collecting sensitive data from its users.  The Maxthon browser has anywhere from .75-1% of the global browser market, and has been estimated to be 2-3% of China’s own domestic browser market.  Total global user count is estimated to be in the hundreds of millions.

 

Using the Fidelis Network solution, Exatel found that there was a periodic upload of encrypted content to China from the Maxthon browser.  The uploaded content-type was purported to be “image/pjpeg”, but Fidelis had found that the filename was actually a zip and there was a dat.txt file included. 

 

/snip

 

I think that this discovery raises two very important points:

Companies, countries and users need to be aware of the potentially egregious data capture happening through installed applications and leaving their respective organizations (and endpoints). Organizations such as Citizenlab have also published similar discoveries but there is still relatively low awareness of these practices.

“Trust, but verify”: Often we’re installing software onto our endpoints at home and at work, but we’re not verifying that the code is doing what it is purported to do. Visibility into both the network and endpoints has become critical for organizations.

Exatel’s discovery is a great example of verifying and validating traffic.  We look forward to the opportunity to highlight more discoveries from our customers and partners.

They have a breakdown of the concerns here ....

http://www.threatgeek.com/2016/07/chinese-web-browsers-perfect-reconnaissance-tool.html

 

Regarding Fidelis Cybersecurity ... they are legit .... being acquired by General Dynamics in 2012 and later acquired by another firm.

 

I've heard of the Maxthon browser ... but have never used ... most certainly will not now.

 

57 minutes ago, oldtimefighter said:

I don't use the Maxthon Browser so it's of little interest to me. I wonder when a English speaking security or tech site is going to pick up this "story". What I didn't know is Maxthon is a browser from a Chinese company based in Beijing. This is a surprise? LOL No one should be using software from a Chinese or Russian company (or hardware for that matter).

Then I guess its time to throw out your computer and your phone then, and any game consoles you have. They're all manufactured by chinese companies.

Hello,


This came pre-loaded on a notebook computer I purchased.  I had disabled its auto-start routines, but otherwise left it in place.  I did leave its update service running, though, and one day when I started my computer, Maxthon popped up after I logged in and showed me a page of celebrity news.

 

I uninstalled it after that, and notified the notebook manufacturer.  Apparently, they had already stopped distributing it in their pre-loads.

 

Regards,


Aryeh Goretsky

 

5 hours ago, SharpGreen said:

Then I guess its time to throw out your computer and your phone then, and any game consoles you have. They're all manufactured by chinese companies.

Well, you can only speak for your ###### and NOT mine... Maybe if you had been reading carefully you would have noticed I was speaking of Maxthon being software from a Chinese COMPANY which would also apply to hardware as in I am NOT specificity referring to where said hardware is made.

Edited by oldtimefighter
This topic is now closed to further replies.
  • Posts

    • Universal USB Installer 2.0.3.7 by Razvan Serea The Universal USB Installer (UUI) is a powerful bootable USB software tool for creating USB boot drives from ISO files, perfect for installing Linux or Windows, running live systems, or building diagnostic toolkits. This versatile ISO-to-USB software makes it easy to boot from USB and create Live USBs for Linux distributions, Windows setup installers, antivirus tools, and system diagnostic utilities. Whether you need a multisystem Windows Media Creation Tool, a Live USB Linux installer, or an all-in-one PC diagnostic toolkit, UUI offers a reliable and flexible Linux and Windows bootable USB creator. Effortlessly carry your favorite portable operating systems and essential troubleshooting and diagnostic tools on a single flash drive or USB boot stick. Take your preferred Live Linux distributions, Windows installers, recovery software, backup utilities, and diagnostic tools with you, all bootable from a single USB drive. No more juggling multiple USB sticks or complicated bootloaders, UUI consolidates everything into one flexible, multiboot solution. Using this open source USB boot maker software is easy as 123. To create a Linux or Windows bootable USB drive, you simply select your target flash drive, choose your distribution from the list, browse to the ISO file (or choose to download the ISO), and then click Create. Once finished, you should have a ready to run Live USB containing the Live operating system, Windows installation media, or system diagnostics utility, or advanced system cleaner tool you previously selected. Universal USB Installer 2.0.3.7 changelog: Expanded the distro and tool catalog with additional popular Linux ISO entries. Updated: several distro homepage and download links, including Ubuntu Unity, Garuda Linux, Arch Linux, Fedora, Manjaro, and SystemRescue. Fixed: ISOs added via drag and drop (or manually copied to the drive) are now listed in the removal dropdown alongside normally installed distros. Download: Universal USB Installer 2.0.3.7 | 19.4 MB (Open Source) Link: Universal USB Installer Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • You are clueless. The updates are done in the background so the next time you open Edge the updates are applied automatically. There is no need to close all your tabs. Just keep browsing like you normally do. Clearly you don't use Edge and are just one of those haters that complain for the sake of complaining.
    • I don't get this David. Can you explain it please.  
    • Microsoft is busy. Lots of changes to be released imminently for Windows server or soon. Also, lots happening for next version as well. Third party virus scanning software is being moved out of Kernel mode to avoid repeat of Crowdstrike incident. Windows Protected Mode and Windows Ready Print no longer require third party print drivers to be installed. New storage stack being developed. New NVME drivers now available for Windows Server 2025 to improve local NVME drive performance by 60+ percent. NVME-Of of fabric being worked on for next release to improve network access to NVME drives. ReFs (next file system) now has ability to boot and will become default file system in next release of Windows Server. ReFs improves on NTFS in several areas including resiliency and reliability and scalability. New update stack is being worked on to unify Windows updates, and updates for drivers and first party/3rd party application software. A stricter and more robust third-party driver certification program (ODI) is being worked on to improve performance, thermals, battery life, and reliability on modern Windows hardware by tightening how OEMs and IHVs (Intel, AMD, Qualcomm, NVIDIA, etc.) build and ship drivers. There is a tone more but too numerous to mention.
  • Recent Achievements

    • Rookie
      Rimplesnort went up a rank
      Rookie
    • One Month Later
      Markus94287 earned a badge
      One Month Later
    • Week One Done
      Markus94287 earned a badge
      Week One Done
    • One Year In
      Markus94287 earned a badge
      One Year In
    • Dedicated
      truespursfan earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      507
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      154
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      79
  • Tell a friend

    Love Neowin? Tell a friend!