Mozilla blocks Microsoft's sneaky Firefox plug-in
Triggers rarely-used blocking feature to protect users from attack
Computerworld - Mozilla late Friday blocked the Microsoft-made software that put Firefox users at risk from attack.
The two-part Microsoft component -- an add-on dubbed ".NET Framework Assistant" and a plug-in named "Windows Presentation Foundation" -- have been blocked by Mozilla as a precautionary measure, said Mike Shaver, the company's head of engineering.
"Because of the difficulties some users have had entirely removing the add-on, and because of the severity of the risk it represents if not disabled, we contacted Microsoft today to indicate that we were looking to disable the extension and plug-in for all users via our blocklisting mechanism," Shaver said in an announcement posted Friday night to the company's security blog.
Mozilla maintains an add-on/plug-in blocking list that automatically bars risky software from being used by Firefox. The open-source company first used the blocker in 2007. Mozilla has used the tool only nine times, including Friday's blocking of the Microsoft add-on and plug-in. In May 2008, Mozilla added a Vietnamese language pack for Firefox to the blocking list when the pack was found to contain a worm.
According to Shaver, Microsoft gave Mozilla the go-ahead to block the .Net Framework Assistant and the Windows Presentation Foundation.
Last week, Microsoft's security team acknowledged that its software -- which had been silently installed in Firefox as far back as February 2009 -- contained a critical vulnerability that could be used by hackers to hijack Windows PCs. The same vulnerability also affects all versions of Internet Explorer (IE), including the newest version, IE8.
Microsoft maintained that users who applied the patches it issued last week as part of a record-setting security update would protect Firefox users from attack. However, the MS09-054 bulletin, which provided details on the vulnerability, said nothing about Firefox. Later last Tuesday, Microsoft expanded on MS09-054 in a blog post by security engineers, and confirmed that Firefox was affected because of the add-on and plug-in.
Mozilla clearly felt that that was not enough, and took the unusual step of blocking the Microsoft add-on and plug-in. Multiple Computerworld staffers have confirmed that Firefox is now blocking the Microsoft software. "These add-ons have a high risk of causing stability or security problems and have been blocked, but a restart is required to disable them completely," the Firefox warning message reads.
The history of the .Net Framework Assistant and Windows Presentation Foundation software is tangled and contentious. Firefox users complained last February, and then again in May, when they found out that Microsoft had pushed the components to their browser as part of the .NET Framework 3.5 Service Pack 1 (SP1) update, which was delivered via Windows Update.
Users were furious that the software was installed without their approval. To add salt to the wound, the components were impossible to uninstall without editing the Windows registry, a chore most users avoid because any misstep could cripple the PC. Later, Microsoft issued a follow-on update that made it possible to uninstall or disable the components without a registry edit.
Mozilla has been aggressively pursuing risky add-ons and plug-ins of late. Last month, it warned Firefox users running outdated versions of Adobe's Flash Player to upgrade, then last week added a more thorough plug-in checking service to its arsenal.
The next edition of the browser, Firefox 3.6, will warn users when they visit a Web site that relies on one or more outdated plug-ins. A beta of Firefox 3.6 is set to launch Wednesday.
Read more about Security in Computerworld's Security Topic Center.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts