Live data from Hacker News

Google Chrome Hacked?

vupen.com

131–140 of 223 posts

Re: Google Chrome Hacked?

#131
post #54

Whether or not this exploit is impressive, using the term "pwnd" comes across as incredibly unprofessional and predisposes me to perceiving this whole article in a negative light.

No disrespect intended, but, it doesn't negatively predispose anyone who conducts or utilizes vulnerability research professionally, so I doubt your concern matters much to them.

Oh, thank you for this comment. I wasn't aware that literally everyone who uses vulnerability research as part of their job had had a meeting and elected a spokesperson.

Re: Google Chrome Hacked?

#132
post #60

Earlier quoted context omitted.

"Whore" is vernacular, but that doesn't mean the FBI uses the word when they announce they've cracked a prostitution ring.

Only hiring offensive security vendors who won't use the term 'pwned' is roughly equivalent to trying to purchase a hand job from someone who won't use the term 'whore'. Neither is likely to get you very far.

It's called lingerie modeling.

Re: Google Chrome Hacked?

#133
post #49

Earlier quoted context omitted.

I'm confused. Why would the government want to break Chrome? Also, if they are not going to release the exploit soon (especially to Google), why are you saying 'safer software for all'?

you know that there is more than one government on earth... and all of them arent pro free-speech :) Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack

Arguably, that's exactly what VUPEN is doing here. They're keeping it secret, and only letting those who are willing to pay have the necessary knowledge regarding this vulnerability and any possible workarounds. It might not be a scam, but I do find it morally questionable to hide the details of a bug of this significance.

Re: Google Chrome Hacked?

#134

Earlier quoted context omitted.

The government is generally more worried about keeping foreign governments out of high-tech firms like Google than about their ability to hack high-tech firms like Google.

Which government are you referring to?

I have to imagine everyone is referring to the same government agencies referred to in the article.

Re: Google Chrome Hacked?

#135
The two things I noticed were that 1) The user of the device is named "IAmAdmin", implying that they have admin rights, and 2) The "integrity" of chrome.exe is changed from Low to Medium at somepoint during the attack. Could this somehow be related to breaking out of the sandbox?

Re: Google Chrome Hacked?

#136

A video of calculator showing up after clicking a link hardly constitutes proof of an exploit. Considering the fact that they aren't going to publish the exploit, I just want to point out that this kind of thing could easily be fabricated. There are plenty of interests that benefit from unfortunate news about their competitors.

What would those "plenty of interests" be in this case?

Re: Google Chrome Hacked?

#138

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved.

Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

Re: Google Chrome Hacked?

#139
post #138

This video is extremely suspicious to the point of probably being an outright lie. I would wager money that this vulnerability is a Flash exploit sold as a Chrome exploit. It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-l…

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved. Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me.

The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that specific data point a basis for a claim, singular.

Re: Google Chrome Hacked?

#140

Earlier quoted context omitted.

I'm pretty sure they limit their customer base to NATO signatories.

Link?

Well, I was close...

- Gov. and Law Enforcement Agencies in Countries Members or Partners of NATO, ANZUS or ASEAN

http://www.vupen.com/english/services/ba-gov.php

Post reply on HN