TechRepublic : A ZDNet Tech Community

IT Security

Host: Chad Perrin
Contact

A months-old Microsoft security faux pas rears its ugly head, and Firefox users pay the price.


Earlier this year, Microsoft came up with a way to surreptitiously add a feature to Firefox — and, at the same time, a new way for Firefox to be vulnerable to malicious security crackers. In Microsoft may be Firefox’s worst vulnerability, I pointed out that:

Microsoft has decided to quietly install what amounts to a massive security vulnerability in Firefox without informing the user.

A number of articles sprang up, including my own, explaining how Microsoft’s .NET extension for Firefox could be removed, and in some cases warning users to refuse to let the .NET update install itself at all. After taking enough heat from users and security experts, Microsoft even released another MS Windows update that made it easier to disable the .NET extension for Firefox.

Unfortunately, a number of subsequent updates have played havoc with the ease of maintaining a system clear of that particular Firefox extension. Microsoft, as always, thinks it knows better than users. In several cases, people have reported removing or disabling the extension only to have it reappear or reactivate itself later, when it wasn’t expected.

On Tuesday this month, Microsoft released a security bulletin that addresses this problem. The company has admitted to a critical vulnerability introduced to Firefox because of the .NET extension it originally claimed was nothing but a perfectly safe improvement in Firefox functionality. According to ComputerWorld’s Sneaky Microsoft plug-in puts Firefox users at risk:

“While the vulnerability is in an IE component, there is an attack vector for Firefox users as well,” admitted Microsoft engineers in a post to the company’s Security Research & Defense blog on Tuesday. “The reason is that .NET Framework 3.5 SP1 installs a ‘Windows Presentation Foundation’ plug-in in Firefox.”

The Mozilla Foundation, which manages the open source Firefox browser development project, has taken steps to protect its users. Some Firefox users may be treated to a warning dialog similar to this screenshot, bearing ominous messages like:

Firefox has determined that the following add-ons are known to cause stability or security problems

The listed add-ons include the Microsoft .NET Framework Assistant and Windows Presentation Foundation. In case the point was not driven home well enough, the point is reinforced below the list of offending add-ons:

These add-ons have a high risk of causing stability or security problems and have been blocked

Mozilla offers more information at its Add-ons Blocklist page.

Hopefully, Microsoft’s evil extensions to third party applications will not be a problem any longer. Hopefully Microsoft will have learned a lesson from the bad press it has gotten as a result of this fiasco. I will not, however, hold my breath.

Chad PerrinChad Perrin is an IT consultant, developer, and freelance professional writer. He holds both Microsoft and CompTIA certifications and is a graduate of two IT industry trade schools. Read his full bio and profile.

Print/View all Posts Comments on this blog

Microsoft makes Firefox vulnerable; Mozilla responds apotheon | 10/18/09
comment c&d4ever | 10/19/09
Why? apotheon | 10/19/09
Love it... silversidhe | 10/19/09
re: DesktopBSD apotheon | 10/19/09
Loading links from emails jgarret9 | 10/20/09
Example? ocie3@... | 10/20/09
Well done, Mozilla NickNielsen | 10/18/09
I expect Microsoft to learn... Snak | 10/19/09
Got message - but add-ons don't show up RandyLyon | 10/19/09
Check the plug-ins list NickNielsen | 10/19/09
I just wonder... jck | 10/19/09
Yes and no . . . apotheon | 10/19/09
I can't believe it either jck | 10/19/09
Do you want to ocie3@... | 10/20/09
nope jck | 10/21/09
MS will behave, yeah right - how many millions Deadly Ernest | 10/18/09
"Best answer, don't use Windows." grax | 10/19/09
"Best answer, don't use Windows." Bishop74 | 10/19/09
Huh? Gis Bun | 10/19/09
Uh . . . what? apotheon | 10/19/09
I'm equating court issues with deliberate coding by MS Deadly Ernest | 10/22/09
Silly melekali | 10/19/09
It wasn't subect to this particular issue was it? Tony Hopkinson | 10/19/09
What? apotheon | 10/19/09
Unix, Linux, or go with a mainframe and use IBM. Deadly Ernest | 10/22/09
You could try Unix, been around a lot longer than Windows Deadly Ernest | 10/22/09
There is no doubt... JCitizen | 10/19/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds jhogan123@... | 10/19/09
Don't apologize for them bpsull@... | 10/19/09
Really? Are you *THAT* stoopid techrepublic@... | 10/19/09
I feel sorry for him alan@... | 10/19/09
I think you misunderstood some details. apotheon | 10/19/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds ajkillgore | 10/19/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds Gis Bun | 10/19/09
How so ? Tony Hopkinson | 10/19/09
The MicroSoft (c) shills turn up again - lestertrad@... | 10/19/09
Please read the article. apotheon | 10/20/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds mauited2004@... | 10/19/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds james@... | 10/19/09
Open Office - that I wouldn't doubt a bit!.. JCitizen | 10/19/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds LesleyDewar | 10/19/09
I always... melekali | 10/19/09
Wish for Microsft Gobang !!! mirmuit@... | 10/20/09
Microsoft has demonstrated over the year a serious disregard for users. hueta | 10/20/09
"It's just too popular!" is not as good an argument as you think. apotheon | 10/20/09
RE: Microsoft makes Firefox vulnerable; Mozilla responds hueta | 10/20/09
Popular obscurity is not security. apotheon | 10/20/09
Microsoft should be prosecuted harrylal | 10/20/09
Yes, Microsoft should be criminally prosecuted dgbell | 10/20/09
Unintentional? bpsull@... | 10/20/09
I imagine MS got it's hide singed JCitizen | 10/20/09
Should we remove .NET ?? ocie3@... | 10/20/09
Good luck not letting updates install... JCitizen | 10/20/09
If only we could be shot of this sh** alan@... | 10/21/09
Getting Rid of .NET ocie3@... | 10/21/09
Symantec?... JCitizen | 10/21/09

What do you think?

White Papers, Webcasts, and Downloads

Recent Entries

TR on Twitter

Archives

TechRepublic Blogs



Quick Reference: Linux Commands
Reduce stress and speed up resolutions with the easiest command references right at your fingertips. You'll receive a PDF file covering Linux, packed with the most common commands you'll need and use daily.
Buy Now
IT Professional's Guide to Policies and Procedures, Third Ed
Whether you're creating policies for management, training, personnel, support, privacy, Internet/e-mail usage, security, or inventory, you'll meet the needs of your entire enterprise with this one download!
Buy Now

SmartPlanet

Click Here