Closed
Bug 713050
Opened 14 years ago
Closed 14 years ago
Malicious "Free Cheesecake Factory" Add-On
Categories
(Toolkit :: Blocklist Policy Requests, defect)
Toolkit
Blocklist Policy Requests
Tracking
()
RESOLVED
FIXED
People
(Reporter: mhammell, Assigned: fligtar)
References
()
Details
(Whiteboard: [extension][hardblock])
User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7
Steps to reproduce:
The third-party add-on "Free Cheesecake Factory" is malicious is actively generating spam on Facebook. It steals the user's browser cookies for Facebook and sends out numerous messages on the users behalf. It also takes actions to hide its activity by injecting an overlay image into the DOM when the user attempts to view their news feed in Facebook. The malicious plugin and the JS files it loads remotely are attached.
Actual results:
Installed the malicious "Free Cheesecake Factory" add-on and it resulting in spam being posted to a Facebook account.
Updated•14 years ago
|
Assignee | ||
Updated•14 years ago
|
Assignee: nobody → fligtar
Comment 1•14 years ago
|
||
Assignee | ||
Comment 2•14 years ago
|
||
UUID youtube@youtube2.com
Status: UNCONFIRMED → NEW
Ever confirmed: true
Whiteboard: [extension][hardblock]
Assignee | ||
Comment 3•14 years ago
|
||
yes, I midaired you and didn't care :p
Assignee | ||
Comment 4•14 years ago
|
||
Blocked in production.
https://addons.mozilla.org/en-US/firefox/blocked/i47
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Assignee | ||
Comment 5•14 years ago
|
||
Yikes, this add-on had 600,000 users and was growing about 50,000 per day until it was blocked.
Assignee | ||
Comment 6•14 years ago
|
||
Please file these bugs in Blocklisting component in the future.
Component: Add-on Security → Blocklisting
Updated•9 years ago
|
Product: addons.mozilla.org → Toolkit
You need to log in
before you can comment on or make changes to this bug.
Description
•