LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   New threat called MarioNet (https://www.linuxquestions.org/questions/linux-security-4/new-threat-called-marionet-4175649048/)

Slackware_fan_Fred 02-25-2019 05:52 PM

New threat called MarioNet
 
The article doesn't say if it affects Linux, etc. or not. all I found is it affects the browser.
https://www.zdnet.com/article/new-br...ve-a-web-page/

hydrurga 02-25-2019 06:13 PM

Using NoScript or similar will help mitigate this threat.

For more information on MarioNet, see the paper presented by its creators:

https://www.ndss-symposium.org/wp-co...ulos_paper.pdf

syg00 02-25-2019 07:11 PM

The problem with noscript is how often you need to temporarily allow access. Doing it manually often introduces more - so, the temptation is to set all to "temp trusted" on that page. Phttt - end of defenses to this sort of thing.
As it happens I never shutdown my browers, I "killall" them. But that is after the horse has bolted ...

hydrurga 02-25-2019 09:55 PM

Quote:

Originally Posted by syg00 (Post 5966903)
The problem with noscript is how often you need to temporarily allow access. Doing it manually often introduces more - so, the temptation is to set all to "temp trusted" on that page. Phttt - end of defenses to this sort of thing.
As it happens I never shutdown my browers, I "killall" them. But that is after the horse has bolted ...

Never give in to temptation. ;) Unless you really have to, of course.

Sandboxing would probably also be a mitigation.

ondoho 02-26-2019 01:46 AM

Quote:

Originally Posted by hydrurga (Post 5966960)
Never give in to temptation.

exactly. if you use noscript, you know this.

even so, this is hardly news... javascript cryptominers... i close my browser, botnet gone :shrugs:

edit: of course chrom/e/ium users have to uncheck "run background services even when closed"

Aeterna 02-28-2019 03:19 PM

this is pretty old article (from Aug, 2018)

out of curiosity, one can always check what is installed:
about:debugging#workers
about:serviceworkers

I have service workers disabled in FF

sevendogsbsd 02-28-2019 03:30 PM

The whole attack scenario is predicated on the end user leaving their browser open as well, no? Guessing these "service workers" require the parent browser process (internet exploder, firefox, chrome, etc) to remain running.


All times are GMT -5. The time now is 09:15 PM.