Firefox add-on spies on Google searches
Wednesday, September 2, 2009
Spyware detected by web security researchers as TSPY_EBOD.A has been infecting Firefox web browsers with an add-on that appears to be an Adobe Flash Player update spread via forum posts.
According to security researchers at Trend Micro, the add-on injects ads into Google search results pages and monitors a user's Google search activity within Firefox, which it sends to a site in the jupdate.com domain.
One of the reasons users have sought out alternative browsers like Firefox, Chrome and Safari is because of malware attacks targeting security holes in Internet Explorer.
Firefox users also seem to prefer the browser for its advanced privacy settings. But this desire for online privacy could potentially undermine Firefox users' online security and leave them vulnerable to cybercriminals who would spy on their activities and attempt to steal their personal information.
Mozilla, the open source project that develops Firefox, recently surveyed Firefox users who chose not to upgrade from Firefox 2 to Firefox 3, even though Mozilla will no longer support version 2 with security patches.
Many of those users cited a feature in Firefox 3 that brings up bookmarks in the address bar.
Mozilla said "a lot of people contacted us to say that they had certain bookmarks they didnt really want to have displayed."

Related News:
Nearly 3,000 smartcard phones infected - 3.19.2010 Nearly 3,000 memory cards in HTC Magic smartphones released by Vodafone were infected by malware before purchase, Vodafone Spain reported on Friday. The initial scare came last week when a researcher for Panda Security discovered the breach on her newly purhcased phone.
Google removes malware-spreading site from searches - 3.19.2010 Google announced on Friday that DealsDirect, Australia's largest discount estore, was temporarily blocked from direct access by users after the search engine detected malware on the site.
Facebook bigger threat to web security than Twitter - 3.19.2010 The amount of information available on a person's Facebook profile page makes the popular social networking site more dangerous than other popular competitors such as Twitter, according to AVG Technologies.
Web security professionals skeptical of national broadband - 3.18.2010 Leading web security experts believe that the recently released National Broadband Program is potentially a major risk to national web security. As more people move from dial-up and other slower forms of internet access, they will be exposed to malware and be unable to handle it.
Authorities call for increased URL regulation - 3.18.2010 In an effort to attack malware at the root of the problem, the Federal Bureau of Investigation and the UK's Serious Organised Crime Agency submitted a new list of recommendations to the Internet Corporation for Assigned Names and Numbers that would make it more difficult to register a domain on the web, according to IT World Canada.
|