Author Topic: Microsoft's implementation of the liberal idea of a level playing field  (Read 2195 times)

Fatman

  • Top Forum Member
  • *****
  • Posts: 1454
  • Liked:
  • Likes Given: 0
http://blogs.zdnet.com/security/?p=4614&tag=nl.e539

Quote
Microsoft exposes Firefox users to drive-by malware downloads

Posted by Ryan Naraine @ 9:24 am


Remember that Microsoft .NET Framework Assistant add-on that Microsoft sneaked into Firefox without explicit permission from end users?

Well, the code in that add-on has a serious code execution vulnerability that exposes Firefox users to the “browse and you’re owned” attacks that are typically used in drive-by malware downloads.

[ SEE: Patch Tuesday: MS plugs critical IE, Windows Media Player holes ]

The flaw was addressed in the MS09-054 bulletin that covered “critical” holes in Microsoft’s Internet Explorer but, as Redmond’s Security Research & Defense team explains, the drive-by download risk extends beyond Microsoft’s browser.

A browse-and-get-owned attack vector exists. All that is needed is for a user to be lured to a malicious website. Triggering this vulnerability involves the use of a malicious XBAP (XAML Browser Application). Please not that while this attack vector matches one of the attack vectors for MS09-061, the underlying vulnerability is different.  Here, the affected process is the Windows Presentation Foundation (WPF) hosting process, PresentationHost.exe.

While the vulnerability is in an IE component, there is an attack vector for Firefox users as well. The reason is that .NET Framework 3.5 SP1 installs a “Windows Presentation Foundation” plug-in in Firefox.

Now, Microsoft’s security folks are actually recommending that Firefox users uninstall the buggy add-on:

For Firefox users with .NET Framework 3.5 installed, you may use “Tools”-> “Add-ons” -> “Plugins”, select “Windows Presentation Foundation”, and click “Disable”.

This introduction of vulnerabilities in a competing browser is a colossal embarrassment for Microsoft.  At the time of the surreptitious installs, there were prescient warnings from many in the community about the security implications of introducing new code into browsers without the knowledge — and consent — of end users.
[SEE: Microsoft says Google Chrome Frame doubles IE attack surface ]

This episode also underscores some of the hypocrisy that has risen to the surface in the new browser wars.  When Google announced it would introduce a plug-in that runs Google Chrome inside Microsoft’s Internet Explorer, Microsoft whipped out the security card and warned that Google’s move increased IE’s attack surface.

“Given the security issues with plug-ins in general and Google Chrome in particular, Google Chrome Frame running as a plug-in has doubled the attach area for malware and malicious scripts. This is not a risk we would recommend our friends and families take.”

Of course, when it’s Microsoft introducing the security risk to other browsers (Silverlight, anyone?), we should all just grin and take it.

* Image via DevExpress.  Hat tip to Gregg Keizer.

Anti: I think some of you gentleman would choose to apply a gun shaped remedy to any problem or potential problem that presented itself? Your reverance (sic) for firearms is maintained with an almost religious zeal. The mind boggles! it really does...

Me: Naw, we just apply a gun-shaped remedy to those extreme life threatening situations that call for it. All the less urgent problems we're willing to discuss.

Pathfinder

  • Top Forum Member
  • *****
  • Posts: 6449
  • DRTV Ranger -- NRA Life Member
  • Liked:
  • Likes Given: 86
Re: Microsoft's implementation of the liberal idea of a playing field
« Reply #1 on: October 19, 2009, 07:08:22 PM »
Shortly after my last set of 24 (24!!!!!) Windows upgrades - one of which was this one - I got a ping from Firefox saying that the .NET add-on had been disabled due to "incompatibility".

I guess the Mozilla universe was on top of this one.
"I won't be wronged, I won't be insulted, I won't be laid a hand on. I don't do this to others and I require the same from them"

J.B. Books

ericire12

  • Top Forum Member
  • *****
  • Posts: 7926
  • DRTV Ranger
  • Liked:
  • Likes Given: 0
Re: Microsoft's implementation of the liberal idea of a playing field
« Reply #2 on: October 19, 2009, 07:09:40 PM »
Hahaha.... I blocked it on mine! :)
Everything I needed to learn in life I learned from Country Music.

Fatman

  • Top Forum Member
  • *****
  • Posts: 1454
  • Liked:
  • Likes Given: 0
Re: Microsoft's implementation of the liberal idea of a playing field
« Reply #3 on: October 19, 2009, 07:10:34 PM »
Yeah, it was installed on mine, then FF notified me it disabled it and wouldn't allow one other item to be installed.
Anti: I think some of you gentleman would choose to apply a gun shaped remedy to any problem or potential problem that presented itself? Your reverance (sic) for firearms is maintained with an almost religious zeal. The mind boggles! it really does...

Me: Naw, we just apply a gun-shaped remedy to those extreme life threatening situations that call for it. All the less urgent problems we're willing to discuss.

ericire12

  • Top Forum Member
  • *****
  • Posts: 7926
  • DRTV Ranger
  • Liked:
  • Likes Given: 0
Re: Microsoft's implementation of the liberal idea of a level playing field
« Reply #4 on: October 19, 2009, 07:20:07 PM »
My firewall alerted me..... it looked weird..... so I did not grant it access.
Everything I needed to learn in life I learned from Country Music.

Sponsor

  • Guest

tombogan03884

  • Guest
Re: Microsoft's implementation of the liberal idea of a level playing field
« Reply #5 on: October 19, 2009, 08:41:40 PM »
Yeah, it was installed on mine, then FF notified me it disabled it and wouldn't allow one other item to be installed.

Shortly after my last set of 24 (24!!!!!) Windows upgrades - one of which was this one - I got a ping from Firefox saying that the .NET add-on had been disabled due to "incompatibility".

I guess the Mozilla universe was on top of this one.

What they said

Big Frank

  • NRA Benefactor Member
  • Top Forum Member
  • *****
  • Posts: 11241
  • DRTV Ranger
  • Liked:
  • Likes Given: 1549
Re: Microsoft's implementation of the liberal idea of a level playing field
« Reply #6 on: October 19, 2009, 09:25:57 PM »
I'm not having any problems like that with Vista. I use McAfee site advisor too. As soon as a page opens it tells you if they have a problem with people trying to hack your browser, or if there are viruses waiting to be download.
""It may be laid down as a primary position, and the basis of our system, that every Citizen who enjoys the protection of a free Government, owes not only a proportion of his property, but even his personal services to the defence of it, and consequently that the Citizens of America (with a few legal and official exceptions) from 18 to 50 Years of Age should be borne on the Militia Rolls, provided with uniform Arms, and so far accustomed to the use of them, that the Total strength of the Country might be called forth at a Short Notice on any very interesting Emergency." - George Washington. Letter to Alexander Hamilton, Friday, May 02, 1783

THE RIGHT TO BUY WEAPONS IS THE RIGHT TO BE FREE - A. E. van Vogt, The Weapon Shops of Isher

jaybet

  • Top Forum Member
  • *****
  • Posts: 3773
  • NRA Life Member, DRTV Ranger, Guitar Player
    • Bluebone- Burnin' and Smokin'
  • Liked:
  • Likes Given: 0
Re: Microsoft's implementation of the liberal idea of a level playing field
« Reply #7 on: October 20, 2009, 03:50:28 PM »
Ever notice how liberal new world order asshats like Bill Gates and George Soros are filthy rich and stay that way by screwing people? Bull****!
I got the blues as my companion.

www.bluebone.net

philw

  • Top Forum Member
  • *****
  • Posts: 3680
  • Aussie Aussie Aussie, Oi Oi Oi
    • Australian Hunting Net
  • Liked:
  • Likes Given: 0
Re: Microsoft's implementation of the liberal idea of a level playing field
« Reply #8 on: October 21, 2009, 06:22:10 AM »
no issues here



Here’s to the crazy ones. The misfits. The rebels. The troublemakers. The round pegs in the square holes. The ones who see things differently. They’re not fond of rules. And they have no respect for the status quo. You can praise them, disagree with them, quote them, disbelieve them, glorify or vilify them. The only thing you can’t do is ignore them

 

SMF spam blocked by CleanTalk