Greasemonkey sotto attacco!

Mark Pilgrim su Mozdev.org avvisa tutti di un buco di sicurezza in Greasemonkey, l’estensione più popolare di Firefox, quella che permette di personalizzare i contenuti dei siti web e “utilizzarli” nei modi più impensabili.

Il suo consiglio attualmente è di DISINSTALLARLO !

Da Mozdev.org:

Uninstall Greasemonkey altogether. At this point, I don’t trust
having it on my computer at all. I would think that whoever is in
charge of addons.mozilla.org should immediately remove the
Greasemonkey XPI and post a large warning in its place advising people
to uninstall it.

By the way, “Greasemonkey Hacks” is DEAD until we fix this. And I’m
posting a big red blinking warning on every page of
diveintogreasemonkey.org advising visitors to uninstall it, until all
of these security holes are closed. This is why God invented the
tag.

Aaron Bodman, mantainer del progetto Greasemonkey ha scritto :

I found out that since Greasemonkey is distributed on
addons.mozilla.org it will automatically update itself, even though I
didn’t put that in the code.

Neat. I’m going to upload the neutered versions at 7pm PST. It’d be
great if people could poke it a little before then.

Chissà come sono contenti a Google..

Fonte: kottke.org

If you enjoyed this post, please consider to leave a comment or subscribe to the feed and get future articles delivered to your feed reader.