Stop using Firefox on Windows right now!

Stop using Firefox on Windows right now!

>There's a zero-day exploit in the wild that's being used to execute malicious code on the computers of people using Tor and possibly other users of the Firefox browser, officials of the anonymity service confirmed Tuesday.

>Word of the previously unknown Firefox vulnerability first surfaced in this post on the official Tor website. It included several hundred lines of JavaScript and an introduction that warned: "This is an [sic] JavaScript exploit actively used against TorBrowser NOW." Tor cofounder Roger Dingledine quickly confirmed the previously unknown vulnerability and said engineers from Mozilla were in the process of developing a patch.

>According to security researchers who analyzed the code, it exploits a memory corruption vulnerability that allows malicious code to be executed on computers running Windows. The malicious payload it delivers, according to an independent researcher who goes by the Twitter handle @TheWack0lian, is almost identical to one that was used in 2013 to deanonymize people visiting a Tor-shielded child pornography site. The FBI ultimately acknowledged responsibility for the exploit, which was embedded in Web pages served by a service known as Freedom Hosting.

>"It's basically almost EXACTLY the same as the payload used in 2013," TheWack0lian told Ars. "It exploits some vuln that executes code very similar to that used in the 2013 Tor browser exploit. Most of the code is identical, just small parts have changed."

...

...

>arstechnica.com/security/2016/11/firefox-0day-used-against-tor-users-almost-identical-to-one-fbi-used-in-2013/

archive.fo/R0aHr

>tsyrklevich.net/tbb_payload.txt

archive.fo/AyfFB

>pastebin.com/AwnzEpmX

archive.fo/uihBr

Other urls found in this thread:

torproject.org/docs/faq.html.en#TBBJavaScriptEnabled
twitter.com/SFWRedditVideos

>implying

But it looks good.

> turning on JavaScript in the tor browser

You have to expect that someone clever might figure out some way when they can run scripts in your browser. Which is why JavaScript is turned off by default. Like the pedos being caught after running flash in the tor browser. It's a user error and not a browser error. Nobody can be anonymous and at the same time run JavaScript and flash nilly willy

Javascript on tor browser is turned on by default, and the tor team suggest not to turn off.

torproject.org/docs/faq.html.en#TBBJavaScriptEnabled

Firefox is a virus.

I hope they've learnt their lesson and change it to off by default with a warning to the users that turning it on may cause problems. This is the second huge case of Javascript exploit.

HEY GUYS STOP USING LINUX!
Some researchers have figured out that copy pasting commands from the Internet might run malicious code on your computer. Better not run Linux at all with this huge bug.

> It included several hundred lines of JavaScript and an introduction that warned: "This is an [sic] JavaScript exploit actively used against TorBrowser NOW." Tor cofounder Roger Dingledine quickly confirmed the previously unknown vulnerability and said engineers from Mozilla were in the process of developing a patch.
>javascript exploit
they deserve to get V& for using javascript

We knew the FBI had a "zeroday" for the tor browser anyway. We also knew it was something fucking stupid like this.

>on computers running Windows
k

Ok.

What browser should wincucks use then? I don't want anything that records my history and URLs and sends them to some server. Is icecat affected by this? Why are there no secure browsers anymore ;_;

Anyone using the tor browser for anything illegal deserves to be v& anyway. Tails and whonix exist for a reason

Hardened Musl Gentoo with Grsec (and the RBAC) master race, get the fuck out Debian plebs thinking you're "secure" with fucking glibc.

I don't care. Oh no my futanari exhentai browser history.

bump

Is there a tool like AppArmor or SELinux on windows that could mitigate this?

if the only people that got harmed were a few pedophiles then good, i am glad the FBI found the exploit and busted those SOBs

I don't even care. How can I disable Javascript? I don't think Alphabay needs it.

>Anyone using the tor browser for anything illegal deserves to be v& anyway.

Like complaining about the government or researching the Tiananmen Square protests of 1989?

Or buying bitcoin or speaking to foreigners? All of them highly illegal

>Windows
People still use this? Why?

Firecucks blown the fuck out yet again.

>2016
>not using Chromium
Even Google Chrome is better than the latest pile of shit from Mozilla.

Some people are too stupid to install something that does not come default user, stop being ableist. Nobody cares that you are edgy and pointing out that people lack mental functions.

>Chromium
Why not iron?

>Nobody cares that you are edgy and pointing out that people lack mental functions.
Look, sure. I just thought it was ironic that people who wished to be anonymoose decided to use a certified botnet OS.

OMG i'm scared! Please Google, MS or someone rape me now!

I mean,
> almost identical to one that was used in 2013 to deanonymize people visiting a Tor-shielded child pornography site
> watching CP
> on WINDOWS

> people lack mental functions
I think that's the most diplomatic way to describe them.

>Nobody cares that you are edgy
>implying he is edgy

>reading arstechnica when they have become a SJW site that also pushes fake news

I have nothing to hide. I don't care about the zero day.

tits or gtfo!
>inb4 male tits

then why are you hiding your big peepee then?