The Hacker News

on Friday, 13 September 2013
 

 

The Hacker News
The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers // via fulltextrssfeed.com

Russian Hacker put up an Android Firefox Zero-Day Exploit for Sale
9/13/2013 4:51:00 PM

A Russian Exploit writer and underground Hacker who goes by the handle "fil9" put up an Android Firefox Zero-Day Exploit for Sale in an open Exploit Market.

Author claims a Zero Day vulnerability in Firefox for Android, which works on Firefox versions 23/24/26 (Nightly).

The advertisement was spotted by Joshua, Malware Intelligence Analyst at Malwarebytes. Hacker Selling exploit with a starting price of $460 only.

According to the proof of concept video uploaded by the Hacker, the exploit forces the mobile Firefox browser to download and execute a malicious app, on just visiting a malicious link only.

What's worrisome is that many major websites are compromised frequently and a large number of visitors of those hacked sites can fall victim to this attack.

"The biggest problem in this situation is that Firefox automatically executes certain known files once they're downloaded, and doesn't give users an option to disable this. Without some sort of prompt, users have no idea that an external app has just been executed." Joshua explained.

An attacker can use social engineering tricks, phishing attackers get the user to click a malicious link and thereby exploiting them.

Android Firefox users are recommended to switch to an alternate browser, until Mozilla patches the vulnerability.

Latest Hacking News Updates

Author details

photo of Mohit Kumar

aka 'Unix Root' is Founder and Editor-in-chief of 'The Hacker News'. He is a Security Researcher and Analyst, with experience in various aspects of Information Security. Other than this : He is an Internet Activist, Strong supporter of Anonymous & Wikileaks. Follow him @ Twitter | LinkedIn | | | Facebook Profile

 

You are receiving this email because you subscribed to this feed at feedmyinbox.com

If you no longer wish to receive these emails, you can unsubscribe from this feed, or manage all your subscriptions

0 comments:

Post a Comment