LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-25-2019, 05:52 PM   #1
Slackware_fan_Fred
Member
 
Registered: Oct 2018
Distribution: Slackware64-14.2 Multilib
Posts: 113

Rep: Reputation: 34
Exclamation New threat called MarioNet


The article doesn't say if it affects Linux, etc. or not. all I found is it affects the browser.
https://www.zdnet.com/article/new-br...ve-a-web-page/
 
Old 02-25-2019, 06:13 PM   #2
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
Using NoScript or similar will help mitigate this threat.

For more information on MarioNet, see the paper presented by its creators:

https://www.ndss-symposium.org/wp-co...ulos_paper.pdf
 
Old 02-25-2019, 07:11 PM   #3
syg00
LQ Veteran
 
Registered: Aug 2003
Location: Australia
Distribution: Lots ...
Posts: 21,140

Rep: Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122Reputation: 4122
The problem with noscript is how often you need to temporarily allow access. Doing it manually often introduces more - so, the temptation is to set all to "temp trusted" on that page. Phttt - end of defenses to this sort of thing.
As it happens I never shutdown my browers, I "killall" them. But that is after the horse has bolted ...
 
Old 02-25-2019, 09:55 PM   #4
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
Quote:
Originally Posted by syg00 View Post
The problem with noscript is how often you need to temporarily allow access. Doing it manually often introduces more - so, the temptation is to set all to "temp trusted" on that page. Phttt - end of defenses to this sort of thing.
As it happens I never shutdown my browers, I "killall" them. But that is after the horse has bolted ...
Never give in to temptation. Unless you really have to, of course.

Sandboxing would probably also be a mitigation.
 
Old 02-26-2019, 01:46 AM   #5
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by hydrurga View Post
Never give in to temptation.
exactly. if you use noscript, you know this.

even so, this is hardly news... javascript cryptominers... i close my browser, botnet gone :shrugs:

edit: of course chrom/e/ium users have to uncheck "run background services even when closed"

Last edited by ondoho; 02-26-2019 at 01:47 AM.
 
Old 02-28-2019, 03:19 PM   #6
Aeterna
Senior Member
 
Registered: Aug 2017
Location: Terra Mater
Distribution: VM Host: Slackware-current, VM Guests: Artix, Venom, antiX, Gentoo, FreeBSD, OpenBSD, OpenIndiana
Posts: 1,011

Rep: Reputation: Disabled
this is pretty old article (from Aug, 2018)

out of curiosity, one can always check what is installed:
about:debugging#workers
about:serviceworkers

I have service workers disabled in FF

Last edited by Aeterna; 03-01-2019 at 12:42 PM.
 
1 members found this post helpful.
Old 02-28-2019, 03:30 PM   #7
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
The whole attack scenario is predicated on the end user leaving their browser open as well, no? Guessing these "service workers" require the parent browser process (internet exploder, firefox, chrome, etc) to remain running.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: Python 3.7.0 Released, Timesys Announces New Threat Resistance Security Technology (TRST) Product Protection, Red Hat OpenStack Platfo LXer Syndicated Linux News 0 06-29-2018 03:05 AM
LXer: New ransomware threat deletes files from Linux web servers LXer Syndicated Linux News 0 08-31-2016 05:12 PM
Netflix Could Be Classified As a 'Cybersecurity Threat' Under New CISPA Rules CorytheGeek General 0 07-03-2014 10:11 PM
[SOLVED] Destructor called on objects in deque without it being called explicitly Snark1994 Programming 4 07-13-2011 08:05 AM
Foreign to this strange new world called Linux..... wem0635 LinuxQuestions.org Member Intro 0 09-10-2003 12:03 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:58 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration