Page 1 of 1

Firefox Malware in linux ! Serisously!

Posted: Sat Apr 19, 2014 8:35 am
by bazsound
I keep getting this page in firefox from time to time.

"UPDATES RECOMMENDED!

It is recommended that you install the software to ensure your browser is the latest version. Please update to continue"

It seems to be when i go to gmail, but its only now and then.

Ive searched google and all i can find is instructions for removing virus/malware in windows, i cant find anything specific to linux.

Ive reset firefox but it still pops up.

My only addins on firefox are Ad Block Plus, and foxy proxy.

Any ideas on how to get rid of this! Its the first time ive had anything like this under linux

Re: Firefox Malware in linux ! Serisously!

Posted: Sat Apr 19, 2014 2:29 pm
by bazsound
I'll get a screen shot next time it comes up. it's dropped doing it foe now but will Probably pop back up tomorrow.

Re: Firefox Malware in linux ! Serisously!

Posted: Sat Apr 19, 2014 4:52 pm
by Eino
bazsound wrote: Ive reset firefox but it still pops up.
Did you empty your cashe in firefox?
Those temporary files can effect the browse at times, even hold malware that effects the browser. Just waiting for the trigger to give you popups.
When all else fails, re-install firefox.

Code: Select all

dpkg --purge firefox
Then

Code: Select all

apt-get update && apt-get install firefox

Re: Firefox Malware in linux ! Serisously!

Posted: Sat Apr 19, 2014 5:52 pm
by Eino
falkTX wrote:btw, I don't know why you're so surprised that there's malware on linux.
every OS is bound to have malware sooner or later (specially if good practices are not followed).

with linux getting more and more attention, it's obvious there will be malicious interest for this side too.
Malware with linux has been few, and far between, most of which only effects the browser.
Unless you except an update from an unreliable source. Which is just plane stupid for anyone to do.
The only way something really bad can happen, is if your on-line as a root user. Otherwise nothing can effect The OS.

Re: Firefox Malware in linux ! Serisously!

Posted: Sat Apr 19, 2014 8:31 pm
by tux99
I very much doubt that this is Linux specific malware, more likely platform independent. I'd guess it's caused by an add-on (which are platform-independent). Reinstalling Firefox will not get rid of it as all user-specific Firefox related stuff is under .mozilla/ in the users home directory.

You could delete the whole .mozilla/ directory in your home folder but then you will also lose your bookmarks, settings and saved passwords.

Re: Firefox Malware in linux ! Serisously!

Posted: Sun Apr 20, 2014 12:55 am
by bazsound
it's still failed to come back.

it's not a pop-up but the website I went to visit got replaces with another web address that contained that message with a button to download obviously dodfy files.

I'm wondering if thus was an attack on Mobile internet. I've heard of addresses being redirected. something do do with the way Mobile broadband works particularly when using open DNS.

Re: Firefox Malware in linux ! Serisously!

Posted: Sun Apr 20, 2014 4:49 am
by GraysonPeddie
Maybe it is a banner ad that contains a sPhoronix ich can redirect you to a malware-infested website, telling you to download an update. Never, ever accept an update from a website as that can infect your computer. Unless you get Firefox from a third-party repository, you will always get official updates from Canonical, the maker of Ubuntu.

Even though website owners will lose funding from advertisement network, I strongly recommend you install NoScript, AdBlock Plus, and Flash-blocking extension for starters. If you truly support a website, enable ads for one particular site. Disable ads if one or more as servers might have been compromised by malware.

I hope I can be of help. Stay safe out there.

(Typed in Nexus 7 running Android 4.4. Expect typos which I am trying to prevent from occurring in my post.)

Re: Firefox Malware in linux ! Serisously!

Posted: Sun Apr 20, 2014 7:20 am
by tux99
bazsound wrote:I'm wondering if thus was an attack on Mobile internet. I've heard of addresses being redirected. something do do with the way Mobile broadband works particularly when using open DNS.
It's quite possible that the DNS you are using is manipulated or hijacked, maybe contact your ISP and tell them about it (although you will need to speak to a real techie as the normal support staff probably won't have a clue about this).