Block Add-on GUID {bbea93c6-64a3-4a5a-854a-9cc61c8d309e}

RESOLVED FIXED

Status

()

defect
P1
normal
RESOLVED FIXED
3 years ago
3 years ago

People

(Reporter: TheOne, Assigned: jorgev)

Tracking

Firefox Tracking Flags

(Not tracked)

Details

The add-on

* hides itself from the add-on manager
* prevents itself from being disabled
* silently downloads and installs other add-ons based on remote data
* prevents connections to the blocklist url and fakes responses
* bypasses the malware domains blocker
* blocks and fakes responses from update service
* blocks and fakes responses for hotfix add-ons

...and more
Assignee

Comment 1

3 years ago
If I understand bug 1251911 correctly, YouTube Unblocker is downloading this add-on, and then this add-on does all the things mentioned in comment #0. Is this correct, Andreas?
Assignee: jorge → awilliamson
Flags: needinfo?(awagner)
Correct.
Flags: needinfo?(awagner)
Assignee

Comment 3

3 years ago
Taking this one since it's fairly urgent.
Assignee: awilliamson → jorge
Assignee

Comment 4

3 years ago
Blocked: https://addons.mozilla.org/en-US/firefox/blocked/i1126
Status: NEW → RESOLVED
Closed: 3 years ago
Resolution: --- → FIXED

Comment 5

3 years ago
Just out of curiosity: is there any way to see a complete list of installed addons, and not the probably "faked" one in the addon manager?
No 100% reliable way. With this add-on, it would be visible in about:support, but as extensions can do anything, they can also hide from any place they would normally show up.
More GUIDs of this add-on that need to be blocked:

{aecf88e4-48b5-4209-b939-6a19cb38207a}
{0490250d-9e0f-42b9-9405-4a6a128f3e49}
Flags: needinfo?(jorge)

Comment 8

3 years ago
if it's the same as in bug 1161259 the maliciously sideloaded addon might have a random ID/name
Based in forum threads https://www.camp-firefox.de/forum/viewtopic.php?f=1&t=114805 and http://www.drwindows.de/programme-tools/96150-warnmeldung-avast-beim-starten-firefox.html

There is strong indication that the following IDs are used by this add-on as well:

{1f43c8af-e9e4-4e5a-b77a-f51c7a916324}
{3a3bd700-322e-440a-8a6a-37243d5c7f92}
{6a5b9fc2-733a-4964-a96a-958dd3f3878e}
{7b5d6334-8bc7-4bca-a13e-ff218d5a3f17}
{b87bca5b-2b5d-4ae8-ad53-997aa2e238d4}
{bf8e032b-150f-4656-8f2d-6b5c4a646e0d}
{d50bfa5f-291d-48a8-909c-5f1a77b31948}
{d54bc985-6e7b-46cd-ad72-a4a266ad879e}
{d89e5de3-5543-4363-b320-a98cf150f86a}
{f3465017-6f51-4980-84a5-7bee2f961eba}
{fae25f38-ff55-46ea-888f-03b49aaf8812}
Product: addons.mozilla.org → Toolkit
You need to log in before you can comment on or make changes to this bug.