Collected research
MITM attack to overwrite addons in Firefox
A Remote Vulnerability in Firefox Extensions
Soghoian's disclosure that Google Toolbar, Browser Sync, Yahoo, Facebook, AOL and other commercial Firefox extensions fetched updates over plain HTTP. Anyone controlling DNS or the network silently installs arbitrary extension code; some vendors had also disabled the update prompt. Extensions on addons.mozilla.org are unaffected.
Record
- Document
- A Remote Vulnerability in Firefox Extensions
- Researcher
- Christopher Soghoian
- Published by
- paranoia.dubfire.net
- Topic
- Browser
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Christopher Soghoian, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .