Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Trojan PWS-Nslog Alters Firefox For Passwords Without Consent

General Esm H500
A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser's password storage, rather than logging a user's keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser's memory. A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically and without requesting the user's consent.

The malware will, for instance, simply comment out Firefox's confirmation request in the nsLoginManagerPrompter.js file and add a line with automatic storage instructions. The H's associates at heise Security were able to reproduce the effect of the manipulations

The link for this article located at H Security is no longer available.

Your message here