The Inquirer-Home

Visitors to Nobel website get a different prize

Not what they expected
Wed Oct 27 2010, 16:15

WEB BROWSER OUTFIT Mozilla has admitted to a zero-day security flaw in Firefox that saw the Nobel Prize website offering up malware.

Windows users of Firefox 3.5 and 3.6 visiting the website were infected by a Trojan that gives the attacker complete control of the user's machine. The insecurity vendor Norman, in its threat analysis said that once the machine is infected, the Trojan creates registry keys to automatically start during Windows' bootup.

Mozilla has acknowledged the vulnerability and confirmed it is working on a fix. In the meantime, affected users who visit the Nobel Prize website find that Firefox's malware protection feature throws up a warning message. The problem with this method of containment is that Mozilla doesn't know if other websites have similar drive-by download exploits.

To counter such a threat on a more general level, Mozilla suggest disabling Javascript or using the Noscript add-on.

Drive-by download attacks are becoming an increasingly common method to push malware onto unsuspecting web users. Making use of holes in scripting language interpreters such as Javascript and Microsoft's ActiveX has been standard practice for many years. Generally it is recommended to disable scripts on all but trusted websites, though few would have thought the Nobel Prize website would end up inadvertently peddling malware.

It seems that this time some Firefox users got caught out while trying to find out which bright spark received a Nobel gong. µ

 

Share this:

Comments
@Narg

Read up on the topic before you post dump comments

posted by : Ein, 28 October 2010 Complain about this comment
@Narg

May I recommend you re-read the article and then research the difference between java and javascript.

posted by : Steve, 28 October 2010 Complain about this comment
LOL

Fist they give the Nobel Peace prize to the guy in charge of TWO invasions, something we hadn't seen since Hitler.

Now they give away malware too...

This organization has become a bad joke. They should pack up their toys and go home.

posted by : Mike, 27 October 2010 Complain about this comment
Chinese payback

The chinese were pissed one of their own dissidents got a nobel prize and are making supporters of the nobel stuff pay... Testing new malware.

posted by : observant, 27 October 2010 Complain about this comment
Java SUCKS!

I've been saying for years that Java is a very BAD platform. At least Apple is taking sides with me on this.

Dump Java, or you will continue to get pounded by exploits such as these.

posted by : Narg, 27 October 2010 Complain about this comment
aboutus
Advertisement
Subscribe to INQ newsletters
Advertisement
INQ Poll

Facebook starts selling shares

Will you buy Facebook shares?