Home > Security Tips > Web Security Advisor > Is Firefox spyware's next target?
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

WEB SECURITY ADVISOR

Is Firefox spyware's next target?


Jonathan Hassell
07.13.2005
Rating: -3.73- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



What you will learn from this tip: Where Firefox stands in the battle against spyware and the browser's future as a secure alternative for Web surfing.

Security practitioners love to trumpet Firefox as the perfect solution to the massive amount of vulnerabilities that plague Microsoft's flagship browser, Internet Explorer. It's true that IE has more than its fair share of problems. At the very least, it's an easy target for spyware. But is Firefox a better alternative for providing users a safe browsing experience?

Let's start with a broad view.

Firefox doesn't have anything close to a perfect security record. Version 1.0.1, released in February, is purported to fix 17 vulnerabilities found in the previous version (More information). The most serious of the vulnerabilities allows an exploit to trick a user into thinking he is at one site while he is actually at a spoofed site with malicious intentions.

The latest version of Firefox is susceptible to other vectors of infestation. Today's malware generally communicates with a Web browser directly over port 80 — obviously something required by the design of Firefox — or by inserting itself as a layered service provider (LSP). Firefox decisively supports LSPs, so malware that targets Firefox and takes advantage of that attack vector will likely be successfully installed. Keyloggers can also pose a potential problem for Firefox users, as Firefox provides a layer of application programming inside of which crackers can plant nefarious code to track keyboard activity.

When we look at spyware, the picture is a little murkier. To date, I'm not aware of any officially announced spyware attacks on Firefox. But they aren't far off. There are rumors of spyware that bypasses the integrated defenses within Firefox and infects Internet Explorer indirectly. It goes something like this: You visit a site using Firefox on a machine that also has the Sun Java Runtime Env



ironment (JRE) installed. The malware targets a bit of code at a weak spot in Firefox and then, through the JRE, begins downloading numerous packages of adware and spyware. IE, once loaded by the user, falls victim to programs. This exploit works with Firefox, Mozilla, the Avant Browser wrapper for IE and Netscape. This is bad for a couple of reasons. First, it demonstrates that Firefox is penetrable and can be used in an attack. And two, if Firefox can serve as a attack vector for malware, that's effectively just as bad as becoming infected itself.

It appears that it's possible for this type of malware to pierce the veil of security that currently resides over Firefox. The aforementioned exploit is perhaps the most direct evidence I've seen to date that Firefox is at risk for these types of attacks, but Webroot and Sunbelt Software are predicting that spyware targeting Firefox will begin appearing this year. And if we don't see spyware targeting Firefox this year, we most certainly will in 2006.

Obviously, Firefox was never the perfect solution to the problems that plague IE. But it is a safer alternative. I use it regularly and prefer it to the current version of IE. I have no doubt that Firefox was designed with security as at least a fundamental consideration, rather than an afterthought as it seems is the case with IE to the present. After all, Firefox's pop-up blocker, ActiveX control blocker and suite of privacy features are evidence of this.

It's impossible to create perfect software. As Firefox's installed base, particularly on Windows, continues to increase, it's only fair and logical to expect Firefox compromises to continue to be discovered and rectified. The ultimate advantage Firefox has — now and presumably in the future, too — is the backing of passionate, empowered developers that can create fixes to such issues much more quickly and efficiently than Microsoft can.

About the author
Jonathan Hassell, a systems administrator and IT consultant in the Charlotte, N.C. area, is the author of several books, including Hardening Windows and Managing Windows Server 2003. He regularly speaks at conferences and contributes articles on Windows administration and network security.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Web Security Advisor,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Browser Security,   Malware, Viruses, Trojans and Spyware,   Information Security Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Web Security Advisor
DNS rebinding defenses still necessary, thanks to Web 2.0
New defenses for automated SQL injection attacks
PCI compliance and Web applications: Code review or firewalls?
Worst practices: Bad security incidents to avoid
Web scanning and reporting best practices
Social networking Web site threats manageable with good enterprise policy
Enterprise security in 2008: Building trust into the application development process
PCI DSS Section 6: A plan for tackling application security
Making the case for Web application vulnerability scanners
Preparing for uniform resource identifier (URI) exploits

Web Browser Security
Security researchers develop browser-based darknet
Microsoft cracks down on click fraud ring
Mozilla patches 11 Firefox security flaws, JavaScript errors
Microsoft patches WebDAV security vulnerability in bevy of updates
IT pros can detect, prevent website vulnerabilities, thwart attacks
Stolen FTP credentials likely in massive website attacks
Trust eroding as social engineering attacks climb in 2009, says Kaspersky expert
IT managers under pressure to weaken Web security policy
US-CERT warns of Gumblar, Martuz drive-by exploits
Google study backs browser silent auto update feature
Web Browser Security Research

Malware, Viruses, Trojans and Spyware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises
PCI compliance requirement 5: Antivirus
Hacker attack techniques and tactics: Understanding hacking strategies
Rootkit Hunter demo: Detect and remove Linux rootkits
Botnet threats and countermeasures
Conficker worm much smaller than feared
New Conficker variant has ties to Storm botnet

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
browser hijacker  (SearchSecurity.com)
cache cramming  (SearchSecurity.com)
cache poisoning  (SearchSecurity.com)
honey monkey  (SearchSecurity.com)
JavaScript hijacking  (SearchSecurity.com)
NCSA  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts