Microsoft Sabotaging Firefox With Sneaky .NET Updates?
Page 1 of 1
tainted4ever
VIP Member



Posts: 11336

PostPosted: Sun, 31st May 2009 23:38    Post subject: Microsoft Sabotaging Firefox With Sneaky .NET Updates?
http://startupearth.com/2009/05/31/microsoft-sabotaging-firefox-with-sneaky-net-updates/

Quote:

Sabotage may be a strong choice of word, but it immediately came to mind with the news of Microsoft’s latest .NET update.

The Microsoft .NET Framework 3.5 Service Pack 1, unleashed in February, forces an undisclosed Firefox extension on Windows users, called “Microsoft .NET Framework Assistant 1.0″, and it does so without asking the users permission.

To add insult to injury, the extension not only injects a serious security vulnerability into Firefox (also present in Internet Explorer), but it disables the uninstall button, meaning the only way to get rid of it, is to edit the Windows registry - a course of action not recommended for your usual non-tech-savvy user, as dabbling in the dark arts of registry editing can open you up to a slew of problems, and potentially kill Windows altogether.

A report by annoyances.org ominously states..

Quote:
“This update adds to Firefox one of the most dangerous vulnerabilities present in all versions of Internet Explorer: the ability for websites to easily and quietly install software on your PC. Since this design flaw is one of the reasons you may’ve originally choosen to abandon IE in favor of a safer browser like Firefox, you may wish to remove this extension with all due haste.”


The official purpose of the add-on is to add ‘One-Click’ support and the ability to report installed .NET framework versions to the web server, but it also allows websites to install software on a users PC without their knowledge. This is a very serious security flaw that effectively turns Firefox into an open gateway for malware, much like Microsoft’s own web browser, Internet Explorer.

At best, one could call this stealth install a serious conflict of interest between competing browsers - at worst, it’s out-and-out sabotage, not only of a user’s PC, but of Firefox itself, which has gained a reputation for stability and security, much to the chagrin of Microsoft.

In forcing this add-on down the throats of faithful Firefox users, Microsoft have circumvented the more honest approach to installing Firefox extensions, via the offical Mozilla Add-ons page, betraying the trust of its users in the process.

Microsoft Internet Explorer currently enjoys a market share of 66% due only to it’s forced integration with the Windows operating system, but Firefox is rapidly gaining ground, currently at an estimated 22% and climbing. Being a competitor in the browser market, Microsoft have absolutely no business injecting stealth add-ons into Firefox, let alone blocking them from the uninstall process.

If you’ve been affected by this malicious update, you can follow the removal instructions provided by annoyances.org.


http://startupearth.com/2009/05/31/microsoft-sabotaging-firefox-with-sneaky-net-updates/

Removal:
http://annoyances.org/exec/show/article08-600

The vulnerability is serious. Allows installation of anything on your computer, as well as loading any DLL on your computer. Thought you might wanna remove it Smile
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Sun, 31st May 2009 23:43    Post subject:
Quote:

To add insult to injury, the extension not only injects a serious security vulnerability into Firefox (also present in Internet Explorer), but it disables the uninstall button, meaning the only way to get rid of it, is to edit the Windows registry


Odd. I didn't even know I had this addon - but checking the Addons tab shows a fully functioning "uninstall" button - and it works too, without reg-editing.
Back to top
VGAdeadcafe




Posts: 22230
Location: ★ ಠ_ಠ ★
PostPosted: Sun, 31st May 2009 23:59    Post subject:
What ? My uninstall is disabled.

Also, I had disabled this shitty addon, but now it's enabled. Must have been re-enabled after some Firefox update or windows update.

I'll remove it pronto.

EDIT: It's gone, thanks t4e Wink
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Mon, 1st Jun 2009 00:02    Post subject:
I just removed mine too. Don't want any fucking IE exploits and holes in my Firefox, thankyouverymuch. I honestly could uninstall though, no faffing about with registry or anything;

Back to top
VGAdeadcafe




Posts: 22230
Location: ★ ಠ_ಠ ★
PostPosted: Mon, 1st Jun 2009 00:24    Post subject:
Are you using latest stable Firefox ? 3.0.10 ?

Maybe MS changed the installation of this update at some point to NOT disable the uninstall option (later)

Later edit : Oh, yeah, you have 1.1, most of us have 1.0


Last edited by VGAdeadcafe on Mon, 1st Jun 2009 03:38; edited 1 time in total
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel 🇮🇱
PostPosted: Mon, 1st Jun 2009 00:32    Post subject:
I've had this crap disabled since who knows when. Didn't know it was vulnerable, but didn't want it running with ffox anyway.
Back to top
PumpAction
[Schmadmin]



Posts: 26759

PostPosted: Mon, 1st Jun 2009 00:38    Post subject:
I didn't care that much because I'm a happy opera user, but I'm uninstalling it right now, after I realized, that I need the FF to play quake live Very Happy


=> NFOrce GIF plugin <= - Ryzen 3800X, 16GB DDR4-3200, Sapphire 5700XT Pulse
Back to top
sabin1981
Mostly Cursed



Posts: 87805

PostPosted: Mon, 1st Jun 2009 02:11    Post subject:
VGAdeadcafe wrote:
Are you using latest stable Firefox ? 3.0.10 ?

Maybe MS changed the installation of this update at some point to NOT disable the uninstall option (later)


Aye, 3.0.10 bud. This update was released back in Feb, so yeah.. it stands a good chance that the "cannot uninstall" glitch/whatever was fixed in the meantime.
Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Mon, 1st Jun 2009 03:02    Post subject: Re: Microsoft Sabotaging Firefox With Sneaky .NET Updates?
tainted4ever wrote:
The vulnerability is serious. Allows installation of anything on your computer, as well as loading any DLL on your computer.
PoC please
Back to top
todd72173




Posts: 2403

PostPosted: Mon, 1st Jun 2009 03:13    Post subject: Re: Microsoft Sabotaging Firefox With Sneaky .NET Updates?
Rinze wrote:
tainted4ever wrote:
The vulnerability is serious. Allows installation of anything on your computer, as well as loading any DLL on your computer.
PoC please


You are running 1.1. The update involved is 1.0. I have 1.0 and the uninstall button is not selectable. Time to manually uninstall it! I hate microsoft!


RYZEN 5 2600|RADEON 570| |ASRock X370 Killer|DDR4@2800Mhz||Corsair SPEC-05 Case|AOC G2590FX 24.5''144hz 1ms|
Back to top
tainted4ever
VIP Member



Posts: 11336

PostPosted: Mon, 1st Jun 2009 03:30    Post subject: Re: Microsoft Sabotaging Firefox With Sneaky .NET Updates?
Rinze wrote:
tainted4ever wrote:
The vulnerability is serious. Allows installation of anything on your computer, as well as loading any DLL on your computer.
PoC please
Can't find any. Just relaying word of mouth.
Back to top
todd72173




Posts: 2403

PostPosted: Mon, 1st Jun 2009 03:57    Post subject:
I uninstalled 1.0 following link in post#1. Had to go thru reg edit, etc...Thanks!


RYZEN 5 2600|RADEON 570| |ASRock X370 Killer|DDR4@2800Mhz||Corsair SPEC-05 Case|AOC G2590FX 24.5''144hz 1ms|
Back to top
Rinze
Site Admin



Posts: 2343

PostPosted: Mon, 1st Jun 2009 04:12    Post subject: Re: Microsoft Sabotaging Firefox With Sneaky .NET Updates?
tainted4ever wrote:
Rinze wrote:
tainted4ever wrote:
The vulnerability is serious. Allows installation of anything on your computer, as well as loading any DLL on your computer.
PoC please
Can't find any. Just relaying word of mouth.
Thought so, neither claim is true then.
Back to top
LeoNatan
☢ NFOHump Despot ☢



Posts: 73196
Location: Ramat Gan, Israel 🇮🇱
PostPosted: Mon, 1st Jun 2009 04:25    Post subject:
The media always likes to come with bombastic and way over-reactive statements to fuel on paranoia. And it works, doesn't it? It has probably been posted on several sites, just like here, and the site has got some publicity. Smile
Back to top
morgan2468




Posts: 91
Location: Northumberland
PostPosted: Mon, 1st Jun 2009 09:59    Post subject:
Unstalled following the first post Smile thanks for the advice


He poured his children's eyes from glass / And from steel wrought their hands / That none could escape his judgment. -- The New Scripture of the Master Builder
Back to top
manu_xl




Posts: 881

PostPosted: Mon, 1st Jun 2009 13:29    Post subject:
thanks. i removed the crap
Back to top
tainted4ever
VIP Member



Posts: 11336

PostPosted: Mon, 19th Oct 2009 22:09    Post subject:
More news on this:
Mozilla unblocks one sneaky Microsoft add-in

http://www.computerworld.com/s/article/9139557/Mozilla_unblocks_one_sneaky_Microsoft_add_in?taxonomyId=125


Sense Amid Madness, Wit Amidst Folly
Back to top
VGAdeadcafe




Posts: 22230
Location: ★ ಠ_ಠ ★
PostPosted: Mon, 19th Oct 2009 22:41    Post subject:
Good, blocking suspicious plugins is good, go on Mozilla Very Happy
Back to top
Page 1 of 1 All times are GMT + 1 Hour
NFOHump.com Forum Index - Applications
Signature/Avatar nuking: none (can be changed in your profile)  


Display posts from previous:   

Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum


Powered by phpBB 2.0.8 © 2001, 2002 phpBB Group