Through their toolbars

May 31, 2007 12:08 GMT  ·  By

The toolbars designed by Yahoo and Google might harm the users' computer because the hackers can use some security flaws to connected to an affected system. All the problems are caused by the add-ons installed in the Firefox browser that are meant to bring new functions to the application but, instead of doing that, it causes a lot of problems. Christopher Soghoian, a student from Indiana University said for Wired Blogs that several add-ons such as Google Toolbar, Yahoo Toolbar, Facebook Toolbar and Del.icio.us extensions might create some security holes that can be exploited by an attacker to gain administrator privileges on an affected system.

As you know, the toolbars designed by the two Internet giants, Google and Yahoo, contain several security functions that can protect users' computers. Along with the popup blocker, the toolbars are also offering features to discover phishing websites that are trying to exploit users' computers and obtain financial information.

"The bitter irony here, is that by downloading an anti-phishing toolbar, you're currently making yourself more vulnerable than if you had never downloaded it at all," Soghoian said according to Wired Blogs. "It's totally trivial to spot. This is in no way a major piece of computer security research. The work of attempting to harass the vendors into fixing the flaw has taken far more time than finding it. My suspicion is that Google/Yahoo's extension teams never asked their security teams their opinion," he added.

It seems that there is only one solution to avoid a successful exploitation of the vulnerabilities: uninstall all the third-party extensions that are not published on the official page of Mozilla Add-ons. As you might have observed, this official website is based on a secure protocol, the page being preceded by https:// instead of the common http://.