This morning I've found an scaring surprise on my Firefox Quantum. Casually it was connected to a proxy when an unexpected connection came up, the browser was connecting to an unknown remote site via HTTP and downloading a ZIP that contains an ELF shared library, without any type of signature on it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
This means two things
1) the owner of that site might spread malware infecting many many people.
2) the ISP also might do that.
Ubuntu Version:
Firefox Quantum version:
The URL: hxxp://ciscobinary.openh264.org/openh264-linux64-0410d336bb748149a4f560eb6108090f078254b1.zip
The zip contains these two files:
3f201a8984d6d765bc81966842294611 libgmpopenh264.so
44aef3cd6b755fa5f6968725b67fd3b8 gmpopenh264.info
The info file:
Name: gmpopenh264
Description: GMP Plugin for OpenH264.
Version: 1.6.0
APIs: encode-video[h264], decode-video[h264]
So there is a remote codec loading system that is unsigned and unencrypted, I think is good to be aware of it.
In this case the shared library is a video decoder, but it would be a vector to distribute malware o spyware massively, or an attack vector for a MITM attacker.
Continue reading
- Nsa Hack Tools
- Hack Tools 2019
- Hacking Tools For Games
- Hack Tools For Pc
- Hacker Tools Free
- Pentest Tools Framework
- Hacker
- World No 1 Hacker Software
- Hacker Tools Mac
- Hack Tools For Games
- Hack Tools For Mac
- Hacking Tools Software
- Top Pentest Tools
- Hacking Tools Software
- Hacking Tools Free Download
- Hacking Tools Windows
- Hacker Tools Apk
- Pentest Tools For Android
- Hacker Tools Linux
- Pentest Tools For Mac
- Hacker Tools For Ios
- Hacking Tools Online
- Pentest Tools Review
- Hacker Tools Free Download
- Pentest Tools Android
- Usb Pentest Tools
- Computer Hacker
- Hacker Tools Software
- Usb Pentest Tools
- Hacker Tools Mac
- Pentest Tools Tcp Port Scanner
- Pentest Tools Alternative
- Hacking Tools Software
- Hacking Tools Windows
- Pentest Tools Online
- Hacking Tools For Windows Free Download
- Hacking Tools For Games
- Pentest Tools Subdomain
- Pentest Reporting Tools
- Pentest Tools Find Subdomains
- Hack Tools Github
- Tools For Hacker
- Hacking Tools Hardware
- Hacker Tools For Ios
- Hacking Tools For Windows
- Pentest Tools Windows
- Pentest Tools Website
- Pentest Tools Framework
- Pentest Tools For Ubuntu
- Hacking Tools And Software
- Hack Tools Download
- Hacker Search Tools
- Install Pentest Tools Ubuntu
- Hacking Tools For Windows
- Hack App
- Pentest Tools Kali Linux
- Bluetooth Hacking Tools Kali
- Wifi Hacker Tools For Windows
- Pentest Reporting Tools
- Hacking App
- Pentest Tools List
- Hack App
- Pentest Box Tools Download
- Pentest Automation Tools
- Pentest Tools Bluekeep
- Hack Tools For Games
- Hacking Tools
- Ethical Hacker Tools
- Android Hack Tools Github
- Hack Tools


1 komentar:
canlı sex hattı
heets
https://cfimi.com/
salt likit
salt likit
QVXWX
Posting Komentar