How to report a security issue?
I was browsing the web when I was suddenly redirected to a website which stated that "Your Browser Software needs to be updated immediately" and on the page was Mozilla Firefox logo's. The page looked like your company was pushing a web page style of update, and I clicked the download button. When the software triggered Windows 8 "User Account Controls" prompting me to confirm the install, I noticed the URL for the source didn't state it came from a Mozilla.org site so I clicked cancel... I then received a message on the website stating the software was successfully installed... The download was shown as "Software_Update.exe" and under properties it never showed as being a Mozilla.org associated file... Not trusting what had just happened I ran Vipre Rescue on my system and it removed two files from my system..,. Both were associated with a Malware called "Iminient (FS)"... I just thought your team should be made aware.
所有回复 (1)
Thanks for the heads up. Did you get any more detail or manage to report the sites ?
Sites misusing Firefox logos & trademarks etc should be reported here
- Violating Website Report — Mozilla - Protect the Fox (and More!) https://www.mozilla.org/en-US/legal/fraud-report/
Did you manage to report any of the sites involved as security or phishing sites, and did you record details of what the sites were ?
You do appear to be using the current Release Firefox 31. Fake sites and scams are unfortunately a fact of life on the internet some can be blocked if reported.
Merely coincidence I hope but Mozilla Firefox has in fact just been running a project to use a hotfix to update users to the latest versions of Firefox because it is known that some users had Firefox set to update but it was for whatever reason failing to do so. I have no reason to expect this is what happened in your case. For Security, these hotfixes are / were signed and deployed by Mozilla (Hot fixes deployed from16th July).
This may also be applicable
- https://www.google.com/safebrowsing/report_badware/
- https://www.google.com/safebrowsing/report_phish/
Firefox will attempt to block some sites once they have been reported.
- Safe & harmless Demo -> its-an-attack
(External to mozilla.org so mozilla itself does not become listed) - https://www.mozilla.org/en-US/firefox/desktop/trust/#secure
- How does built-in Phishing and Malware Protection work?