Live data from Hacker News

Google Chrome Hacked?

vupen.com

141–150 of 223 posts

Re: Google Chrome Hacked?

#141

Earlier quoted context omitted.

I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.

Be fair. Exceptional claims require exceptional evidence. They offer no evidence at all. Scepticism is healthy.

A security bug in a web browser on windows may not happen everyday, but I've heard more extraordinary things.

Re: Google Chrome Hacked?

#142

Earlier quoted context omitted.

Publicly announcing a security vulnerability, claiming that you're sharing it with other clients with the intent of using it for "weaponized ... offensive missions", and then demanding a fee to gain the information to protect against said weaponization, sounds an awful lot like extortion. In the offline world, I don't think you can legally run a business with a strategy of: discover a problem in the security at one o…

I don't see why not. As long as you don't actually break into Exxon and commit I crime. The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over. But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensatio…

It is possible to be an accessory to a crime. If you plan a bank robbery and give the details to somebody else to perform, you're still guilty. Hell, you're still guilty even if you never perform the crime (conspiracy to commit ...)!

If you send a letter to a bank saying "I have found a breach in the kind of vault you use at your banks, I'm giving the details to some expert robbers but you can't have it unless you pay me $10m", with evidence you've done it, I'm pretty sure you will find yourself waking up at gunpoint at 6am, courtesy of the FBI.

Since unauthorised access of a computer is a crime in many places, I'm sure you can see the relevance, even if the consequences aren't as drastic. One hopes that we have misinterpreted this and that they have performed 'responsible disclosure' by telling Google all the details.

Re: Google Chrome Hacked?

#143

Earlier quoted context omitted.

I have over the years participated on a number of communities "for smart people", and this is the case in all of them. People have their particular points of view, and when there is some evidence against what the group considers to be good they use all kinds of ad-hominem attacks. I know it is just human nature, but it is sad that people don't see these patterns occurring.

Be fair. Exceptional claims require exceptional evidence. They offer no evidence at all. Scepticism is healthy.

Browser bugs are found in every single browser on every single platform. They're reported for free, traded privately, sold privately, given to the vendor for a bounty, used to spread malware, discovered in American corporations, discovered in Iranian corporations, and more. There is nothing exceptional here. This is business as usual. It's non-trivial, but far from exceptional.

Re: Google Chrome Hacked?

#144
post #138

Earlier quoted context omitted.

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved. Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

It just sounds to me like they are exploiting a size overflow in some kind of content - a 400MB image, video, sound, 400MB of self expanding Javascript ... I'm not sure how you can conclude only flash can take such memory.

Re: Google Chrome Hacked?

#145
post #53
post #18

Earlier quoted context omitted.

"With 20 to 25 binary analysis and private exploits/PoCs released each month, the VUPEN In-Depth Binary Analysis and Exploits service allows organizations and corporations to evaluate and qualify risks, and protect national infrastructures and corporate assets from emerging attacks." If you are interested in protecting your network, patches and workarounds are your first priority, not "proof of concept" exploits.

Do you do a lot of in-the-field security work? How do you work around a vulnerability without being able to see whether and how it works?

If VUPEN found the vulnerability, the work around is to pay VUPEN in order to patch your codebase. Pretty simple, theoretically.

If you don't have access to the codebase (like a Safari or MSIE bug), then you pay VUPEN to disclose a firewall filter, or some other kind of deep packet inspection to disallow the code required to execute the vulnerability on your network. Again, pretty simple, in theory.

VUPEN plays a pretty tight game. The only way to get in on their action is money. You know this though, and I doubt our opinions differ on the matter. Unlike opensource, full-disclosure GitHub junkies, some people find enjoyment in financially benefiting on everything they stumble across. Just another side of the coin, and the argument about that topic is best left for other sites. :)

Re: Google Chrome Hacked?

#146
post #44

Earlier quoted context omitted.

Out of speculation, would this tie in at all to an article I saw on HN a while back about the Government hiring 3rd parties to hack Google for some reason?

Is it wrong for our government to do any security research? I mean can good things not come out of it? Be thankful it was reported.

I never said if anything was right or wrong, nor did I assume any of it, I just asked if it was related. Good to know curiosity gets flagged around here.

Re: Google Chrome Hacked?

#147
post #138

Earlier quoted context omitted.

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved. Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

(Note that I haven't been able to see the original video so far, so add salt to taste.)

> If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me.

I can understand this as a weak prediction, but it certainly doesn't work as a strong one. I can trivially make a tab use over a gigabyte of memory in recent Chromium by creating a gazillion nested objects in JavaScript. (I just did, in fact. If you really want the screenshot and/or source, say so and I'll post it somewhere.) Absent some default limit in V8 that I haven't encountered, I could presumably make it use unbounded memory. I can also create apparently-unbounded latency in a single tab's UI this way, by chewing up CPU in blocking JavaScript code, though this will eventually trigger the “page seems unresponsive” dialog box.

I would also tend to expect an exploit to potentially abuse the JavaScript engine by straining its limits, including things like pouring a large number of identical objects onto the heap to fill memory with exploitable patterns.

Re: Google Chrome Hacked?

#148
post #40

Earlier quoted context omitted.

Who cares if they sound unprofessional to you? Very obviously they produce.

"Who cares if they sound unprofessional to you? Very obviously they produce." Sadly we can't verify that in this case. Because you know, we're not the CIA.

VUPEN cracks Chrome for the Government!!!!! On Windoze, even!

I would have thought if they really had a US govt / CIA / military / espionage customer, said customer would NOT want them to reveal ANYTHING about the exploit to Google nor the public, especially not its existance. So, they told us that there is an exploit, and now it's top hax0r news, might likely feature in mainstream news. Most sensible people will most likely hear of it, and will disable flash / plugins in chrome until someone fixes it. Any worthy target for netspionage with any money and brain will hear about it immediately, and quit using chrome for lynx, dillo, or something even simpler.

Anyone who uses such a large app as a modern over-engineered web HTML5 bugzilla-feeding browser is kissing security goodbye forever. GNU ls(1) may have security bugs FFS, do you think your browser doens't? Do they include Chrome or Firefox in the 'pretty secure' OpenBSD base install? No, no, they do not nor never will do this, although it is a most popular app!! (also because nearly all *BSD boxes become servers, but you get my drift.) Even if Chrome were regarded as an essential system service for every box to run, they would NOT include it! better the system grind to a halt by itself without yielding access.

Google will redouble Chrome's general security and sandbox security in a push-patch, and this will most likely break the hack. Or they will rediscover it. LOL at your short-lived hack, your Government _will_ be pleased that you disrespected their payment and trust, boasting about it everywhere, putting Google and their targets on red-alert.

The 'secret black ops' part of Government would not only be displeased, they would kick their ass so damn hard for revealing that there is an exploit, that they would not be able to discover more exploits for years due to severe ass damage pain.

They pay you to learn stuff so we can do espionage or whatever fuckdoggery they might be intending at poor Arab countries to steal their oil, or suchlike... Then this silly idiot hacker company posts 'woohoo we found an exploit, look at us: but we can't tell you how it works - 'tis just for our pals in the govt'. Then the presumably nasty branch of govt gets out the concrete mixer and applies the concrete slippers - national borders not being much of an obstacle - then tosses the talkative hackers into the middle of the pacific trench (there's deep water there). They are then eaten by those nasty deep-sea fish with big teeth, and lights on stalks to freak us out.

So anyway, this 'half-secret hack' business reeks deeply of bullshit to me.

For some real bullshit, forget everything else I said. Windows is the utter pinnacle of bullshit for security, full stop. I understand that certain few idiots among the population do use it for playing games, and watching porn, and trying to be hackers, and in offices, but seriously: if you use Windows, any edition of Windows, for your own security, you obviously have not a clue nor give a real fuck about your security at all. Your password is probably 'dog' or 'cat'. OS X and Linux are barely any better for security.

If you want real security, throw away all the public and commodity crap operating systems and build your own. Or pay someone smart to build it. If it takes you less than 5 years to debug it before deployment, or it's more than 100KB of code in total size, I guess you failed: it's not secure. I'll give you a hint. Every process in the system should have access to precisely nothing by default. Not even the CPU, not even the time of day. Every single resource that is needed must be introduced to the process's environment by a neighbor or parent process (if possible, and in most cases it should not be). The entire system, especially process / resource structure, privilege and connection must be visible as a nested, nodes-and-arcs graph, for the user / sysop to verify and check what the hell is going on in it. If there's no link from Chrome to your printer, and you've disabled changes to that part of the process structure, Chrome will not ever print anything unless there's a solar storm - or similar stimulus - that miraculously alters everything without crashing it. You ANTICIPATED THAT UNLIKELY EVENT, and made 3 or 4 systems running everying exactly the same, in parallel, in sync at each step. If one screws up due to solar fuckdoggery, throw it in the bin and swap in another (like RAID). They do this shit in planes I believe, not the swap in bit, until it lands. The solar demons won't miraculously pseudo-break them all at once in the SAME WAY.

Windows, Microsoft, Security - can you spot the odd one out? Can you see a juxtaposition here folks? Can you feel it? A disturbance ripples through the force, out through the local cluster (of galaxies) and back, because those three words were collected together in one place.

No amount of ill-acquired M$ money spent on Windoze security enhancements can break their appallingly bad track record for security holes, loss of privacy, and the happy virus cultivation ecosystems that Microsoft has consistently provided over the years with every version of Windows, almost from before viruses were invented. I think the first well-made and famous exploit came well before windows was conceived, I'd suggest Ken's cc hack. That's the first brilliant exploit I happen to know about - from the vendor himself, sly bastard. It's hard to believe he didn't go to jail for that, anyway, heh.

So yeah - VUPEN, Chrome, Windoze, haX0Rz working for the Big-G Government. LOL. Security Jokes all around. Chrome being the more respectable and secure among them in my opinion. And anyone who runs a nuclear reactor that depends for its stability or continued safe operation on a computer is a cow-tipping idiot too. Cars don't even. @stuxnet @.mil

Re: Google Chrome Hacked?

#149
post #138

Earlier quoted context omitted.

> First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved. Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?

On an otherwise empty page? Yes, it is extremely likely when combined with the payload delay. If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me. The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that s…

No, it's not extremely likely. Given that most browser exploits utilize some sort of a heap spray, a growing memory usage is almost standard pattern for a browser vuln.

Re: Google Chrome Hacked?

#150
post #40

Earlier quoted context omitted.

Who cares if they sound unprofessional to you? Very obviously they produce.

"Who cares if they sound unprofessional to you? Very obviously they produce." Sadly we can't verify that in this case. Because you know, we're not the CIA.

I forgot to mention - Chrome, it's written in a dialect of C, right? Ahahahhahaha!! and there goes any chance of security right there.
Post reply on HN