{"id":2979,"date":"2010-10-21T11:12:36","date_gmt":"2010-10-21T10:12:36","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=2979"},"modified":"2015-09-09T19:37:25","modified_gmt":"2015-09-09T11:37:25","slug":"malware-pushers-abuse-firefox-warning-page","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2010\/10\/malware-pushers-abuse-firefox-warning-page\/","title":{"rendered":"Malware Pushers Abuse Firefox Warning Page"},"content":{"rendered":"

This is a pretty neat attack from the malware pushes leveraging on the ignorance of the average user – which in all honestly is a safe bet most of the time! You could consider it a Social Engineering<\/a> attack as it’s taking something that’s familiar and changing it to deliver malware.<\/p>\n

I’m sure all the Firefox users reading have at some point or another been faced with the warning screen that tells you a site is not safe to visit, the red page which states in big white letters “Reported Attack Page!”.<\/p>\n

Hackers have subverted warnings generated by Firefox about dangerous sites to punt fake anti-virus portals.<\/p>\n

Surfers straying onto a web page offering the “Security Tool” rogue anti-virus are offered a warning page that convincingly mimics the genuine Firefox block page. The site offers supposed updates for Mozilla’s technology that are actually scareware packages.<\/p>\n

If Windows users apply these updates they will be falsely warned that their system is infected and continuously nagged into buying worthless scareware packages that serve only to line the pockets of cyber-scammers.<\/p>\n

The rogue application will automatically attempt to install itself on the machines of prospective marks in cases where scripts are enabled, net security firm F-Secure warns.<\/p><\/blockquote>\n

Personally I’d say this attack would be pretty effective, my only question would be – how would the user land on that site in the first place? I guess through the normal channels (e-mail spam, facebook wall worms and so on).<\/p>\n

After landing the user would realize they’ve been spammed\/scammed and see the Firefox warning…then download the ‘security update’ and install it – unknowingly pwning themselves in the process.<\/p>\n