Live data from Hacker News

Google Chrome Hacked?

vupen.com

11–20 of 223 posts

Re: Google Chrome Hacked?

#11
Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

Re: Google Chrome Hacked?

#13

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

About 11 yrs ago I was in a chat room talking to someone, he was using this sort of language, was about 16 years old, told me he sold his security company for millions. Of course I wrote him off. Later he sold another company for 35 millions, and today has another one on the market for 100 millions. That's before 30 years old. We're good friends today, and I learned my lesson. Don't write people off because they sound or look "unprofessional".

Re: Google Chrome Hacked?

#15
post #11

Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

Considering the business they're in, I'm not sure lying about that would be a good idea.

Re: Google Chrome Hacked?

#16
seems odd to me that they don't publicly disclose the vulnerabilities, but they do publicly disclose the software versions affected by their "weaponized exploits", thereby giving the heads up to whomever might be targeted to avoid using that newly compromised software.

Re: Google Chrome Hacked?

#17
post #11

Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

I'm willing to bet any of their Government customers wouldn't be able to confirm the exploit anyhow. Seems like an easy way to keep a lucrative Government contract...

Re: Google Chrome Hacked?

#18
post #7
post #4

Earlier quoted context omitted.

I'm not too sure that's the business VUPEN is in. Sure, it doesn't hurt them much to share their latest Safari exploit given how slow Apple is on the fix, but with Google their window has the potential to be very short.

Citation needed for such a serious accusation. They claim to be ethical. From their about page: "VUPEN follows a private responsible disclosure policy and reports all discovered vulnerabilities to the affected vendor under contract with VUPEN, and works with them to create a timetable pursuant to which the vulnerability information may be publicly disclosed."

"With 20 to 25 binary analysis and private exploits/PoCs released each month, the VUPEN In-Depth Binary Analysis and Exploits service allows organizations and corporations to evaluate and qualify risks, and protect national infrastructures and corporate assets from emerging attacks."

If you are interested in protecting your network, patches and workarounds are your first priority, not "proof of concept" exploits.

Re: Google Chrome Hacked?

#19
post #11

Not saying this isn't true, as I'm sure VUPEN is quite legit, but what stops me from creating a keyboard shortcut to calculator.exe, opening a random website which loads for a few seconds, and then pressing ctrl+alt+f6 or something to open calculator?

nothing; nor does anything stop you from doctoring video. but it doesn't seem like faking this would be very beneficial for anyone involved.

Re: Google Chrome Hacked?

#20

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

I think it's a reference to the Pwn2Own contest - https://secure.wikimedia.org/wikipedia/en/wiki/Pwn2Own

Chrome's historically performed extremely well in the competition, which is why it's notable they've actually found an exploit.

Post reply on HN