Firefox to restrict all plug-ins except latest Flash with Click to Play
Mozilla is tackling drive-by download attacks by rolling out a tool to restrict, by default, all Firefox-browser plug-ins except the current version of Flash.
The 'Click to Play' feature, recently included in Firefox, acts as a control gateway, determining which plug-ins can play when a website requests one to be loaded. Although plug-ins are legitimately used to display content that, for example, requires Flash, Silverlight or Java, attackers frequently exploit flaws in un-patched versions of the products to compromise PCs.
Now, instead of automatically loading any plug-in requested by a website, Firefox users will need to deliberately click on a plug-in when a request is made; or configure Click to Play to run plug-ins on a particular website.
The control feature should help combat drive-by web attacks that exploit vulnerable versions of popular software like Adobe Flash and Java.
Read More