• Home
  • Exams
    • Exams
    • Punjab Text Book Board
    • Oxford University Press
    • The Educators
    • Allied School System
  • E News
    • Educational News
    • Technology News
    • Other News
    • تعلیمی خبریں
    • ٹیکنالوجی خبریں
    • دیگر خبریں
  • STUDENTS
    • Message for students
    • Online Resources
    • Share an event
    • Become a Volunteer
    • Students Magazine
    • Student Ambasadors
    • Scholarships
  • PARENTS
    • Message For Parents
    • Online Resources
    • Submit articles
    • Scholarships
  • TEACHERS
    • Message for Teachers
    • Online Resources
    • Submit your articles
    • Scholarships
  • INSTITUTIONS
    • Message for Institutions
    • Directory of Educational Institutes
    • Academic Disciplines
  • ABOUT
    • Our Mission
    • Frequently Asked Questions
    • Feedback & Suggestions
    • Login
    • Help
  • Sign Up for Zahanat
Login Help
Sign Up for Zahanat

Google purges bad extensions from Chrome

April 9, 2015

Most rogue extensions bombard people with ads, but the most malicious steal login names and other valuable data.

Carried out by security experts and Google, the project analysed more than 100 million visits to the search giant’s sites.

It led to Google purging almost 200 bad extensions from its online catalogues of browser add-ons.

Bad behaviour?

Extensions and add-ons for web browsers add all kinds of functions and features to the software.

Many of these extensions have hidden extras that cause trouble for people who install them, said UC Santa Barbara computer scientist Alexandros Kapravelos, who worked with Google on the rogue extensions project.

The research found that malicious extensions were available for every major browser.

The findings are due to be published in full in May at the IEEE Symposium on Security and Privacy.

Preliminary results revealed that 5% of people accessing Google every day have been caught out by at least one malicious extension.

Of these victims, about a third have four or more bad add-ons installed in their browser.

“It is a very hard problem to deal with,” said Mr Kapravelos.

Some bad extensions were easy to spot, he said, because they were so obviously written to steal saleable data such as bitcoins, bank logins or personal data.

However, many used techniques seen in legitimate extensions, he said, and it took a lot of extra analysis to pin down the bad ones.

“Even when we have a complete understanding of what the extension is doing, sometimes it is not clear if that behaviour is malicious or not,” he said.

“You would expect that an extension that injects or replaces advertisements is malicious, but then you have AdBlock that creates an ad-free browsing experience and is technically very similar.”

Experts from Swedish security firm ScrapeSentry said it had found examples of extensions that gathered data in ways that could easily be abused.

Some malicious extensions are very obvious and seek to steal bitcoins and other valuable data

ScrapeSentry’s analysis of one extension, called Webpage Screenshot, revealed that it contained code that let it grab copies of all the browser traffic from the PC on which it was installed.

The gathered data was then sent to a server in the US. The extension has been downloaded about 1.2 million times.

“What happens to the personal data and the motives for sending it to the US server is anyone’s guess, but we’d take an educated guess that it’s not going to be good news,” said Martin Zetterlund from ScrapeSentry.

A spokesman for Webpage Screenshot said there was nothing malicious about the data it gathered. Instead, said the spokesman, it was used to understand who the extension’s users were and where they were located to help drive development of the code.

Users could opt out of sharing data, he said.

Deleting data

Mr Kapravelos said Google had acted on the early findings of the research by removing 192 actively malicious extensions from its Chrome catalogue. About 14 million people had been tricked into using these extensions, he said.

The UC Santa Barbara team was working with Google to develop tools that can automatically spot malicious extensions and flag them to the search giant’s security staff.

In addition, said Mr Kapravelos, firms whose adverts were being injected onto webpages by the rogue extensions had been informed.

Unfortunately, he said, ad injection had become “entrenched” as a way for some unscrupulous developers to make money.

The research found that only a small number of developers were behind the majority of the rogue extensions that pepper people with ads, suggesting that targeted action could help tackle the problem.

Source: BBC News

 

 

Main sidebar

  • High-tech military goggles combine night vision, thermal imaging
    May 14, 2015
  • Google Play now lets you preregister for upcoming apps and games
    May 14, 2015
  • Apple’s Next Big Thing: Your DNA?
    May 11, 2015
  • Microsoft to stop producing Windows versions
    May 11, 2015
  • Mini launches prototype of glasses that give ‘X-ray vision’
    May 11, 2015

Follow Zahanat

Like us on Facebook Zahanat.Official



Our Channel at VimeoZahanat



Our Channel at dailymotionZahanat




Zahanat.com

Zahanat.com is a self sustained project; a free online resource for Pakistan’s academic communities. It covers widely used curricula in Pakistan from class I to XII. We also provide career guidance, exam preparation, health & social well being tips to students. We do not receive any grants from any one nor do we follow any third party agenda. We value what is good for our students and country more than any gain or profit.

Get Involved

Zahanat.com provides a platform to socialize and engage in healthy extracurricular activities for students, parents and teachers
Students: Click to learn more
Parents: Click to learn more
Teachers: Click to learn more
Our aim is to engage individuals from all academic background and field of life.
Visit our FAQ Section to learn more about how can can participate.

Legal Policies

Terms and Conditions
Privacy Policy
Copyright Policy
Anti-Spam Policy
Linking Policy
Legal Disclaimer
These policies and disclaimers apply only to the Zahanat.com. Therefore, once you link to another site, you are subject to the policies of the new site.
Beta Disclaimer
This is the Beta launch, you may experience few shortcomings or technical issues. Team Zahanat!

Parents Account

Zahanat.com offers a 21st century parenting guide for better parenting by sharing knowledge of experts with you, parents can also create a free account at zahanat.com and can become part of progressive parents community.
Visit our Frequently Asked Questions Section to learn more about how to create parent account and related benefits.

Teachers Account

Zahanat.com has created a platform for the Teachers, where they can find various useful academic articles and online resources to polish their teaching skills. Teachers can create free account and opt to be part of National Teachers Directory.
Visit our FAQ Section to learn more about how to create account and related benefits.

SMS Verification

To ensure the safe and approved online interactivity of student at zahanat.com, we have developed & implemented the SMS Verification System, under this system, students are asked to Enter their parents / guardian Mobile Number, our system sends the account approval & verification code to the provided number to get authorization for account creation.
copyright 2015 Zahanat.com