A trojan recently analysed by Webroot is said to rely on retrieving web page passwords from a browser's password storage, rather than logging a user's keyboard inputs. To make sure it will find all the interesting passwords in Firefox, the malware, called PWS-Nslog, makes some changes to jog the browser's memory. . A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically and without requesting the user's consent. The malware will, for instance, simply comment out Firefox's confirmation request in the nsLoginManagerPrompter.js file and add a line with automatic storage instructions. The H's associates at heise Security were able to reproduce the effect of the manipulations The link for this article located at H Security is no longer available. . A few manipulations in a JavaScript file prompt Firefox to store log-in information automatically an. trojan, recently, analysed, webroot, retrieving, passwords, browse. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.