Sunday, December 20, 2009

"Google Update" firefox plugin: Google's first malware

I was just looking into options to chat or do more through browser. I didn't want to install anything on my computer. So I went to this website: http://www.google.com/talk/. I clicked on the video chat link thinking if it opens in the browser then awesome or else if it asks for download, I will cancel it. Guess what, it actually started installing on my computer without any download pop-up. Well, I didn't feel immediately threatened as the website was a google website, but it did took me with a big surprise.

How can Firefox download and install something without explicitly showing the download popup? I was puzzled for a few seconds. And then it occurred to me that Extensions and Plugins can change Firefox's behavior. And there it was - "Google Update" plugin. I disabled it and tried the same thing, this time Firefox did show the download dialog popup.

Google sneaked in this plugin without my knowledge!!! I think it did when I installed Google chrome. You never know when this plugin will install application on your machine - clicking on a link could take you to a new page or directly install an application bypassing any Firefox security. Uninstall/Disable this plugin ASAP.

Google - the malware provider!

No comments:

Post a Comment