Tag

Google Chrome extensions

Browsing

By Andy Meek.

While she was performing some routine tasks one day that relate to her job of constantly hunting for digital threats online, security researcher Jamila Kaya stumbled across the first in a series of malicious Google Chrome extensions that would spark a two-month investigation and lead to the removal of more than 500 extensions by Google from its web store. Unfortunately, more than 1.7 million Chrome users had already installed that first batch of extensions she found, which gave some urgency to this investigation — the results of which have been unveiled in a newly published report into what turned out to be a huge malware operation active for at least two years.

After her initial discovery, Kaya reached out to the Duo security team at Cisco, according to the report. She contacted them about a variety of Chrome extensions she found that infected browsers and would “exfiltrate data as part of a larger campaign.”

“These extensions were commonly presented as offering advertising as a service,” the report notes. “Jamila discovered they were part of a network of copycat plugins sharing nearly identical functionality. Through collaboration, we were able to take the few dozen extensions and utilize CRXcavator.io to identify 70 matching their patterns across 1.7 million users and escalate concerns to Google.”

The Duo team goes on to explain that bad actors are increasingly using legitimate internet activity to obscure their malicious actions, one of the most popular channels being the use of advertising cookies and the redirects within them. It’s a technique called “malvertising” that is surprisingly hard to detect. “Malvertising often occurs within other programs, acting as a vehicle for multiple forms of fraudulent activity, including ad-fraud, data exfiltration, phishing, and monitoring and exploitation,” the report continues. “Alternatively, it also emerges in multipart malicious campaigns that involve advertising collection and defraudment.”

The code within these malicious extensions would sometimes redirect users to an affiliate link on sites like Best Buy’s or Macy’s. Other times, the destination might be a download site for malware. The researchers said Google was responsive when they escalated the matter up to them, and a Google spokesman said that it always takes action when the research community alerts it to issues that violate the company’s policies. Moreover, Google said it performs “regular sweeps to find extensions” similar to these that use comparable techniques, code, and behaviors.

Feature Image Credit: Valentin Wolf/imageBROKER/Shutterstock

By Andy Meek

Andy is a reporter in Memphis who also contributes to outlets like Fast Company and The Guardian. When he’s not writing about technology, he can be found hunched protectively over his burgeoning collection of vinyl, as well as nursing his Whovianism and bingeing on a variety of TV shows you probably don’t like.

Sourced from BGR

 

Chrome is the biggest web browser. Use these extensions to get it to work for you

Chrome’s web store is full of little digital gadgets to help make your web browsing simpler, more productive, and more enjoyable. Here are our top ten extensions that tick those boxes and are all downloadable for free in a matter of moments.

Social Blade

Compatible with YouTube, Twitch, Instagram and Twitter, Social Blade feeds you knowledge about the videos you watch. A user’s followers, estimated ad earnings and views are shown in an interface next to what you are watching, letting you check how your favourite users and rivals are performing. Get the extension here.

Cite This For Me

Anyone who needs to show the source of their information, be it for an essay or a presentation, will find this button exceedingly useful. It quickly cites the webpage you are looking at in one of four citation styles, which can then be saved for later or pasted into a document. Click here to find out more and install the extension.

LastPass

LastPass means you only have to remember one password to keep all your other login details together in one place. It will also help keep your other accounts secure by generating super secure passwords that it will fill in automatically as needed. There’s space for notes for offline information that you want to be well protected too. Install it here.

Colorzilla

When you simply have to know the precise hue of something online, Colorzilla’s eyedropper can check any pixel and tell you. You can then paste that colour’s data into another programme or adjust the values and save it within the extension for future reference. It’s an invaluable extension for digital design work. Get the extension here.

TinEye

When finding the source of a picture’s proving difficult, try TinEye’s reverse image search. It focuses on the closest possible matches instead of just similarity, making it useful for finding originals, higher resolution versions, or checking for online fakes. The extension itself makes searches available in only a couple of clicks. Install TinEye’s Chrome extension from here.

Unpaywall

For those who want to read academic papers without stumping up for subscription fees. As you look for research, this extension searches for free (and completely legal) versions of the same articles, and pops into view if it finds a match. A potential saver of both time and money. Get it here.

Save to Pocket/Instapaper

Either of these extensions will let you to save web pages and articles for reading on your synced devices later, even without an internet connection. Both have premium versions too, if you want to support the developers and get extra features in return. Get Pocket and Instapaper’s extension here.

The Great Suspender

It’s all too easy to open absurd numbers of tabs in your browser. The Great Suspender helps to manage your computer’s performance by stopping abandoned tabs until you click back on them. There is a lot of room for configuration too, the extension able to keep certain sites open indefinitely, or unload others after a shorter period of time. Install it here.

Backstop

It’s happened to all of us. One bad key press and you’re on the previous webpage and all the info you were just typing into that form has disappeared. This simple extension stops your backspace key from taking you to the previous page, saving you from wasted time and frustration. Get it here.

Sourced from WIRED

Chrome is the biggest web browser. Use these extensions to get it to work for you

Chrome’s web store is full of little digital gadgets to help make your web browsing simpler, more productive, and more enjoyable. Here are our top eight extensions that tick those boxes and are all downloadable for free in a matter of moments.

LastPass

LastPass means you only have to remember one password to keep all your other login details together in one place. It will also help keep your other accounts secure by generating super secure passwords that it will fill in automatically as needed. There’s space for notes for offline information that you want to be well protected too. Install it here.

Colorzilla

When you simply have to know the precise hue of something online, Colorzilla’s eyedropper can check any pixel and tell you. You can then paste that colour’s data into another programme or adjust the values and save it within the extension for future reference. It’s an invaluable extension for digital design work. Get the extension here.

TinEye

When finding the source of a picture’s proving difficult, try TinEye’s reverse image search. It focuses on the closest possible matches instead of just similarity, making it useful for finding originals, higher resolution versions, or checking for online fakes. The extension itself makes searches available in only a couple of clicks. Install TinEye’s Chrome extension from here.

Unpaywall

For those who want to read academic papers without stumping up for subscription fees. As you look for research, this extension searches for free (and completely legal) versions of the same articles, and pops into view if it finds a match. A potential saver of both time and money. Get it here.

Save to Pocket/Instapaper

Either of these extensions will let you to save web pages and articles for reading on your synced devices later, even without an internet connection. Both have premium versions too, if you want to support the developers and get extra features in return. Get Pocket and Instapaper’s extension here.

The Great Suspender

It’s all too easy to open absurd numbers of tabs in your browser. The Great Suspender helps to manage your computer’s performance by stopping abandoned tabs until you click back on them. There is a lot of room for configuration too, the extension able to keep certain sites open indefinitely, or unload others after a shorter period of time. Install it here.

Backstop

It’s happened to all of us. One bad key press and you’re on the previous webpage and all the info you were just typing into that form has disappeared. This simple extension stops your backspace key from taking you to the previous page, saving you from wasted time and frustration. Get it here.

Feature Image Credit: WIRED / Google

Soured from WIRED