Closed Bug 1538141 Opened 5 years ago Closed 5 years ago

Extension block request: {a9c33302-4c97-11e9-9a9d-af400df725e3}

Categories

(Toolkit :: Blocklist Policy Requests, task)

task
Not set
normal

Tracking

()

RESOLVED FIXED

People

(Reporter: rayadohanu, Assigned: Fallen)

Details

Extension name: Security
Extension UUID: {a9c33302-4c97-11e9-9a9d-af400df725e3}
Extension versions to block: all
Applications, versions, and platforms affected: all
Block severity: (hard/soft) hard

Homepage, AMO listing, other references and contact info:
null

Reasons:
decrypted script code

What do you mean by "decrypted script code"?

"decrypted script code" means obfuscated addon code

the same reason was given here: https://bugzilla.mozilla.org/show_bug.cgi?id=1535088

Thank you. Obfuscated code is not a reason for blocklisting. Can you elaborate why this add-on should be blocked?

I think this add-on does things like

Remote code execution
Search hijacking
User tracking
Newtab hijacking

and also cryptomining

Assignee: nobody → philipp
Status: UNCONFIRMED → ASSIGNED
Ever confirmed: true

Reason: remote code execution

The block has been staged. Jorge, can you review and push?

Flags: needinfo?(jorge)

Done.

Status: ASSIGNED → RESOLVED
Closed: 5 years ago
Flags: needinfo?(jorge)
Resolution: --- → FIXED

Hello all.

I thought I would do a test that would check the reliability of the site administrators' work.
Unfortunately, it was fatal for people who verify addons.

I made an add-on myself, which does nothing (random code generated), I obfuscated the code (size about 2kB) and I've added the bugzilla report.

What was my surprise when the administrator saw "remote code injection" :)
A question to admin: can you tell me where I found something in the generated random code:>

Your work is really unreliable.

Status: RESOLVED → REOPENED
Flags: needinfo?(philipp)
Resolution: FIXED → ---

Unfortunately we don't disclose any details about the blocks and the methods we use to verify them. This bug is fixed for its purpose.

Status: REOPENED → RESOLVED
Closed: 5 years ago5 years ago
Flags: needinfo?(philipp)
Resolution: --- → FIXED
Type: enhancement → task
You need to log in before you can comment on or make changes to this bug.