Clever nefarious method of installing probably infected Firefox version
Categories
(Firefox :: Installer, enhancement)
Tracking
()
People
(Reporter: bugzilla.daydream735, Unassigned)
Details
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/110.0
Steps to reproduce:
I searched for a question I had about towing with a car with a capacity of 3500lbs and got a page that indicated my Firefox was out of date and needed updating. I immediately went to the Help page to check and it indicated I was up to date.
More than suspicious.
Problematic page: https://outdoordriving.com/what-can-i-tow-with-3500-lb-capacity/
Actual results:
An attempt was made to replace my Firefox installation with another from a non-Mozilla site.
Note the following information was encoded in the destination link:
browser=Unknown
zoneid=2188318
bannerid=2142834
os=Windows
country=United+States
region=Seattle
isp=CenturyLink
useragent=Mozilla%2F5.0+
Windows+NT+10.0
Win64%3B+x64
Gecko
Firefox
110.0
language=11
placement=18299578
subid=1d673905f3848019de1beabbee7c9126
hsh=7132266533280
Expected results:
Nothing. My Firefox installation is fine.
Comment 1•3 years ago
|
||
I will set this enhancement as new so the engineering team could take a look at this.
If this is not the correct component, please feel free to change it to a more appropriate one.
Comment 2•3 years ago
|
||
I don't think that there is much that we, in engineering, can do about this. I submitted the URL to the Safe Browsing form. I believe that that should result in it shortly being added to the Safe Browsing database, which should warn users before going to that page.
But as far as engineering, I don't think that there is anything to be done here. We can't easily tell that a website is advertising something that it shouldn't be. I think the best that we can do is rely on the Safe Browsing database, which we already do.
Thanks for your report, but since I don't believe there to be anything actionable engineering-wise, I'm going to go ahead and close this.
Description
•