Security Newsletter
29 September 2020
Firefox bug lets you hijack nearby mobile browsers via Wi-Fi
Mozilla has fixed a bug that can be abused to hijack all the Firefox for Android browsers on the same Wi-Fi network and force users to access malicious sites, such as phishing pages.
The actual vulnerability resides in the Firefox SSDP component. SSDP stands for Simple Service Discovery Protocol and is the mechanism through which Firefox finds other devices on the same network in order to share or receive content (i.e., such as sharing video streams with a Roku device). To better understand how this bug could be weaponized, imagine a scenario where a hacker walks into an airport or mall, connects to the Wi-Fi network, and then launches a script on their laptop that spams the network with malformed SSDP packets. Another scenario is if an attacker targets vulnerable Wi-Fi routers. Attackers could leverage exploits to take over outdated routers, and then spam a company's internal network and force employees to re-authenticate on phishing pages.
Moberly said he reported the bug to Mozilla earlier this summer. The bug was fixed in Firefox 79; however, many users may not be running the latest release. Firefox for desktop versions were not impacted. Reached for comment, a Mozilla spokesperson recommended that users upgrade to the latest version of Firefox for Android to be safe.
Read More on ZDNet
Proof of Concept code and description
 
More #News
 
#Patch Time!
 
#Tech and #Tools
This content was created by Kindred Group Security. Please share if you enjoyed!
Kindred Group in brief
Kindred is one of the largest online gambling companies in the world with a diverse team of 1,600 people serving over 26 million customers across Europe, Australia and the US. We offer pre-game and live Sports betting, Poker, Casino and Games through 11 brands across our markets. We are committed to offer our customers the best deal and user experience possible, while ensuring a safe and fair gambling environment. Kindred is a pioneer in the online gambling industry and is an innovation driven company that builds on trust.
You can access the previous newsletters at https://news.infosecgur.us
If you no longer wish to receive this newsletter, you can unsubscribe from this list.