• Log In
  • Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

Ethical Hacking

Wade Mackey

Ethical Hacking

MIS 5211.702 ■ Fall 2020 ■ Wade Mackey
  • Home
  • About
  • Syllabus
  • Gradebook

In the News Article

September 21, 2020 by Rudraduttsinh Leave a Comment

A Vulnerability identified in Firefox for android could have been exploited to remotely open arbitrary websites on a targeted user’s phone without the need to click on links, install malicious applications, or conduct man-in-middle (MitM) attacks.

The flaw was discovered by researcher Chris Moberly in version 68 of the Firefox for android. According to Moberly, the vulnerability is related to Firefox periodically sending out SSDP discovery messages in search of a second-screen device that I can cast to. These messages can be seen by any device that is connected to the same LAN. AN attacker connected to the same WI-FI as a targeted user can deploy a malicious SSDP serves that is set up to respond with specially crafted messages that cause Firefox to open an arbitrary website. Further, Moberly mentions” had it been in the wild, it could have targeted known-vulnerable intents in other applications. Or it could have been used in similar to phishing attacks where a malicious site is forced onto the target without their knowledge in the hopes, they would enter some sensitive info or agree to install a malicious application (Kovacs, 2020). Moberly has released technical details and proof-of-concept (PoC) exploits. ESET researcher Lukas Stefano has confirmed that the exploit works and has posted a video showing how an attacker can open an arbitrary website on three phones at the same time.

 

References

Kovacs. Eduard. (September 21,2020). Firefox Flaw Allowed Hackers to Remotely Open Malicious Sites on Android Phones. Securityweek. Retrieved from https://www.securityweek.com/firefox-flaw-allowed-hackers-remotely-open-malicious-sites-android-phones

Filed Under: Week 04: Network Mapping and Vulnerability Scanning Tagged With:

Reader Interactions

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

Weekly Discussions

  • Uncategorized (46)
  • Week 01: Overview (3)
  • Week 02: TCP/IP and Network Architecture (6)
  • Week 03: Reconnaisance (5)
  • Week 04: Network Mapping and Vulnerability Scanning (11)
  • Week 05: Metasploit (10)
  • Week 06: More Metasploit (4)
  • Week 07: Social Engineering (7)
  • Week 08: Malware (6)
  • Week 09: Web Application Hacking (7)
  • Week 10: SecuritySheperd (6)
  • Week 11: Intro to Dark Web and Intro to Cloud (4)
  • Week 12: Introduction to Wireless Security with WEP and WPA2 PSK (7)
  • Week 13: WPA2 Enterprise and Beyond WiFi (3)
  • Week 14: Jack the Ripper, Cain and Able, and Ettercap (4)

Copyright © 2025 · Course News Pro on Genesis Framework · WordPress · Log in