Alan Edwardes

Firefox Auto Download Security Flaw

Old Content Warning

This post is very old (it was published 5 years ago), so I can't vouch for its content or accuracy. It may be here for posterity. Please take its content with a pinch of salt.

So, picture this: Someone on your windows live messenger contact list gets a virus. That virus then goes on to hijack their windows live messenger account and sends everyone on the contact list a link to the same virus, thus spreading it around. So, you accidentally click on the link (I was distracted), and open pops Firefox asking whether you would like to save the file or cancel. Obviously realising what had happened I clicked cancel, sure i'd dismissed it and it hadn't so much as touched my hard drive. But, sure enough, a few seconds later Windows Live OneCare popped up and told me that it had quarantined a trojan - the same trojan I just told firefox to ignore.

WTF? So does Firefox download stuff for you now? So it turns out it does. When I looked in the OneCare quarantine it displayed the path that the virus was found in. So, I was a bit worried when it turned out that the file was found in the Firefox cache folder. Interesting.

04th of June 2008 at 5:35 PM

4 years, 11 months ago

I was 16 years old when I wrote this

180 words

rand: By God! It Vorks!

next: Using PHP isset To ...

prev: Why Windows Live OneCare ...

share:FacebookTwitterRedditdiggStumbleUpondeliciousHacker NewsLinkedIn

Add a Comment

© 2006 – 2013 Alan Edwardes / Source on GitHub
Top