+Warwagon MVC Posted October 16, 2009 MVC Share Posted October 16, 2009 Sneaky Microsoft plug-in puts Firefox users at riskAn add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves that browser open to attack, Microsoft's security engineers acknowledged earlier this week. One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made plug-in pushed to Firefox users eight months ago in an update delivered via Windows Update. "While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," admitted Microsoft engineers in a post to the company's Security Research & Defense blog on Tuesday. "The reason is that .NET Framework 3.5 SP1 installs a 'Windows Presentation Foundation' plug-in in Firefox." For the rest of the article http://news.idg.no/cw/art.cfm?id=5CF0A4A7-...45F5A54F2136086 Consider that add-on uninstalled from my system. Idiots. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/ Share on other sites More sharing options...
Andrew Lyle Global Moderator Posted October 16, 2009 Global Moderator Share Posted October 16, 2009 At least it was detected by Microsoft Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713820 Share on other sites More sharing options...
thealexweb Posted October 16, 2009 Share Posted October 16, 2009 Its Microsofts cunning plan to increase the bumber of security holes in rival browsers to make IE look better. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713822 Share on other sites More sharing options...
Hurmoth Posted October 16, 2009 Share Posted October 16, 2009 Didn't they already do this a while back and got a lot of grief for it then too? This is the same thing that Apple does with downloading unwanted crap in Windows (i.e. MobileMe). Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713828 Share on other sites More sharing options...
iamawesomewicked Posted October 16, 2009 Share Posted October 16, 2009 Welcome to a few months ago. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713850 Share on other sites More sharing options...
+Warwagon MVC Posted October 16, 2009 Author MVC Share Posted October 16, 2009 Welcome to a few months ago. Yes it was known a few months ago they added this. But now they are saying it can be exploited. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713870 Share on other sites More sharing options...
ichi Posted October 16, 2009 Share Posted October 16, 2009 This was discussed some time ago, and someone jumped infuriated on the suggestion that it could introduce a new extra attack vector. Well, there you go. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713908 Share on other sites More sharing options...
Ci7 Posted October 16, 2009 Share Posted October 16, 2009 not the same thing that was clickonce somethn Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713940 Share on other sites More sharing options...
ichi Posted October 16, 2009 Share Posted October 16, 2009 not the same thing that was clickonce somethn Probably. It was also a .NET Framework 3.5 plugin getting installed on firefox anyway. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591713976 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 Firefox is out for me. Didn't ask, won't let me unblock it. There's nothing wrong with it. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716206 Share on other sites More sharing options...
oceanmotion Posted October 17, 2009 Share Posted October 17, 2009 I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716398 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 (edited) How do you remove plugins from the blocklist? EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/) Do NOT block things on my computer without permission or a way to re-enable them, Mozilla. Edited October 18, 2009 by GreyWolfSC Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716404 Share on other sites More sharing options...
Ci7 Posted October 17, 2009 Share Posted October 17, 2009 Probably.It was also a .NET Framework 3.5 plugin getting installed on firefox anyway. pretty much,yes How do you remove plugins from the blocklist?EDIT: Fixed. I had to turn off extensions.blocklist.enabled in about:config and reinstall the framework assistant. (Mozilla removed it from their repository. I found it here: http://mirror.atlanticmetro.net/mozilla/addons/9449/) Do NOT block things on my computer without permission or a way to re-enable them, Mozilla. your link is broken , remove the ")" from the end of the link :) Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716514 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 Fixed, thanks. :) Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716522 Share on other sites More sharing options...
Tai Posted October 17, 2009 Share Posted October 17, 2009 I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again. same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ... Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716550 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 same here, and also noticed my Firefox hanging recently. I'd prefer no Firefox secret installations from Microsoft if they are reading this ... It's not a secret Firefox installation. The plug-in is installed as part of the .NET Framework and Firefox picks it up automatically. If anything, we should complain to Mozilla for the browser not asking if the "found" plugin should be added. Their methodology could easily activate a hidden malware plugin the same way. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716568 Share on other sites More sharing options...
SuperKid Posted October 17, 2009 Share Posted October 17, 2009 What addon? i can't find any addon by microsoft in firefox except silverlight? Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716574 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 What addon? i can't find any addon by microsoft in firefox except silverlight? Mozilla removed one and disabled the other. The WPF one was located under "Plugins" rather than "Extensions". Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716590 Share on other sites More sharing options...
+BeLGaRaTh Subscriber¹ Posted October 17, 2009 Subscriber¹ Share Posted October 17, 2009 Strangely this morning when I turned my monitor on (My PC is on constantly) I had a warning from Firefox that it had disabled the Windows Foundation plugin (when checking the plugins it just says "known to cause security issues") and it directed me to the webpage https://en-gb.www.mozilla.com/en-GB/blocklist/ Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716592 Share on other sites More sharing options...
SuperKid Posted October 17, 2009 Share Posted October 17, 2009 Mozilla removed one and disabled the other. The WPF one was located under "Plugins" rather than "Extensions". Ah, its not their for me must of been removed or something. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716598 Share on other sites More sharing options...
goji Posted October 17, 2009 Share Posted October 17, 2009 I just got the notice from Firefox today. Said the Microsoft.NET Framework Assistant and Windows Presentation Foundation would cause instability and you know what, I have noticed some hanging the last day or so with Firefox open that I never noticed before. Could be related or maybe not. Will see if the issue pops up again. I got the message yesterday as well, right before firefox crashed on me. :no: Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716600 Share on other sites More sharing options...
dingl_ Posted October 17, 2009 Share Posted October 17, 2009 Mozilla is in your browser, disabling your addons ;) screw that sh*t its been all over the net how to disable/remove this Microsoft addon long before they enabled the option i do not need Mozilla looking out for me Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716608 Share on other sites More sharing options...
Eric Veteran Posted October 17, 2009 Veteran Share Posted October 17, 2009 Mozilla is in your browser, disabling your addons ;) screw that sh*t its been all over the net how to disable/remove this Microsoft addon long before they enabled the option i do not need Mozilla looking out for me That's what I'm sayin'. I bet Mozilla wouldn't have liked it if Microsoft had uninstalled and blacklisted Firefox due to the crypto spoofing flaw. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716622 Share on other sites More sharing options...
protocol7 Posted October 17, 2009 Share Posted October 17, 2009 Weird. I haven't got any messages about this addon and it's installed here. Checked for updates and Firefox is up-to-date. Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716628 Share on other sites More sharing options...
Pikey Posted October 17, 2009 Share Posted October 17, 2009 Just got it myself ... Link to comment https://www.neowin.net/forum/topic/834612-sneaky-microsoft-plug-in-puts-firefox-users-at-risk/#findComment-591716658 Share on other sites More sharing options...
Recommended Posts