Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Fixes and Improvements

October 23rd, 2012, 10:38 GMT · By

Possibilities for Malicious Browser Extensions Are Almost Infinite, Researcher Says

SHARE:

Adjust text size:

Malicious browser extensions can be more dangerous than traditional malware
Enlarge picture
The Hacker Halted security conference that’s scheduled to start this week in Miami, Florida will host a number of interesting talks. One of them is made by Hungarian security researcher Zoltan Balazs who wants to demonstrate that we haven’t seen the worst yet as far as malicious browser extensions go.

We’ve often seen malicious browser extensions being utilized for all sorts of tasks, including clickjacking and other attacks that can aid cybercrooks in making a considerable profit.

However, Balazs warns that the capabilities of browser extensions are far beyond what we’ve witnessed so far.

“The possibility of a malicious browser extension is almost infinite, but we have not seen very powerful malicious extensions yet. The protective measures against malicious extensions are in their stone-age, and the number of these malicious extensions rise exponentially,” the expert wrote in the abstract of his presentation.

During his talk, the researcher will unveil proof-of-concept Chrome and Firefox extensions, which function based on a command-and-control architecture, possess rootkit capabilities, and are able to steal sensitive information, execute JavaScript, and manipulate files.

Malicious browser extensions have an advantage over classic pieces of malware because they can evade security systems more easily, Balazs told The Register.

That’s because the threat’s communication channel with the command and control server is not blocked. Firewalls and other security applications might miss malicious extensions because they only detect the browser as communicating with the Internet, which is a legitimate operation.

Furthermore, malicious browser extensions are not limited to a single platform. The expert tested his proof-of-concept on OSX Snow Leopard, Windows 7, Ubuntu 12.04 and Android 2.3.7.

Balazs believes that the risks posed by such extensions can be mitigated if browser vendors ensure that only components that come from trusted sources can be installed.

More specifically, he suggests that vendors should adopt the App Store model and prohibit the installation of components that originate from outside this ecosystem.

Updated to clarify the mitigation solution.


1,169 hits · 2 comments
Link to this article · Print article · Send to friend

MUST-READ RELATED ARTICLES:


Experts to Youths: Control Over Images and Videos Posted Online Can Be Easily Lost

Mikko Hypponen: Stuxnet and Flame Are Like James Bond

Security Solutions Provider Secunia Celebrates 10-Year Anniversary

Softpedia Exclusive Interview: Lynette Owens on Cyberbullying and Amanda Todd Suicide

Most Cyberattacks Are Launched by the United States, Not Against Them, Experts Say

READER COMMENTS:


Comment #1 by: Eric on 23 Oct 2012, 19:44 UTC reply to this comment

Perhaps an oversimplification:

"Balazs believes that the risks posed by such extensions can be mitigated if browser vendors ensure that only components that come from trusted sources can be installed."

What does that even mean? Only from big companies? Or only extensions that are legit? How does one define that? Check every extension and reject those you don't like, creating a central extension store? Doesn't that then lead to censorship?

I don't disagree that extensions are and will become bigger issues from a security standpoint...but sometimes security researches really give abstract solutions that are easier said than done...

Comment #1.1 by: Eduard K on 25 Oct 2012, 06:08 GMT

Thanks for the feedback Eric. I've added some clarifications to explain what the mitigation strategy is all about.

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM