Submission + - New Exploit in Firefox-Major Extensions Vulnerable
An anonymous reader writes: Christopher Soghoian, the fake boarding pass guy is at it yet again. He has announced a new vulnerability in the extension update mechanism in the Firefox Web Browser. A number of high profile commercial extensions are vulnerable including Google
Toolbar, Yahoo Toolbar,
Del.icio.us Extension,
Facebook Toolbar,
AOL
Toolbar, Netcraft
Anti-Phishing Toolbar, PhishTank
SiteChecker. A malicious hacker can trick a user's computer into installing malicious software that can spy on the user, or hijack e-banking sessions. Until vendors release updates, users should remove or disable all at risk Firefox extensions.
More information on the vulnerability is available here, while a demo video of one of the attacks can be seen here: (12MB Quicktime).