Zero Day
Ryan Naraine and Dancho DanchevGoogle Chrome vulnerable to carpet-bombing flaw
Summary
Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.
Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference [...]
Topics
Blogger Info
Ryan Naraine
Biography
Ryan Naraine
Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.
Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.
Dancho Danchev
Biography
Dancho Danchev
Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks.
Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities — a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference — to trick users into launching executables direct from the new browser.
Raff has cooked up a harmless demo of the attack in action, showing how a Google Chrome users can be lured into downloading and launching a JAR (Java Archive) file that gets executed without warning.
[ SEE: Google Chrome, the security tidbits ]
In the proof-of-concept, Raff’s code shows how a malicious hacker can use a clever social engineering lure — it requires two mouse clicks — to plant malware on Windows desktops.
The Google Chrome user-agent shows that Chrome is actually WebKit 525.13 (Safari 3.1), which is an outdated/vulnerable version of that browser.
Apple patched the carpet-bombing issue with Safari v3.1.2.
Some Google Chrome early adopters using Windows Vista are reporting that files downloaded from the Internet are automatically dropped on the desktop, setting up a scenario where a combo-attack using this unpatched IE flaw could be used in attacks.
Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.
Disclosure
Ryan Naraine
Biography
Ryan Naraine
Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.
Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.
More from “Zero Day”
Related Discussions on TechRepublic
Did you know you can take part in these discussions with your ZDNet membership?Talkback Most Recent of 129 Talkback(s)
-
reverseswing09/02/2008 03:18 PM -
Especially when its built...
...on previously compromised code. Wonder if Apple bothered to remind them of that little factoid.
flatliner09/02/2008 09:28 PM -
Why would Apple tell them?
Anyone can download the source. It's fairly difficult for all possessors of the source to be notified directly.
rpmyers109/03/2008 06:09 AM -
No one except Google
is to blame for this pathetic oversight.
Sure, Apple's original software had the flaw, but given that this was s KNOWN flaw, once Google modified it and slapped its name on it Apple's responsibility ended.
wow. pathetic, just pathetic
tikigawd09/03/2008 09:16 AM -
Yep. Pretty lame.
I was wondering about it when I read that Chrome was based on WebKit, as is Safari.
Duh.
seanferd09/03/2008 06:59 PM -
Give me a break! It's a BETA...
Let me remind EVERYONE here, this is a BETA RELEASE... they have NOT yet CLAIMED to be vulnerability free!!! The point of a beta is to allow users to try a PRE-RELEASE of the software... when you download the software, you agree to their terms which states they take no responsibility for downloading the BETA PRE-RELEASE of the software... I will agree it seems silly that they didn't build off of the latest release of webkit, however, unless you are a coder, and unless you understand what must truely go into the creation of software, I don't want to hear your calling a brilliant new entry into the web browser war...
jacobfogg09/04/2008 08:57 AM -
As usaual...
Im impressed by your (jason) beautiful words supporting the crashing of the Google Chrome. If this had happened to Microsoft, everyone will throw hot-blows on them. When it comes to Google Chrome, everyone speaking about; 'this is beta', 'there might be bugs', and thus the supporting explanations goes on.
I still know alot of forums, shouting at the bugs in the IE8 beta release. At that time, there was no one to think that IE is in BETA state.
Anyway, choices & opinions are personal. It will be much better, if u watch your back at the time of commenting.
abhilashca(Edited: 09/04/2008 10:14 AM) -
ie8 = beta?
You are kidding, right? IE8 != IE1. It's evolutionary, not revolutionary. Chrome is brand spankin new, not built atop previous releases.
It's an oversight on the version of the software used to build it, not something that's coded into the product.
smoring09/05/2008 05:46 PM -
except WebKit is NOT the compromised code
the exploit has nothing to do with WebKit, but it's about
Apple's decision to automatically download anything with Safari,
which is part of the UI shell, not the webkit engine.
Chrome already has an option to prompt every time before
download, so it's actually NOT vulnerable to this carpet bombing
exploit.
wellofsouls09/03/2008 08:41 PM -
more typical ZDnet FUD
Chrome prevents access to user folders including the
desktop using permissions. R-E-A-S-E-A-R-C-H
ericesque09/02/2008 03:43 PM -
Are u sure?
Google did say they don't have full control of those plug-ins running inside Chrome.
LBiege09/02/2008 03:45 PM -
RTFA
Did you see where demos were made, along with a link? Don't believe it? Try it yourself.
rpmyers109/02/2008 04:15 PM -
OOPS
Apologies!
egg on face
mouth outfitted with shoe store
etc...
In my defense, I read the whole comic, so clearly I am
a Chrome security expert already... there must be
something wrong with the intarweb.
ericesque09/02/2008 06:06 PM -
eggmanbubbagee@...09/03/2008 06:42 AM -
RE: Google Chrome vulnerable to carpet-bombing flaw
"Raff???s code shows how a malicious hacker can use a clever social engineering lure ??? it requires two mouse clicks ??? to plant malware on Windows desktops."
I can do that in one click. Open Internet Explorer.
drhowarddrfine09/02/2008 06:46 PM
Talkback - Tell Us What You Think
Get it the way you want it
ZDNet Newsletters
Get the best of ZDNet delivered straight to your inbox
Blog Roll
- All About Microsoft
- The Apple Core
- Between the Lines
- BriefingsDirect
- Collaboration 2.0
- Dev Connection
- A Developer's View
- Digital Cameras & Camcorders
- Ed Bott's Microsoft Report
- Emerging Tech
- Enterprise Web 2.0
- Five Nines: The Next Gen Datacenter
- Forrester Research
- Googling Google
- GreenTech Pastures
- Hardware 2.0
- Home Theater
- iGeneration
- India IT
- Irregular Enterprise
- IT Project Failures
- Laptops & Desktops
- Lawgarithms
- Linux and Open Source
- Managing L'unix
- The Mobile Gadgeteer
- On Sustainability
- The Semantic Web
- Service Oriented
- Smartphones and Cell Phones
- Social Business
- Social CRM: The Conversation
- Software & Services Safari
- Software as Services
- Storage Bits
- Team Think
- Tech Broiler
- Tom Foremski: IMHO
- The ToyBox
- Virtually Speaking
- The Web Life
- ZDNet Education
- ZDNet Government
- ZDNet Healthcare
- Zero Day
Blog Archive
White Papers, Webcasts, & Resources
- 77 Features for Windows 7 that Every IT Professional Should Know AboutWindows 7 builds on Windows Vista's positives and eliminates many of the ... (Global Knowledge) Download Now
- 10 Dying IT SkillsThere are some things in life, like good manners, which never go out of ... (Global Knowledge) Download Now
- Ten Things You Should Know about Windows 7There's a lot to Windows 7 - as one might expect, in a 17GB operating ... (Global Knowledge) Download Now




