Firefox 3 Alpha Blocks Malware, Secures Plug-in Updates
来源:互联网 发布:java图片断点续传 编辑:程序博客网 时间:2024/06/05 16:01
Mozilla Corp. updated the preview of Firefox 3.0 to alpha 8 Thursday, unveiling for the first time to users several security features it's talked up for months.
Among the security provisions debuting in the new alpha of "Gran Paradiso," the code name for Firefox 3.0, are built-in anti-malware warnings and protection against rogue extension updates, according to documentation Mozilla posted to its Web site.
The malware blocker, which was first mocked up in June, will block Web sites thought to contain malicious downloads. The feature, a companion to the phishing site alert system in the current Firefox 2.0, will use information provided by Google Inc. to flag potentially-dangerous sites, warn anyone trying to reach those URLs with Firefox and automatically block access to the site.
Mozilla also pointed to a URL that demonstrates the new malware blocker for alpha 8 users.
Also taking a bow is a check meant to prevent plug-ins' automatic updates from sending users to malicious sites where they might be infected by attack code or drive-by downloads.
Firefox relies on small plug-ins -- called "extensions" in the Mozilla vernacular -- for much of its power and flexibility. Several thousand extensions have been written, the vast bulk of them by outside developers, that do everything from boost browsing speed to block irritating Flash animations. Firefox regularly checks to see if the installed extensions are up to date, and if not, automatically pulls in the newest version and installs it.
"Firefox automatically checks for updates to add-ons using a URL specified in the add-on's install manifest," Mozilla spells out in a developer's document. "Currently there are no requirements placed on these URLs. In particular, [they are not] required to be https. This allows either the update manifest or the update package to be compromised, potentially resulting in the injection of malicious updates. A demonstration of one form of compromise is already public."
Most extensions are hosted on Mozilla's own servers -- at the servers feeding its Add-ons site -- but some are not; it's those off-site extensions that Mozilla wants to lock down.
To stymie attacks through a compromised extension update, Mozilla will require updates -- both the actual update package and the much smaller "manifest," or notification of an update -- to be delivered over an SSL-secured connection. Or the update must be digitally signed.
The change doesn't affect the initial installation of an extension, something Mozilla recognized. "[This] has no impact on the security of initial add-on installs," it told developers in the online guide.
This newest preview, which can be downloaded in versions for Windows, Mac OS X and Linux from the Mozilla site, still comes with a warning to end users. "Alpha 8 is intended for Web application developers and our testing community. Current users of Mozilla Firefox should not use Gran Paradiso Alpha 8," the browser's release notes.
Mozilla has not officially committed to a release date for the final version of Firefox 3.0.
- Firefox 3 Alpha Blocks Malware, Secures Plug-in Updates
- 在Firefox和Opera等浏览器中使用Plug-In
- Installing flashplayer debug Firefox plug-in on Ubuntu 10.4
- 在Ubuntu下firefox添加java-plug-in
- plug-in
- Mozilla Firefox 3 Alpha 5 RC2
- plug-in for eclipse 3X
- 2007-8-3 Eclipse plug-in
- Eclipse6.5+Flex Builder 3 Plug-in
- updates-documents-nested-in-arrays
- plug-in网址
- C# Plug-in resources
- Eclipse plug-in
- plug in, Basic idea
- ZDA plug-in,删无赦!
- datawindow plug-in
- powerbuilder window plug-in
- Nagios plug-in开发
- 通配符 vs 正则表达式
- Nokia has decided not to develop Carbide.j further
- 微软大中华区CEO陈永正的辞职信
- zlib 1.1.4 手册(Published by spark.fandlr )
- 找出mysql中效率最低的语句
- Firefox 3 Alpha Blocks Malware, Secures Plug-in Updates
- 各种流行编程工具的简介
- GDI+ 画箭头线的方法
- 转 命名规范
- 利用客户端缓存对网站进行优化
- 今天非常残酷
- Unhandled exception in XX.exe:oxc0000005:access violation 错误调试
- .NET上控制台输出的实时截取
- 转 程序注释