Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old May 30th, 2012, 05:39 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Chrome, Internet Explorer, Firefox Response To ‘Exploit’

https://insanitybit.wordpress.com/20...-to-exploit-7/
Quote:
A recent blogpost showed how Chrome, Internet Explorer 9, and Firefox are all vulnerable to a specific bug that can be used to trick the user into downloading a file when they meant to download something else.
__________________
  #2  
Old May 30th, 2012, 06:36 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

That's a rather pathetic response from these vendors, especially MS. If Chrome devs are at least saying they plan to look at it, I would take a guess that they will be doing so in secret and not saying anymore about it until the fix shows up in an update. Then again, I could be placing too much faith in them. Though one thing I'd say about Chrome is that for those paying attention, this would be hard to exploit, seeing as how Chrome updates Flash on its own.

But Firefox and MS, for shame. One can only hope they fix this for IE 10. The last thing they need right now is to get that reputation for bad security back.
  #3  
Old May 30th, 2012, 06:40 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

There was discussion on the Firefox side though at least and they'll probably address it, there's just no confirmation.

Chrome has confirmed that they'll fix it there's simply no date yet.

Quote:
Though one thing I'd say about Chrome is that for those paying attention, this would be hard to exploit, seeing as how Chrome updates Flash on its own.
Sure, but you can do this with Java too. Anything, really.

The proof of concept downloads calc.exe I believe.

edit: Actually, I believe Chrome is "more vulnerable" than Firefox in this case as the Firefox download UI provides more information. Can't confirm as I haven't looked. Either way, like I said in the article, if I were to post a "Critical Flashplayer Update" I'd probably infect quite a few Wilders users.
__________________

Last edited by Hungry Man : May 30th, 2012 at 06:50 PM.
  #4  
Old May 30th, 2012, 06:58 PM
dw426 dw426 is offline
Massive Poster
 
Join Date: Jan 2007
Posts: 5,543
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

Actually yeah, you probably could infect quite a few. It's a pretty darn awesome way to hook someone. It's yet another reason one should always go straight to the source instead of trusting links.
  #5  
Old May 30th, 2012, 07:00 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

A hacked website, email, facebook, twitter, anything could do a lot of damage with it.
__________________
  #6  
Old May 30th, 2012, 07:27 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,998
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

Quote:
Originally Posted by dw426
That's a rather pathetic response from these vendors, especially MS. If Chrome devs are at least saying they plan to look at it, I would take a guess that they will be doing so in secret and not saying anymore about it until the fix shows up in an update. Then again, I could be placing too much faith in them. Though one thing I'd say about Chrome is that for those paying attention, this would be hard to exploit, seeing as how Chrome updates Flash on its own.

But Firefox and MS, for shame. One can only hope they fix this for IE 10. The last thing they need right now is to get that reputation for bad security back.

This is a really interesting issue but unlikely to be used because standard social engineering is more effective. Sure you could link this to your friends but why would you? If someone happened to stumble across it I think they'd find it odd that they suddenly ended up on a flash download page and close it. There really isn't any use case for this outside of being linked to it and explicitly told by said person "you need to download that".

On the plus side IE9 explicitly states the false origin of the file and it also would be blocked by IE9's App Reputation.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
  #7  
Old May 30th, 2012, 07:32 PM
Hungry Man's Avatar
Hungry Man Hungry Man is offline
Incredibly Massive Poster
 
Join Date: May 2011
Posts: 8,486
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

Quote:
There really isn't any use case for this outside of being linked to it and explicitly told by said person "you need to download that".
Right, but imagine the potential for, say a hacked twitter, email, facebook, or website.

It also wouldn't necessarily be blocked by AppReputation or SmartScreen just as any antivirus might miss it. That would certainly help though.
__________________
  #8  
Old May 30th, 2012, 08:50 PM
funkydude's Avatar
funkydude funkydude is offline
Massive Poster
 
Join Date: Apr 2004
Posts: 5,998
Default Re: Chrome, Internet Explorer, Firefox Response To ‘Exploit’

Quote:
Originally Posted by Hungry Man
It also wouldn't necessarily be blocked by AppReputation or SmartScreen just as any antivirus might miss it. That would certainly help though.

AV isn't default-deny, AppRep is. The chances of an unsigned file from suspicious website x being allowed is highly unlikely.
__________________
OpenDNS with DNSCrypt

SSD: Windows 8 Pro x64 | IE10 (Enhanced Protected Mode) & Fanboy's TPLs
HDD: Xubuntu 12.04 LTS (x64) | Firefox: ABP(Fanboy's list) & HTTPS Everywhere
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 07:14 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums