Home

Google Chrome Browser

making the web faster, safer, and easier

Main menu

  • Home
  • Chromebook
  • Chrome OS
  • Books
  • Releases
    • Stable
    • Beta channel
    • Dev channel
  • Downloads
  • Videos
    • Top Rated
    • Most Viewed
    • Most Commented
  • Articles
    • Top Rated
    • Most Viewed
    • Most Commented
  • About Us
Home

Add to Technorati Favorites

Subscribe to Google Chrome Browser by e-mail

Delivered by FeedBurner

Syndicate

Syndicate content

User login

Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password

Tag Cloud

Beta updates browser browsers browsing chrome chrome extensions Chrome OS chromium Dev updates Downloads extension extensions feed Firefox Google google chrome googlechrome Linux News opera release safari security Stable updates TC video web web browser web browsers windows
more tags

Twitter Updates

Follow us on Twitter @ChromeBrowser


    Hacker Pwnes Google Chrome’s Security Brags with a Plugin

    • View
    • Track
    Submitted by admin on Fri, 07/09/2010 - 14:24
    • chrome
    • feed
    • google chrome
    • Google News
    • Internet Browsers
    • security

    <!-- wp-jquery-lightbox, a WordPress plugin by ulfben -->

    Google has made every attempt to keep Chrome secure and safe from hackers. However, it was only a question of days before someone outsmarted their annoying sandbox and today is the day.

    Google Chrome has been hacked by a browser plugin! The plugin checks for login account details on Gmail, Twitter and Facebook and runs with the help of JQuery. Once again, this is a proof of concept hack and will not leak any information retrieved in the process.

    The hack has exploited the access to DOM, which the plugins are allowed. The hack can also be used to steal cookies and hijack sessions as reported by the hacker Andreas Grech on his blog.

    He writes,

    The Google Chrome browser allows the installation of third-party extensions that are used to extend the browser to add new features. The extensions are written in JavaScript and HTML and allow manipulation of the DOM, amongst other features.

    By allowing access to the DOM, an attacker can thus read form fields…including username and password fields. This is what sparked my idea of creating this PoC.

    The extension I present here is very simple. Whenever a user submits a form, it tries to capture the username and password fields, sends me an email via an Ajax call to a script with these login details along with the URL and then proceeds to submit the form normally as to avoid detection.

    Google Chrome’s sandbox for plugins just got pwned.

    (Source)

    Share:
    Comment on This Post |
    Tweet This |
    Share on Facebook |
    Save to Delicious |
    Stumble This |
    Digg This |
    Reddit This

    TAGS: chrome, Google News, Security


    Hacker Pwnes Google Chrome’s Security Brags with a Plugin originally appeared on Techie Buzz written by Chinmoy Kanjilal on Friday 9th July 2010 03:24:26 PM under Internet Browsers. Please read the Terms of Use for fair usage guidance.




    No votes yet
    • 336 reads
    • Feed: Techie Buzz
    • Original article

    Post new comment

    • Web page addresses and e-mail addresses turn into links automatically.
    • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
    • Lines and paragraphs break automatically.
    • E-Mail addresses are hidden with reCAPTCHA Mailhide.
    • You may insert videos with [video:URL]

    More information about formatting options

    CAPTCHA
    This question is for testing whether you are a human visitor and to prevent automated spam submissions.

    Google Chrome Browser is a community site for users and developers of the Google Chrome browser.
    Google™ is a Trademark of Google Inc. All other company and product names may be trademarks of the respective companies with which they are associated.
    Google Chrome Browser site is not affiliated with or sponsored by Google Inc.
    Google Chrome Browser site is built on the Drupal open source content management system.