TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

We busted a fake Chrome extension that was trying to steal data

108 点作者 cws超过 6 年前

13 条评论

tyingq超过 6 年前
<i>&quot;It&#x27;s also not clear how any other tool would have detected the long-lived, persistent outbound connection with relatively low bandwidth&quot;</i><p>Perhaps, but this extension could have been stealthier. It was using a plaintext web socket on port 6332. If the extension author had instead gotten a Google analytics account, and exfiltrated data via encrypted https GETS to Google servers, it might have never been spotted. That kind of traffic likely happens 24&#x2F;7 in a typical corporate environment.
评论 #18629077 未加载
kungfufrog超过 6 年前
The blog post was moderately informative&#x2F;useful and interesting, marketing brochure website behind it next to useless and can&#x27;t find anything meaningful about what they actually sell or do. Frustrating follow-up experience for me that reminds me of most enterprise ISVs.
评论 #18625378 未加载
评论 #18630714 未加载
codedokode超过 6 年前
This is a serious issue with Chrome Store. Google doesn&#x27;t properly warn users that the store is not premoderated and can contain malware. Instead, they have made a colourful positively looking site without necessary warnings.
评论 #18628579 未加载
porlune超过 6 年前
It should be noted, that at one time, Postman was a chrome extension. They recently depreciated that extension.<p><a href="http:&#x2F;&#x2F;blog.getpostman.com&#x2F;2017&#x2F;11&#x2F;01&#x2F;goodbye-postman-chrome-app&#x2F;" rel="nofollow">http:&#x2F;&#x2F;blog.getpostman.com&#x2F;2017&#x2F;11&#x2F;01&#x2F;goodbye-postman-chrome...</a>
评论 #18628559 未加载
empyrical超过 6 年前
Because the visibility of the Arc Welder extension (the one that lets you use Android apps on desktop chrome) is set to hidden, which hides it from both Web Store and Google Searches, there are malicious extensions that take advantage of this and will become the top search result for Arc Welder. And if you don&#x27;t know where to look, it can be very hard to find the real link for Arc Welder. So as a result, these malicious Arc Welders often get many thousands of installs before being taken down. Very frustrating because even if you report them immediately after they are added, it takes a few days to take them down.
评论 #18629458 未加载
ocdtrekkie超过 6 年前
<i>As of this writing, the malicious &quot;Postman&quot; extension is still available in the Google Chrome extension store and has been downloaded over 27,000 times.</i><p>This is pretty much par for the course, unfortunately.
评论 #18625381 未加载
评论 #18629509 未加载
cws超过 6 年前
Here’s a ZDNet article about the same extension <a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;industrial-espionage-fears-arise-over-chrome-extension-caught-stealing-browsing-history&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;industrial-espionage-fears-ari...</a>
kalehrishi超过 6 年前
Black theme of tool makes me chuckle. Wondering how it became defacto color theme of hacking tools! Only thing missing is neon green.
评论 #18626001 未加载
评论 #18625260 未加载
评论 #18625203 未加载
AznHisoka超过 6 年前
.. and this is what SimilarWeb browser extensions have been doing for 5+ years. Yet Google doesn&#x27;t seem to care.
m_developer超过 6 年前
Well, that was a fun way to find out you have a malicious app installed in your browser.<p>It would be nice to have an overview of what exactly was exported to know the impact of this breach (without having to use reveal(x) myself).
评论 #18627776 未加载
xte超过 6 年前
Generally speaking anyone can create malicious software disguised in various way, so FOSS project included.<p>However instead of creating a &quot;antivirus&quot; vs &quot;virus&quot; classic scenario, that we all know it doesn&#x27;t work my lines is: all must be open (hw, sw) and developed in a FOSS way from the start.<p>For instance if you are an hw OEM who want to produce a new GNU&#x2F;Linux phone? Ok, start work on it in a public repo. If your project interest others, many with valuable skills came to help. Perhaps including some bad one. But the community will protect you, because you publish from the start the rate of benevolent and interested individuals that follow your project from the start will likely detect any bad guys, far better than any software, heuristic and even &quot;AI&quot; in general terms. After you know that community give credit so if the project will be successful people will buy your product, paying you back for your part of work and physical production. Other, of course, may use your schematics and software for free but if they add competitive features you get them back for free because of FOSS licensing, if they do not respect licenses you&#x27;ll get backed by FSF&amp;c that have a firepower and advertising capability normally superior to any new company&#x2F;startup. Otherwise if there is only a price competition many will go for the cheap, many, not all. And if you and the community keep innovate the project you keep gaining money, no different than pharmaceutical industry that do research vs pharmaceutical &quot;generic&quot; industry.<p>Long story short: I can&#x27;t trust closed sources extensions nor more nor less than closed source security software, I can&#x27;t trust a company no more than another (only reputation can lead to small percentage variations). So I do my best to avoid inoculate in my systems software that I can&#x27;t trust... Good assessments are still needed but they are IMO not really much valuable without the openness at the base: the <i>need</i> of trust is a weakness, so we need to being able to trust each other with the power of verify trust at the core, not only at the skin.
berbec超过 6 年前
Nice ad.
cws超过 6 年前
As of this writing, the fake Postman extension appears to have been removed from the Chrome extension store. Huzzah!