View Single Post
Staro 05.09.2008., 00:34   #145
Bono
Uptime 99.99%
Moj komp
 
Bono's Avatar
 
Datum registracije: Nov 2001
Lokacija: Zagreb Croatia
Postovi: 2,472
Izasli su prvi exploiti za Chrome, jedan se moze iskoristiti na mnogo nacina, a drugi rusi Chrome i sve njegove tabove.

Citiraj:
Google's new Web browser (Chrome) allows files (e.g., executables) to be automatically
downloaded to the user's computer without any user prompt.

This proof-of-concept was created for educational purposes only.
Use the code it at your own risk.
The author will not be responsible for any damages.

Tested on Windows Vista SP1 and Windows XP SP3 with Google Chrome (BETA)
Citiraj:
Result:
Google Chrome Crashes with All Tabs

Problem:
An issue exists in how chrome behaves with undefined-handlers in chrome.dll version
0.2.149.27. A crash can result without user interaction. When a user is made to visit
a malicious link, which has an undefined handler followed by a 'special' character,
the chrome crashes with a Google Chrome message window "Whoa! Google Chrome has crashed.
Restart now?". It lies in dealing with the POP EBP instruction when pointed out by the
EIP register at 0x01002FF4.
__________________
“Those who surrender freedom for security will not have, nor do they deserve, either one.”
Bono je offline   Reply With Quote