LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-14-2013, 11:16 PM   #1
nerdofdarkness
LQ Newbie
 
Registered: Oct 2013
Posts: 28
Blog Entries: 1

Rep: Reputation: Disabled
Can BetterSurf add-on malware attack Mozilla Firefox on Linux?


Chrome and Firefox have been subjected to add-on malware called BetterSurf.

Everything suggests that this primarily surfaces on Windows, but this is an add-on. It might be applicable to Linux.

Possibly some Windows-specific exploit is necessary to get it to show up in the first place. However, if it is Javascript-based, I believe it is possible that hostile web pages might implant it even on Linux. (I am a newbie to Linux and security, so perhaps this malware cannot run on Linux, but until I know that for a fact, I am remaining wary.)

The following info is quoted from the linked source.

http://webapps.stackexchange.com/que...ion-is-malware

the BetterSurf Firefox extension, I am forced to make a new question about this extension.

Beware, it is malware. How it get's onto your machine is still a mystery.

If you do run it, this is what happens: It starts servers listening on 127.0.0.1:0 It steals private information from all local Internet browsers

But this is not the frightening part. There are several other things it does to your PC, including a TASK it schedules to run called AmiUpdXP, which you can find and delete from c:\windows\tasks\AmiUpdXp.job on windows 7.

Other things I have found: A folder is created in your appdata/local called SwvUpdater which is referenced by the Task to run Updater.exe - the frightening part, since it will be able to download and execute any future malware/virus/worm. Server data goes to: hamonetizer.com Update downloads from: hxxp://www.helpfuldownload.com/update.php (borked it so it doesn't create clickable link)
 
Old 11-15-2013, 04:50 AM   #2
Mr. Bill
Member
 
Registered: Mar 2011
Location: Maryland, USA
Distribution: Xubuntu 14.04 - 64
Posts: 185

Rep: Reputation: 14
You are correct in not assuming that Linux is 100% failsafe- it is not. While it may be nearly impossible to bork your system files with the traditional virus attacks, not many hackers go that route today. Linux-specific or multi-platform worms or trojans could theoretically still perform their duties, including using your Linux PC as a spam server or in a bot-net for DoS attacks, for example. While I use Linux exclusively, I am still behind a router/firewall with name/password changed and security settings higher than factory default.
 
Old 11-15-2013, 07:30 PM   #3
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,321
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
Linux is not immune to browser exploits.
 
Old 11-15-2013, 09:42 PM   #4
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
nor other exploits
last year there was a Mac drive by that was able to run on linux
All you had to do to uninstall it was reboot

linux is NOT 100% free
99.999% free, but not 100.0000000%

if YOU install the virus or malware then ... well YOU installed it
 
  


Reply

Tags
malware



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Linux wiper malware used in South Korean attack LXer Syndicated Linux News 0 03-22-2013 09:12 PM
LXer: Mozilla says Microsoft browser malware can Firefox off LXer Syndicated Linux News 1 10-18-2009 02:12 PM
[SOLVED] May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 22 08-17-2008 01:05 PM
May have contracted malware. Yes, malware. Firefox on Ubuntu Fiesty. Seeking a fix drachenchen Linux - Security 1 06-12-2008 05:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:57 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration