RB2: OWASP Day podcast: Exploiting Firefox extensions
NoScript will not save you from Roberto and Nick's uber-cool technique...
August 21, 2009 --
In this special interview you'll hear our New Zealand correspondent Paul Craig interviewing Security-Assessment.com's Roberto Suggi Liverani and Nick Freeman discuss their research into exploiting Firefox extensions.
These guys were doing a review of a large web application and evaluation of a related firefox extension was in scope.
Skype extensions, search toolbars -- all those extensions that people routinely install into their browsers, well, it turns out a lot of them are buggy as hell and these two have figured out how to exploit these little suckers, and at best guess, there's around 30 million boxes out there vulnerable to the extension bugs they've identified.
Recent Posts
-
Public satellite imagery yields a wealth of intelligence...5 days 17 hours ago
-
Awesome feature track this week. Check it out here!5 days 17 hours ago
-
Special guests The Grugq, Singe, Charl and Andrew...1 week 6 days ago
-
Pwnage! Malware! Cats and dogs living together!1 week 6 days ago
-
All your herp derps are belong to RPTs...3 weeks 6 days ago



Recent comments
11 weeks 5 hours ago
12 weeks 1 day ago
14 weeks 5 days ago
21 weeks 1 day ago
21 weeks 3 days ago
22 weeks 2 days ago
25 weeks 22 hours ago
27 weeks 6 days ago
30 weeks 1 hour ago
30 weeks 3 hours ago