Closed
Bug 362103
Opened 19 years ago
Closed 17 years ago
Remote code execution through Conduit toolbars (incl. BBC and Digg toolbars)
Categories
(addons.mozilla.org Graveyard :: Administration, defect)
addons.mozilla.org Graveyard
Administration
Tracking
(Not tracked)
RESOLVED
FIXED
People
(Reporter: jwkbugzilla, Assigned: rbango)
References
()
Details
Attachments
(1 file)
|
645 bytes,
text/html
|
Details |
This is a bug the file ebtoolbar.js used by a few dozen toolbar extensions, e.g. BBC Bar or Australio Radio Toolbar. The toolbars inject a JavaScript object EBToolbarApi into the web pages that has a method ExecuteFunction accepting a string. This method will evaluate the passed string in chrome context.
Testcase coming.
| Reporter | ||
Comment 1•19 years ago
|
||
Install one of the toolbar extensions e.g. BBC Bar and open this testcase. You will be presented a list of your cookies, the page could do anything else as well - with the privileges of your browser.
| Reporter | ||
Comment 2•19 years ago
|
||
I don't have all the extensions on my harddisk but from the ones I have affected are:
* Abandonia Toolbar
* All Yours Chats Toolbar
* Anderson Tech Club Toolbar
* Atom Sounds Toolbar
* Australia-Radio Toolbar
* BBC Bar
* Bob Dawg's Pad Toolbar
* BX Toolbar
* Careforkids Toolbar
* Casino Free Money Toolbar
* Celebar
* Cengoo.de Toolbar
* CG Toolbar
* Cowgirl Image Toolbar
* Cowgird Model Toolbar
* Deutschland Radio
* Digg.com extension toolbar
* DVDEmpire Toolbar
* EZPharmacyFinder Toolbar
Updated•19 years ago
|
Summary: Remote code execution through several toolbar extensions → Remote code execution through several toolbar extensions (incl. BBC and Digg toolbars)
| Reporter | ||
Comment 3•19 years ago
|
||
Since these extensions are no longer hosted at AMO, I looked at conduit.com, clicking on Community I saw that they feature Gotuit Toolbar. Downloaded, it still has exactly the same backdoor in it.
Well, actually I see a whole bunch of Conduit toolbars in the sandbox but none of them seem to have an install box. I downloaded the TexasBar from the URL in the description - and sure enough, this backdoor is there.
| Reporter | ||
Updated•19 years ago
|
Summary: Remote code execution through several toolbar extensions (incl. BBC and Digg toolbars) → Remote code execution through Conduit toolbars (incl. BBC and Digg toolbars)
Comment 4•19 years ago
|
||
Not a lot we can do about it here, since doing a blocklist entry for all of the generated toolbars is basically a non-starter, but I can try to find someone at Conduit to whom to report the bug if you haven't already.
Thanks for the report, it's a pretty serious bug!
| Reporter | ||
Comment 5•19 years ago
|
||
No, I didn't contact them.
Comment 6•19 years ago
|
||
That's fair -- contacting the listed authors isn't very helpful, likely, given their usually significant inability to fix anything or even know what's going on. I'll see what I can do, and we should disable the conduit ones from the sandbox too.
Comment 7•19 years ago
|
||
Mike: any updates on this?
Comment 8•19 years ago
|
||
I sent mail to people at Conduit, haven't heard back. Not much more we can do on this end. :/
Status: NEW → RESOLVED
Closed: 19 years ago
Resolution: --- → FIXED
Updated•17 years ago
|
Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Updated•17 years ago
|
Assignee: nobody → basil
Status: REOPENED → NEW
Updated•17 years ago
|
Assignee: bhashem → rbango
Updated•17 years ago
|
Component: Add-ons → Administration
QA Contact: add-ons → administration
I'm emailing my contact at Conduit. They'd like to get back onto AMO so I'm sure they'll look into this immediately.
| Reporter | ||
Comment 10•17 years ago
|
||
Supposedly they already fixed that issue in July last year but I didn't verify.
| Assignee | ||
Comment 11•17 years ago
|
||
Ok. I've pinged them and asked for confirmation. This recently showed up on my bug list so I was following up.
| Assignee | ||
Comment 12•17 years ago
|
||
I confirmed that it's fixed. Closing this.
Status: NEW → RESOLVED
Closed: 19 years ago → 17 years ago
Resolution: --- → FIXED
Updated•10 years ago
|
Product: addons.mozilla.org → addons.mozilla.org Graveyard
| Reporter | ||
Comment 13•10 years ago
|
||
I think that this should be made public by now.
Flags: needinfo?(jorge)
Updated•10 years ago
|
Group: client-services-security
Flags: needinfo?(jorge)
You need to log in
before you can comment on or make changes to this bug.
Description
•