its times like these (among others) that makes me happy my browser automatically updates behind the scenes
That works as long as the exploit is known. What happens when it's not?
Google Chrome Hacked?
81–90 of 223 posts
Re: Google Chrome Hacked?
#82Re: Google Chrome Hacked?
#83Earlier quoted context omitted.
Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…
This is probably why they keep repeating that their customer is the government. You could probably sell Exxon's security vulnerabilities to the government and demand $N dollars from them to show them how to fix the problem. It's advertising the vulnerability with posts like this that seems most questionable (similar to extortion) to me.
I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be crossing a line if they posted a press release trumpeting a major vulnerability they discovered, mentioning by name which company and approximately where the vulnerability was located, but then refused to disclose it to the company in question.
I'm not sure how much it survives, but I believe there was traditionally even a common-law "duty to warn" if you were aware of significant risks to someone's person or property.
Re: Google Chrome Hacked?
#84I wonder if this is a sandboxing issue with NaCL, which is I noticed was added (default disabled) in Chrome 11. Considering how non specific VUPEN are, I wouldn't be surprised if they're hiding this.
Sounds like it's Windows only, so I'd expect it to be related to the Windows sandboxing.
1) A remote code execution exploit in Chrome
2) A privilege elevation exploit allowing the hijacked browser process to break out of its mandatory access control jail
Number 1 is of necessity a bug in Chrome itself (or a plugin). Number 2 is probably a vulnerability in the Windows sandbox, but it could instead be that they found a way to successfully attack the small part of Chrome that runs outside low integrity mode. They weren't specific as to the details.
This is, again, at the very least a remote code execution hole in Chrome, and there's no fundamental reason Linux or OS X should be invulnerable to the same hole. That Chrome on Windows is less secure than on Linux or OS X would be the wrong thing to take from this; the point of this demo is that VUPEN accomplished the feat of bypassing all the security mechanisms protecting Chrome on Windows, whereas on the other platforms you have fewer of these mechanisms in the first place (no real ASLR on OS X, no Chrome sandboxing last time I checked on Linux).
Re: Google Chrome Hacked?
#85"it works on all Windows systems (32-bit and x64)" They didn't say that the exploit didn't work on Mac or Linux, but one can only assume they tested those and weren't successful?
Or maybe not. I'm just saying, we can't assume either way.
Re: Google Chrome Hacked?
#86Earlier quoted context omitted.
Do policemen work for free? It's a dirty job, I 'd want to be paid
That's a poor example. Policeman get paid to protect everyone; police protection is not (usually) a subscription service.
Re: Google Chrome Hacked?
#87"This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers" Love the capital G.
Re: Google Chrome Hacked?
#88Earlier quoted context omitted.
The net result in this case is the government owning a zero-day root exploit for every Chrome/Win citizen’s computer. It’s worse than zero-day because we have no reason to expect a patch, so the window of attack will stay open.
Wouldn't "the government" keep quiet about even having found an exploit? Why let VUPEN publicize this if they intend to use it?
Re: Google Chrome Hacked?
#89I can understand their joy but the last sentence in the post and the Twitter update: "Sorry Google...we have officially pwned Google Chrome and its sandbox with a 0-Day." [1] seem rather unprofessional for the "world leader in vulnerability research for defensive and offensive security" [2], a company with "Government customers". [1] https://twitter.com/VUPEN [2] http://www.vupen.com/english/company.php
Re: Google Chrome Hacked?
#90Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.