Search
Search titles only
By:
Search titles only
By:
Log in
Register
Search
Search titles only
By:
Search titles only
By:
Menu
Install the app
Install
Forums
New posts
All threads
Latest threads
New posts
Trending threads
Trending
Search forums
What's new
New posts
New ads
New profile posts
Latest activity
Free Ads
Latest reviews
Search ads
Members
Current visitors
New profile posts
Search profile posts
Contact us
Latest ads
Ad icon
GOOGLE AI PRO - 18 Month - Rs.500.00
Sanathbh
Updated:
Yesterday at 8:25 PM
📸 SIGMA 85mm F1.4 DG HSM | Art — Nikon Mount
romeshnonis
Updated:
Wednesday at 3:56 PM
Ad icon
Singapore V2Ray VPN for Tunneling
hu KANNA
Updated:
Monday at 9:03 PM
Plan your Crypto & Forex entries before you take the trade
romeshnonis
Updated:
Monday at 3:20 AM
RHCSA, RHCE, AWS, Docker, Kubernetes Training
Sanjeewani95
Updated:
Sep 8, 2026
Electronics
Vehicles
Property
Search
Reply to thread
Forums
General
ElaKiri Talk!
What is the best Browser
Get the App
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Message
<blockquote data-quote="hansakach" data-source="post: 2889586" data-attributes="member: 4419"><p><strong>Serious Security Flaw in Google Chrome (Carpet-Bombing)</strong></p><p></p><p><span style="color: DarkRed"><span style="font-size: 15px">Google Chrome has quickly become one of our favorite browsers , but as Ryan Narraine, a security evangelist at Kaspersky Lab, reports, Chrome has also inherited a potentially serious security flaw from the old version of WebKit it is based on. An attacker could easily trick users into launching an executable Java file by combining a flaw in WebKit with a known Java bug and some smart social engineering.</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Security expert Aviv Raff, who first discovered this flaw, set up a demo of the exploit here. (Note: This page will automatically download a Java file onto your desktop). You can safely click on the download, as it only opens up a notepad application written in Java.</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Carpet-Bombing</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">The problem here is that, after a user double-clicks the download at the bottom of the screen, this application is opened without any warning, which would allow a malicious hacker to easily execute any Java program on a user's machine.</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Two facts make this exploit especially embarrassing for Google. First of all, Google stressed the security of Chrome in both the official announcement as well as in today's live video demo just before the launch.</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Apple Already Did It</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">More importantly, as ZDNet reports, Apple already patched WebKit against this flaw when it released Safari 3.2.1 in July, though only after the flaw had been known already for more than two months. Google, however, is using an older version of WebKit as the basis for Chrome.</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Social Engineering</span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px"></span></span></p><p><span style="color: DarkRed"><span style="font-size: 15px">Obviously, this exploit only works because of the social engineering behind it. Just like some pop-up ads trick users into clicking "OK" because the ad mimics a typical system message in Windows, this exploit would trick users who are not yet familiar with Chrome's interface into believing that the download is actually just part of the web page.</span></span></p><p></p><p><span style="color: #8b0000"><span style="font-size: 18px"><span style="font-family: 'Century Gothic'">what do u say about this ???? <img src="/styles/default/xenforo/smilies/default/confused.gif" class="smilie" loading="lazy" alt=":confused:" title="Confused :confused:" data-shortname=":confused:" /> <img src="/styles/default/xenforo/smilies/default/confused.gif" class="smilie" loading="lazy" alt=":confused:" title="Confused :confused:" data-shortname=":confused:" /> <img src="/styles/default/xenforo/smilies/default/confused.gif" class="smilie" loading="lazy" alt=":confused:" title="Confused :confused:" data-shortname=":confused:" /> </span></span></span></p></blockquote><p></p>
[QUOTE="hansakach, post: 2889586, member: 4419"] [b]Serious Security Flaw in Google Chrome (Carpet-Bombing)[/b] [COLOR="DarkRed"][SIZE="4"]Google Chrome has quickly become one of our favorite browsers , but as Ryan Narraine, a security evangelist at Kaspersky Lab, reports, Chrome has also inherited a potentially serious security flaw from the old version of WebKit it is based on. An attacker could easily trick users into launching an executable Java file by combining a flaw in WebKit with a known Java bug and some smart social engineering. Security expert Aviv Raff, who first discovered this flaw, set up a demo of the exploit here. (Note: This page will automatically download a Java file onto your desktop). You can safely click on the download, as it only opens up a notepad application written in Java. Carpet-Bombing The problem here is that, after a user double-clicks the download at the bottom of the screen, this application is opened without any warning, which would allow a malicious hacker to easily execute any Java program on a user's machine. Two facts make this exploit especially embarrassing for Google. First of all, Google stressed the security of Chrome in both the official announcement as well as in today's live video demo just before the launch. Apple Already Did It More importantly, as ZDNet reports, Apple already patched WebKit against this flaw when it released Safari 3.2.1 in July, though only after the flaw had been known already for more than two months. Google, however, is using an older version of WebKit as the basis for Chrome. Social Engineering Obviously, this exploit only works because of the social engineering behind it. Just like some pop-up ads trick users into clicking "OK" because the ad mimics a typical system message in Windows, this exploit would trick users who are not yet familiar with Chrome's interface into believing that the download is actually just part of the web page.[/SIZE][/COLOR] [COLOR="#8b0000"][SIZE="5"][FONT="Century Gothic"]what do u say about this ???? :confused: :confused: :confused: [/FONT][/SIZE][/COLOR] [/QUOTE]
Insert quotes…
Verification
Haya warak paha keeyada? (haya wadi kireema paha)
Post reply
Top
Bottom