|
|
Topic started on 17-10-2009 @ 06:04 PM by Scooby Doo
|
                       +28 more
An add-on that Microsoft silently slipped into Mozilla's Firefox last February leaves the browser open to attack, Microsoft's security engineers
acknowledged earlier this week.
One of the 13 security bulletins Microsoft released Tuesday affects not only Internet Explorer (IE), but also Firefox, thanks to a Microsoft-made
plug-in pushed to Firefox users eight months ago in an update delivered via Windows Update.
"While the vulnerability is in an IE component, there is an attack vector for Firefox users as well," admitted Microsoft engineers in a post to the
company's Security Research & Defense blog on Tuesday. "The reason is that .NET Framework 3.5 SP1 installs a 'Windows Presentation Foundation'
plug-in in Firefox."
The Microsoft engineers described the possible threat as a "browse-and-get-owned" situation that only requires attackers to lure Firefox users to a
rigged Web site.
Numerous users and experts complained when Microsoft pushed the .NET Framework 3.5 Service Pack 1 (SP1) update to users last February, including Susan
Bradley, a contributor to the popular Windows Secrets newsletter.
Full CompuerWorld Article
Today kids, we ask: " How low can Microsoft go?" Just as you think Microsoft couldn't sink to a lower level, this comes up.  Maybe if
Microsoft started building decent browsers, maybe people could rely on them. - After this however, who would?
|
copyright & usage
|
Click here for more General Conspiracy Discussion topics
Hot Topics
|
Top Topics
|
This Week
|
Subscribe
|
Home
|
reply posted on 17-10-2009 @ 06:18 PM by LadySkadi
|
         
Interesting timing. Not 5 minutes ago Firefox alerted me to this, but said it had been blocked. Recommended a re-start to be safe.
*MS Framework assistant .net 1.1
*Windows Presentation foundation
S&F
[edit on 17-10-2009 by LadySkadi]
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:24 PM by ohioriver
|
 
reply to post by LadySkadi
Same thing for me, about the same time period. Said the plug in would make firefox unstable.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:35 PM by juniperberry
|
 
Wow.. I've seen these popups on 3 different computers these last couple days. Right after critical patch Tuesday...
MS Framework assistant .net 1.1
And
Windows Presentation foundation?
|
copyright & usage
|
|
AboveTopSecret.com is advertising supported.
|
reply posted on 17-10-2009 @ 06:37 PM by LifENcircleS
|
  
Same here just yesterday. I went to the Tools/Add-ons and uninstalled it immediately(microsoft.net framework) I suggest everyone do the same...
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:39 PM by Maxmars
|
         
Well, I have to take my hat's off to the FF programmers who alerted me to this problem the second I opened my browser....
Unbelievable that we had to find out about it as potential victims.. after the fact.
I suppose MS has no interest in keeping the net safe for non-IE users
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:40 PM by Le Colonel
|
i got the same message also earlier. I shrug it off. means nothing to me. not worried about it. It is unacceptable behavior for a company to do,
but what do you want, they feel like they rule the computer world.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:41 PM by tgidkp
|
i have manually verified that i did not receive this update through the system for win7.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:41 PM by searching4truth
|
damn  I quit using IE and norton bc of "issues" and now firefox.
I do have to say I feel vindicated though, I had an attack a few months ago and had to call norton. I had about a month left on the protection and
the person told me that I would have to pay $90 for them to remote access my system and remove the files. The program itself costs $90!!!!!! I never
download anything, I have no file sharing, the only thing my system is allowed to accept (with permission even) are updates from norton and windows.
So, I suggested that it was attached to one of their downloads and that I would not be renewing the program. It would appear I may not have been far
off.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:42 PM by SLAYER69
|

|
copyright & usage
|
|
AboveTopSecret.com is advertising supported.
|
reply posted on 17-10-2009 @ 06:44 PM by Epsillion70
|
I had these Add ons as well I disabled them quick smart
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:45 PM by Walkswithfish
|
So that is what that was eh?
I got that pop up too, I thought about hitting the cancel button, heck, how could anything from Microsoft be bad?
[edit on 17-10-2009 by Walkswithfish]
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 06:54 PM by Hypntick
|
This is exactly why I have my firewall set to block any and all windows update traffic. No updates are installed without my explicit permission, seems
a lot safer to me than just randomly allowing security loopholes to be "updated" into the code.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 07:03 PM by Violater1
|

Excellent find. Once again fellow ATS members protect the IT community by informing each other and others of potential attacks against computer
owners.
 Bill Gates has no shame.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 07:05 PM by zazzafrazz
|
Originally posted by LadySkadi
Interesting timing. Not 5 minutes ago Firefox alerted me to this, but said it had been blocked. Recommended a re-start to be safe.
*MS Framework assistant .net 1.1
*Windows Presentation foundation
S&F
[edit on 17-10-2009 by LadySkadi]
Thats what mine did, did Firefox take care of for me?
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 07:29 PM by GradyPhilpott
|
     
Microsoft .NET Framework Assistant is now on Mozilla's blocked add-on list.
www.mozilla.com...
|
copyright & usage
|
|
AboveTopSecret.com is advertising supported.
|
reply posted on 17-10-2009 @ 07:29 PM by blackhatchet
|
Glad I ditched Windows 9 years ago.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 08:02 PM by Mr Knowledge
|
Same thing for me as well. When I saw it, I was like, wtf?
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 08:07 PM by grover
|
Just to be on the safe side I checked my firefox but whatever Microsoft did it didn't inflitrate macs.
|
copyright & usage
|
 |
reply posted on 17-10-2009 @ 08:11 PM by LadySkadi
|
Originally posted by zazzafrazz
Originally posted by LadySkadi
Interesting timing. Not 5 minutes ago Firefox alerted me to this, but said it had been blocked. Recommended a re-start to be safe.
*MS Framework assistant .net 1.1
*Windows Presentation foundation
S&F
[edit on 17-10-2009 by LadySkadi]
Thats what mine did, did Firefox take care of for me?
Firefox isolated it and just to be sure I went to "tools" "add-ons" and made sure it was blocked (or deleted) and than restart the computer - hope
that took care of the problem. I do NOT see the .net installed on the 'puter so I'm guessing it worked.
[edit on 17-10-2009 by LadySkadi]
|
copyright & usage
|
 |