Bitcoin Forum
April 27, 2024, 10:26:35 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [2019-06-24] “zero-day” vulnerability in Firefox directed against Coinbase  (Read 187 times)
Kakmakr (OP)
Legendary
*
Offline Offline

Activity: 3430
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
June 24, 2019, 08:19:35 AM
 #1

"A recent hacker attack was a threat not only to users but also to Coinbase employees. Mozilla Firefox assigned the threat the highest level of danger, declaring it a “zero-day” vulnerability. Fortunately, the attack was stopped, and all means are safe."

https://cryptobit.media/en/news/exchanges/1692/

*Please update your Mozilla Firefox products and Firefox ESR to the latest version, if you are using Firefox as your browser, because one of the biggest exchanges are being targeted by these exploits now.  Angry

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
1714256795
Hero Member
*
Offline Offline

Posts: 1714256795

View Profile Personal Message (Offline)

Ignore
1714256795
Reply with quote  #2

1714256795
Report to moderator
1714256795
Hero Member
*
Offline Offline

Posts: 1714256795

View Profile Personal Message (Offline)

Ignore
1714256795
Reply with quote  #2

1714256795
Report to moderator
The Bitcoin software, network, and concept is called "Bitcoin" with a capitalized "B". Bitcoin currency units are called "bitcoins" with a lowercase "b" -- this is often abbreviated BTC.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714256795
Hero Member
*
Offline Offline

Posts: 1714256795

View Profile Personal Message (Offline)

Ignore
1714256795
Reply with quote  #2

1714256795
Report to moderator
1714256795
Hero Member
*
Offline Offline

Posts: 1714256795

View Profile Personal Message (Offline)

Ignore
1714256795
Reply with quote  #2

1714256795
Report to moderator
1714256795
Hero Member
*
Offline Offline

Posts: 1714256795

View Profile Personal Message (Offline)

Ignore
1714256795
Reply with quote  #2

1714256795
Report to moderator
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
June 24, 2019, 01:31:18 PM
 #2

I don't believe this story, at least not without more details


Security vulnerabilities in a browser would only affect the website if they're serving web content using the browser software. Who the fuck uses Firefox to serve web content?!?!? Huh

This basically sounds impossible, so someone is very confused about this, not least of all myself



Edit: maybe Coinbase users of Firefox are being targetted? Don't see what makes Coinbase any different to any other exchange, and so it's still baffling tbh

Vires in numeris
Theb
Hero Member
*****
Offline Offline

Activity: 1680
Merit: 655


View Profile
June 24, 2019, 07:18:16 PM
 #3

I don't believe this story, at least not without more details

Well if that's the case what's their main goal in spreading this news? Do they want to create some kind of panic in the market to pull the price down or they just want to force people to update their Firefox? Or since a Google employee is involve do you think they are just damaging the reputation of Mozilla so that they can switch to Chrome? With all the scenarios I have given I think that they don't have a real motive on spreading this kind of news if it was fake, they might just be really concerned about the public's safety and security.

..bustadice..         ▄▄████████████▄▄
     ▄▄████████▀▀▀▀████████▄▄
   ▄███████████    ███████████▄
  █████    ████▄▄▄▄████    █████
 ██████    ████████▀▀██    ██████
██████████████████   █████████████
█████████████████▌  ▐█████████████
███    ██████████   ███████    ███
███    ████████▀   ▐███████    ███
██████████████      ██████████████
██████████████      ██████████████
 ██████████████▄▄▄▄██████████████
  ▀████████████████████████████▀
                     ▄▄███████▄▄
                  ▄███████████████▄
   ███████████  ▄████▀▀       ▀▀████▄
               ████▀      ██     ▀████
 ███████████  ████        ██       ████
             ████         ██        ████
███████████  ████     ▄▄▄▄██        ████
             ████     ▀▀▀▀▀▀        ████
 ███████████  ████                 ████
               ████▄             ▄████
   ███████████  ▀████▄▄       ▄▄████▀
                  ▀███████████████▀
                     ▀▀███████▀▀
           ▄██▄
           ████
            ██
            ▀▀
 ▄██████████████████████▄
██████▀▀██████████▀▀██████
█████    ████████    █████
█████▄  ▄████████▄  ▄█████
██████████████████████████
██████████████████████████
    ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
    ▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
       ████████████
......Play......
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
June 24, 2019, 07:35:31 PM
 #4

I don't believe this story, at least not without more details

Well if that's the case what's their main goal in spreading this news?

the basic angle seems to be : "COINBASE ATTACKED"


maybe it's a hitpiece against mozilla too, but all browsers that interpret javascript are susceptible to these issues really, javascript's so powerful that it's a permanent security nightmare (and hence a bad fit for Bitcoin). This Firefox bug wasn't in the javascript interpreter, but a sandbox escape bug (the sandbox is there to mitigate the damage that malicious javascript can do)

Vires in numeris
Kakmakr (OP)
Legendary
*
Offline Offline

Activity: 3430
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
June 25, 2019, 06:26:54 AM
 #5

Carlton, I am just forwarding the news that I have read on several websites out there, so do not shoot the messenger.  Wink  I also received a zero day warning from a reputable source and they advised me to update any Mozilla Firefox products that I use, because they know I own Crypto currencies.

It might not be a bad idea for other people just to update their software to the latest version to prevent any other possible hacks that might be triggered via this exploit, if it was not plugged.  Wink

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
June 25, 2019, 06:40:17 AM
 #6

Carlton, I am just forwarding the news that I have read on several websites out there, so do not shoot the messenger.  Wink  I also received a zero day warning from a reputable source and they advised me to update any Mozilla Firefox products that I use, because they know I own Crypto currencies.

It might not be a bad idea for other people just to update their software to the latest version to prevent any other possible hacks that might be triggered via this exploit, if it was not plugged.  Wink

relax, the story is weird, but that's not really your fault


I simply don't get why this is being reported as a "Coinbase story". A Coinbase user was affected, so what? It's missing the point completely

Vires in numeris
hatshepsut93
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
June 25, 2019, 07:35:10 AM
Merited by Carlton Banks (1)
 #7

This is kinda old news already: https://www.zdnet.com/article/firefox-zero-day-was-used-in-attack-against-coinbase-employees-not-its-users/

The attack targeted Coinbase employees, not users, hackers sent them phishing emails with malware that abused Firefox bugs, trying to steal sensitive information to penetrate the servers, but according to the article the attack was prevented, reported to Mozilla and they have patched Firefox.


.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Carlton Banks
Legendary
*
Offline Offline

Activity: 3430
Merit: 3071



View Profile
June 25, 2019, 08:04:30 AM
 #8

@hatshepsut93 thanks for doing the legwork, story makes much more sense now


Vires in numeris
Kakmakr (OP)
Legendary
*
Offline Offline

Activity: 3430
Merit: 1957

Leading Crypto Sports Betting & Casino Platform


View Profile
June 26, 2019, 06:02:37 AM
 #9

This is kinda old news already: https://www.zdnet.com/article/firefox-zero-day-was-used-in-attack-against-coinbase-employees-not-its-users/

The attack targeted Coinbase employees, not users, hackers sent them phishing emails with malware that abused Firefox bugs, trying to steal sensitive information to penetrate the servers, but according to the article the attack was prevented, reported to Mozilla and they have patched Firefox.



Yea, I figured as much from the limited information that was provided in the article and what I have read from other sources. It is nice to see that Coinbase is working proactively to prevent hacks and that they are working closely with other reputable entities to prevent "holes" in their system.

In any way, plugging the same "holes" in our own browsers with a update is never a bad idea, because they can easily use the same hole to gather information from users of Coinbase.  Wink

..Stake.com..   ▄████████████████████████████████████▄
   ██ ▄▄▄▄▄▄▄▄▄▄            ▄▄▄▄▄▄▄▄▄▄ ██  ▄████▄
   ██ ▀▀▀▀▀▀▀▀▀▀ ██████████ ▀▀▀▀▀▀▀▀▀▀ ██  ██████
   ██ ██████████ ██      ██ ██████████ ██   ▀██▀
   ██ ██      ██ ██████  ██ ██      ██ ██    ██
   ██ ██████  ██ █████  ███ ██████  ██ ████▄ ██
   ██ █████  ███ ████  ████ █████  ███ ████████
   ██ ████  ████ ██████████ ████  ████ ████▀
   ██ ██████████ ▄▄▄▄▄▄▄▄▄▄ ██████████ ██
   ██            ▀▀▀▀▀▀▀▀▀▀            ██ 
   ▀█████████▀ ▄████████████▄ ▀█████████▀
  ▄▄▄▄▄▄▄▄▄▄▄▄███  ██  ██  ███▄▄▄▄▄▄▄▄▄▄▄▄
 ██████████████████████████████████████████
▄▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▄
█  ▄▀▄             █▀▀█▀▄▄
█  █▀█             █  ▐  ▐▌
█       ▄██▄       █  ▌  █
█     ▄██████▄     █  ▌ ▐▌
█    ██████████    █ ▐  █
█   ▐██████████▌   █ ▐ ▐▌
█    ▀▀██████▀▀    █ ▌ █
█     ▄▄▄██▄▄▄     █ ▌▐▌
█                  █▐ █
█                  █▐▐▌
█                  █▐█
▀▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▀█
▄▄█████████▄▄
▄██▀▀▀▀█████▀▀▀▀██▄
▄█▀       ▐█▌       ▀█▄
██         ▐█▌         ██
████▄     ▄█████▄     ▄████
████████▄███████████▄████████
███▀    █████████████    ▀███
██       ███████████       ██
▀█▄       █████████       ▄█▀
▀█▄    ▄██▀▀▀▀▀▀▀██▄  ▄▄▄█▀
▀███████         ███████▀
▀█████▄       ▄█████▀
▀▀▀███▄▄▄███▀▀▀
..PLAY NOW..
hatshepsut93
Legendary
*
Offline Offline

Activity: 2954
Merit: 2145



View Profile
June 26, 2019, 09:41:03 AM
 #10


It is nice to see that Coinbase is working proactively to prevent hacks and that they are working closely with other reputable entities to prevent "holes" in their system.


It's nothing unusual, people in software, even direct competitors, generally are very responsible and helpful towards each other when it comes to security holes - this is because there are very deep dependency connections, and vulnerability in one program can make thousands of others vulnerable. Remember how Bcash developers privately disclosed a dangerous Bitcoin bug?


In any way, plugging the same "holes" in our own browsers with a update is never a bad idea, because they can easily use the same hole to gather information from users of Coinbase.  Wink

The hackers could have gone for a mass attack against Coinbase and other exchange users, but in that case the hole would be patched very quickly, instead they choose to make a targeted attack, but luckily it was stopped (according to Coinbase).

.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!