Google Chrome Pwned by VUPEN aka Sandbox/ASLR/DEP Bypass

Discussion in 'other security issues & news' started by AvinashR, May 9, 2011.

Thread Status:
Not open for further replies.
  1. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    I do use Adblock Plus with Firefox 4.0.1 so yes.

    Yeah its weird though because it does not seem to be doing it now. Maybe the site was temporarily hijacked?

    Here is a pic of the alert itself.
     

    Attached Files:

    Last edited: May 13, 2011
  2. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,738
  3. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    I actually visited that website as well, when Kees1958 posted it, but I saw no issues with it. Most likely because I got JavaScript, plugins and ads blocked.

    About the domain blocked by avast! -http://www.urlvoid.com/scan/sator.vv.cc (More may detect. Browser Defender provides same ratings as Norton SafeWeb, for example.)

    Most likely a compromised ad. And, for what I see in avast!'s alert, it would require JavaScript. So, if JavaScript is enabled on a per-site basis, then the PDF exploit wouldn't initiate. If JavaScript is enabled, then if PDF plugin is not, it wouldn't initiate either.
     
  4. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Sorry,

    Browsed with safe-admin (forced Low-IL Chrome and 1806 on deny).

    I have put on GeSWall and Chrome in normal usage, but do not see anything suspicious in the GW log now

    o_O
     
  5. Rmus

    Rmus Exploit Analyst

    Joined:
    Mar 16, 2005
    Posts:
    4,020
    Location:
    California
    I went to the geek.com page earlier with IE8 and everything enabled, and nothing out of the ordinary took place.

    I downloaded the PDF file shown in the alert and on opening, it attempted to connect out:

    pdf_exploit.gif

    Allowing the connection, nothing happened.

    Checking that URL directly, it's no longer working, so the exploit - whatever it was - has been cleaned up.

    -rich
     
  6. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    Yeah that exploit was only there for a short period of time. When I first got prompted by Avast I was like whoa. I was able to replicate it twice within a short period of time. Shortly after I notified Ron, and he changed up the links, the site was clean.

    I also checked with Avast and they did confirm that it was not a fp. Guess I gotta load noscript at work again on my Firefox. :)

    Also, ~ VirusTotal Results Link Removed per Policy ~.
     
    Last edited by a moderator: May 14, 2011
  7. m00nbl00d

    m00nbl00d Registered Member

    Joined:
    Jan 4, 2009
    Posts:
    6,623
    Google Engineers Deny Chrome Hack Exploited Browser's Code

    Source: -http://www.pcworld.com/article/227680/google_engineers_deny_chrome_hack_exploited_browsers_code.html
     
  8. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    How do they know if they don't have access to it?
     
  9. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    They know it's a buffer overflow attack and they've seen it in action. That's a lot of information for them to figure it out.

    I'm not surprised.
     
  10. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    +1. ;)
     
  11. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
  12. Daveski17

    Daveski17 Registered Member

    Joined:
    Nov 11, 2008
    Posts:
    10,239
    Location:
    Lloegyr
    Anyway, Google appear to be in denial
     
  13. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    They're owning up to it. They're just pointing out that it's nowhere near what Vupen claimed. Vupen is acting like they attack Chromium code when, really, they just attacked flash in a google sandbox.

    As they say:
     
  14. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    As long as flash is an integral and bundled part of Chromium, it's completely correct to state that it is a Chromium issue, not a flash issue. Add to that the fact that Chromium even has a unique version of flash specially designed for Chromium.

    Twist it how you want but at the end of the day it will be a code change in Chromium that fixes it.
     
  15. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    It's a flash issue AND a Chrome issue. (Does Chromium come bundled?)

    It can be chrome or adobe that fixes this issue. Whoever gets to it first. Either Chrome will patch the code for adobe or Chrome will change the sandbox OR adobe will patch the code.
     
  16. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417

    Flash is not bundled with Chromium, AFAIK. Sorry.
     
  17. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    As long as a plugin has the ability to breach the sandbox, maliciously or not, it's a Chromium issue.
     
  18. Hungry Man

    Hungry Man Registered Member

    Joined:
    May 11, 2011
    Posts:
    9,146
    Like I said, it's a Chrome AND a flash issue. It's on both Google and Adobe to solve this problem.
     
  19. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    Let's not forget that the OS in question is Win 7.
    And for people who claim that it is this issue or that issue so very emphatically, there is this:
    from a link already posted in this thread.

    And it's not a Chromium issue. It's a Chrome issue. Even an uneducated person will understand the difference and keep bias under control.
     
  20. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    You insulting me ? Only kidding ;)

    Well i'm not super heducated, officially :p & i don't know the difference. That's because i've mainly always used & been concerned with FF & previously IE.
     
  21. PJC

    PJC Very Frequent Poster

    Joined:
    Feb 17, 2010
    Posts:
    2,959
    Location:
    Internet
    "As Google Chrome Usage Increases, more Vulnerabilities will come up".
    Time will tell...;)
     
  22. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    +1.

    I think the Google team is doing a wonderful job considering it is dividing its focus over a variety of operating systems and various versions of the same operating system and still has the least vulnerable browser.
     
  23. elapsed

    elapsed Registered Member

    Joined:
    Apr 5, 2004
    Posts:
    7,076
    Even an uneducated user knows that Chrome is simply Chromium repackaged by Google. Do you ACTUALLY think Google is adding the ability for plugins to break the sandbox? Please, think before you post. :rolleyes:
     
  24. vasa1

    vasa1 Registered Member

    Joined:
    May 1, 2010
    Posts:
    4,417
    The same applies to you. Some of your posts border on trolling.
     
  25. Trooper

    Trooper Registered Member

    Joined:
    Jan 26, 2005
    Posts:
    5,507
    Just an update to my exploit that I posted about last week.

    Read this.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.