Closed Bug 1517154 Opened 5 years ago Closed 5 years ago

Blocklist more PDF print and save clones

Categories

(Toolkit :: Blocklist Policy Requests, task)

52 Branch
task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: Fallen, Assigned: Fallen)

Details

There are more add-ons like bug 1516488 with a remote iframe that seems to be doing background coin mining.


Guids to block:

{942e0fec-19f2-4ebc-8a74-009da7fa625d}
{cae82615-f7be-4aff-875d-33da1bc93923}
{ff1c4e62-7c11-4ea7-b734-3462417ceeb5}
{00cf6ee0-14f3-4e35-a4fd-d2160fe2f05e}
{f15cfa53-fa9b-43cf-84e8-16ece6695922}
{8b1dd8f3-224b-4975-bda2-cb2dd184d4d8}
{7b402578-ddec-4eee-9c8b-98e4e8db0059}
{da0fa57e-17d3-40d3-99f8-e9d5b2a7759d}
{105c14a6-8b6f-49ef-b0d6-41bad99ad5e8}
{87a8a08c-82a8-4d1d-8b80-f7b5cd4751bf}
{ffa0a57e-17d2-41d3-96f8-e8d5b2a0759d}
{396056fc-1697-4954-b535-06de8d62fe1b}
{591468f8-ebbd-497a-92f1-fa0a1206adb4}
{5f6c3eb8-aa32-489a-bb01-b12b23d2001a}
{7ae2bde0-f7ea-4bf3-a055-06953f9fcf31}
{e164563a-1512-4b81-99ff-95f2644c4075}
{6cbb397a-d865-42b2-8454-25a75b710dff}
The block has been staged. Jorge, can you review?
Flags: needinfo?(jorge)
I might be able to add a few more to the mix, running another query. If you get to this early I'll just add another bug, otherwise I'll comment here.
Full list, including those from comment 0:

{00cf6ee0-14f3-4e35-a4fd-d2160fe2f05e}
{0da583da-e623-41f2-b2d2-0ac61b493171}
{105c14a6-8b6f-49ef-b0d6-41bad99ad5e8}
{10a15a74-271f-4098-a662-bd827db4f8bc}
{13e02b9b-2797-4100-8144-65b73c4145c4}
{1eb56568-8a30-42b1-a646-ad9f485f60fe}
{1eb8a08c-82a8-4d1d-8b80-f7b5cd4751bf}
{2f8220a8-b2a7-4277-ba6b-bdcb6958f669}
{33f39a5d-137c-4757-9f9d-e86395c8bf20}
{347ca189-9e63-43d2-8a2f-5d5141598bdc}
{396056fc-1697-4954-b535-06de8d62fe1b}
{3d530918-dbe8-442c-8faf-1f4ca7ca8ab9}
{3e283c2e-cde3-4baa-8076-226ca8fb90ef}
{591468f8-ebbd-497a-92f1-fa0a1206adb4}
{5f6c3eb8-aa32-489a-bb01-b12b23d2001a}
{6cbb397a-d865-42b2-8454-25a75b710dff}
{7ae2bde0-f7ea-4bf3-a055-06953f9fcf31}
{7b402578-ddec-4eee-9c8b-98e4e8db0059}
{7fb00cf7-40d3-4415-a0c8-a48d3fbe847f}
{87a8a08c-82a8-4d1d-8b80-f7b5cd4751bf}
{888220a8-b2a7-4277-ba6b-bdcb6958f669}
{8b1dd8f3-224b-4975-bda2-cb2dd184d4d8}
{8bcdc9cc-f6be-4203-ae43-a9d281f0bcdb}
{8cda9ce6-7893-4f47-ac70-a65215cec288}
{8dc9b946-0bb9-4264-9c76-fd9ff1e159a2}
{942e0fec-19f2-4ebc-8a74-009da7fa625d}
{b2a720a8-b2a7-4277-aa6b-bdeb6958f669}
{bdcf953b-d2aa-4e7a-8176-aeb1e95a0caf}
{cae82615-f7be-4aff-875d-33da1bc93923}
{d2aa953b-bdcf-4f7a-8476-ddb1e9500caf}
{da0fa57e-17d3-40d3-99f8-e9d5b2a7759d}
{da1237ca-e35d-4653-b2b5-d98043f33781}
{e164563a-1512-4b81-99ff-95f2644c4075}
{e2a720a8-b3a7-1277-aa2b-bdeb2958f669}
{e6a90490-6ef7-407d-863a-7dd120f6f7dc}
{f15cfa53-fa9b-43cf-84e8-16ece6695922}
{f722c845-2d8b-4a0a-b518-4f39af703e79}
{ff1c4e62-7c11-4ea7-b734-3462417ceeb5}
{ffa0a57e-17d2-41d3-96f8-e8d5b2a0759d}
Pushed live.
Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Flags: needinfo?(jorge)
Resolution: --- → FIXED
You have blocked youtube video downloader 2.2.2 which I use all of the time, very unhappy. It does not contain any background coin mining,as I check CPU usage for any extensions I use. please unblock.
I'm sorry to hear. It is not limited to coin mining, there are a few other issues with these add-ons. Please check on addons.mozilla.org, there are a bunch of alternative youtube downloaders.
(In reply to Philipp Kewisch [:Fallen] [:📆] from comment #6)
> I'm sorry to hear. It is not limited to coin mining, there are a few other
> issues with these add-ons. Please check on addons.mozilla.org, there are a
> bunch of alternative youtube downloaders.

hi
can you please suggest a good one.
tnks
rion
Thank you for finding these issues Philipp! I was also surprised to see my translate plugin blocked.

If you don't mind:
    What is the protocol (and maybe even a brief discussion of the method) for finding these problems? I am using a host file (dns blacklist) so they may not exhibit themselves on my machine. Perhaps a combination of DNS information with netstats ?

I would of course much rather see these things happen before plugins make it to the store and am guessing Apple's AppStore (and finally now GooglePlay) Are including a wide number of prechecks. 

But come to think of it, I probably didn't get this from an official Firefox download site; not sure. Mozilla should consider certifying and signing these, and offering a "signed only" mode of operation.
Thank you everyone for the comments and inquiries you have made here, I understand this is an issue that brings up a lot of questions. At the same time, this is a bug tracker meant mostly for technical discussion around the actions taken. Note also we generally don't discuss the methodologies or details about the block.

Therefore, I am restricting comments to this bug. If you have further questions, please post them to our discussion forums: https://discourse.mozilla.org/c/add-ons .

Thank you for your understanding.
Restrict Comments: true
Assignee: nobody → philipp
Type: enhancement → task
You need to log in before you can comment on or make changes to this bug.