ALL NEWS ABOUT SAFETY

in #spanish6 years ago

BAD-ONS (1 PART)

ADD-ONS, COMPLEMENTS EXTENSIONS, ARE PROGRAMS THAT IMPROVE OR INCREASE THE ORIGINAL FUNCTIONS OF THE BROWSER. HOWEVER, THESE HELP CAN BE TRANSFORMED INTO A DANGER ...

One of the attractions of browsers such as firefox and chrome is that, with the help of add-ons, they can improve their initial functions: listen to the radio on the internet, block advertising or increase the speed of navigation. However, what many users do not know is that some of these add-ons can also become dangerous. There is the possibility of encountering extensions that become "bad-ons" add-ons that spy on your system. And what can they do?

MINI PROGRAMS WITH MANY RIGHTS

Everything an extension does is something that usually happens in the background. Pro this reason, is also something that usually remains hidden for the user. An example is adblock plus, a very popular extension to block advertising that has many rights, since it analyzes web pages, deletes advertising windows, shows others ... and, for that, compares data, with lists, in the server of the eyeo supplier. This extension constantly obtains information.

EXAMPLE OF ATTACK THROUGH AN EXTENSION

Many extensions can be easily manipulated and used to steal data. To illustrate this, the 1 & 1 security team has analyzed the adblock plus advertising filter, a well-known extension for chrome. The team only needed a few lines of code to turn this extension into an espionage tool capable of cheating many antivirus. By executing a remote command, it can be transformed into a bad-on prepared to transmit to the attackers, secretly, all the entered passwords. Of course, this is just a laboratory experiment. Fortunately, the bad-on we have tried is not freely accessible on the net.

1. In this laptop with chrome, the manipulated extension adblock plus has been installed. Olaf pursche can open your online accounts with her, such as amazon, ebay & co.

2. In the lab, mathias otten controls the server with which the harmless extension will be trasformed as bad-on in order to steal data.

 steemit.com/@ross1977 

Sort:  

Congratulations @ross1977! You have completed some achievement on Steemit and have been rewarded with new badge(s) :

You published 4 posts in one day

Click on any badge to view your own Board of Honor on SteemitBoard.
For more information about SteemitBoard, click here

If you no longer want to receive notifications, reply to this comment with the word STOP

By upvoting this notification, you can help all Steemit users. Learn how here!

Coin Marketplace

STEEM 0.30
TRX 0.12
JST 0.034
BTC 63815.31
ETH 3124.40
USDT 1.00
SBD 3.99