Bitcoin Forum

Other => Off-topic => Topic started by: deepceleron on August 08, 2015, 03:51:18 PM



Title: Firefox users, update now, file stealing exploit found
Post by: deepceleron on August 08, 2015, 03:51:18 PM
Firefox 39.0.3 was released and fixes a huge 0-day flaw in the built in PDF reader that allows a site to steal files from a PC - for you this means wallet files.

"The vulnerability comes from the interaction of the mechanism that enforces JavaScript context separation (the “same origin policy”) and Firefox’s PDF Viewer. Mozilla products that don’t contain the PDF Viewer, such as Firefox for Android, are not vulnerable. The vulnerability does not enable the execution of arbitrary code but the exploit was able to inject a JavaScript payload into the local file context. This allowed it to search for and upload potentially sensitive local files".

https://blog.mozilla.org/security/2015/08/06/firefox-exploit-found-in-the-wild/

It was found in ads on a news site that actively searched for and stole FTP client and account information along with bash history and scripts. It is as easy to imagine drive-bys taking wallet files or anything the user can access.

The exact mechanism is not detailed without having access to the CVE. Mitigations such as moving or renaming the wallet file may not be effective, as searching for files is possible. Disabling the built-in PDF reader via about:config may not be effective either, so update.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: |Bitcoin| on August 08, 2015, 03:58:05 PM
I use chrome so there is no need to worry.  Even if I use firefox I have my wallet on my phone. Nothing to worry for me.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: linkgostar on August 08, 2015, 04:08:08 PM
i used chrome too. anyway thank for this News


Title: Re: Firefox users, update now, file stealing exploit found
Post by: mindrust on August 08, 2015, 04:09:00 PM
Thanks for letting us know that you are safe against this exploit,  @|Bitcoin| . Be safe.

As a 39.0 user, thanks to the original poster for letting me know. I'll update right away.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: Cryptock on August 08, 2015, 04:10:20 PM
Holy crap. Thanks for the heads up


Title: Re: Firefox users, update now, file stealing exploit found
Post by: countryfree on August 08, 2015, 05:16:37 PM
Thanks for info, but my Firefox is tuned for auto updates, so there's no risk. One nice Firefox's feature is to allow profiles. I have one profile dedicated to BTC, banking and online shopping, which I'm not using now. That helps make my computer a bit more secure. I keep on thinking Firefox is the best browser around. And I'm not sharing anything with Google.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: unamis76 on August 08, 2015, 05:25:57 PM
I've read this before and immediately pictured my empty wallet files on my desktop being stolen :D Anyways, I'm on Chrome. But I'm also worried as it might have the same or a similar exploit. I hope it is discovered if it's there...

Good thing they promptly corrected the issue after being discovered.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: White sugar on August 08, 2015, 10:16:13 PM
just use noscript and you will be fine

also is this for all OS's that have the reader or just some?


Title: Re: Firefox users, update now, file stealing exploit found
Post by: rokkyroad on August 08, 2015, 11:26:57 PM
linux users can use Firejail to further protect themselves. Firejail sandboxes browsers and others.

https://l3net.wordpress.com/projects/firejail/


Title: Re: Firefox users, update now, file stealing exploit found
Post by: Xian01 on August 08, 2015, 11:28:45 PM
I've read this before and immediately pictured my empty wallet files on my desktop being stolen :D
LPT: Ensure that your wallet is encrypted with a redonkulously long password.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: Superhitech on August 08, 2015, 11:37:38 PM
Thanks for the heads up, updated my firefox.  :)


Title: Re: Firefox users, update now, file stealing exploit found
Post by: Foxpup on August 09, 2015, 02:11:47 AM
just use noscript and you will be fine
No, you won't. The PDF viewer script is internal to Firefox and is not blocked by NoScript. Please don't post dangerous false information for the sake of your signature campaign.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: Holliday on August 09, 2015, 05:25:41 AM
If you store bitcoin private keys on a computer which is also used to browse the web (or even connected to the internet for that matter), you are probably going to have a bad time.


Title: Re: Firefox users, update now, file stealing exploit found
Post by: LiteCoinGuy on August 09, 2015, 07:41:27 AM
If you store bitcoin private keys on a computer which is also used to browse the web (or even connected to the internet for that matter), you are probably going to have a bad time.

yeah, you should not store everything in a hotwallet on your pc  :-X

you could use a hardware wallet:

https://bitcointalk.org/index.php?topic=899253.0