HNHacker News
TopNewBestAskShowJobs

XORcat

32 karma · joined August 16, 2016

[ my public key: https://keybase.io/xorcat; my proof: https://keybase.io/xorcat/sigs/Rx9eKf7xu4fM7MlU8u5sE7v1Z0p89eh1TjGf7N9nOig ]
submissionscomments
XORcat··on Update Your Logitech Wireless Dongle Right Now
And if you wanted a proof of concept[1] to scare the pants off of you, I'm here for you.

[1]: https://github.com/insecurityofthings/uC_mousejack

XORcat··on All extensions disabled due to expiration of intermediate signing cert
I would have the same question if I didn't see the response come back from https://normandy.cdn.mozilla.net/ myself.

I encourage you to go through the whole Normandy process yourself in a test environment, and even better (if possible), check out the code to see whether it looks legit or benign.

I'm happy, because I went through and checked it out myself without needing to enable Normandy on my actual Firefox, but ultimately, it will be great when Moz can get instructions for manually applying the fix out.

XORcat··on All extensions disabled due to expiration of intermediate signing cert
JSON response from the `normandy` API here: https://xor.cat/assets/other/random/2019-05-04/normandy_sign...

hotfix-update-xpi-signing-intermediate-bug-1548973: https://storage.googleapis.com/moz-fx-normandy-prod-addons/e...

From the looks, it installs the above plugin, and changes `app.update.lastUpdateTime.xpi-signature-verification` to `1556945257`

I can't get it to work in ESR 60 though. Getting file not found on "resource://gre/modules/addons/XPIDatabase.jsm"

edit: The linked XPI definitely seems to add the new certificate, whatever mechanism used to reverify the signatures just doesn't seem to work in 60.

edit2: Restarting Firefox appears to have forced the reverify... Possibly a flag that I twiddled with though, hard to be sure. Either way, the above should help people get everything running again without having to enable studies/normandy.

XORcat··on EquationGroup Tool Leak – ExtraBacon Demo
In my lab, re-enabling did not kill the current connection, so it could be a very quick switch flick, login, revert to try and avoid detection.