Home

Google Chrome Browser

making the web faster, safer, and easier

Main menu

  • Home
  • Chromebook
  • Chrome OS
  • Android
  • Books
  • Releases
    • Stable
    • Beta channel
    • Dev channel
  • Downloads
  • Videos
    • Top Rated
    • Most Viewed
    • Most Commented
  • Articles
    • Top Rated
    • Most Viewed
    • Most Commented
  • About Us
Home

Add to Technorati Favorites

Subscribe to Google Chrome Browser by e-mail

Delivered by FeedBurner

Syndicate

Syndicate content

User login

Login/Register
What is OpenID?
  • Log in using OpenID
  • Cancel OpenID login
  • Create new account
  • Request new password

Tag Cloud

Beta updates browser browsers browsing chrome chromebook chrome extensions Chrome OS chromium Dev updates Downloads extensions feed Firefox Google googlechrome google chrome Internet Explorer Linux open source opera release security Stable updates TC video web web browser web browsers windows
more tags

Twitter Updates

Follow us on Twitter @ChromeBrowser


    The Next Web uses cheap JavaScript hack to fool you into installing an extension, heralds new age of phishing attacks

    • View
    • Track
    Submitted by admin on Tue, 07/13/2010 - 12:00
    • extension
    • hack
    • insecure
    • javascript
    • security
    • the next web
    • TheNextWeb

     

    Update: The Next Web has now removed the JavaScript alert bar. Hooray!

    You may recall a couple of months ago when I falsely reported on what I thought was a new feature of Chrome. It was admittedly kind of neat: I thought websites could link themselves to a Chrome Extension, and pop up an alert at the top of your browser if you hadn't installed it.

    As it turned out, it's just a cheap JavaScript hack that looks just like an official Chrome alert. I had hoped that I wouldn't see it again, but of course that was too much to ask of the Internet. As of today, The Next Web is now using it on every single one of its pages. Click through, check it out -- I'm sure they'll appreciate the extra ad impressions.

    For a technology blog, TNW displays disgustingly little foresight. This bar is, in effect, an updated phishing or rogue malware attack. You all know the type: that pop-up that claims to scan your hard disk for viruses but actually installs a bunch of Trojans.

    Does TNW not realise that you could make this bar link to a nefarious domain that looks exactly like the Chrome Extensions website? TNW's intentions might be benevolent, but with such high profile use of this JavaScript copycat, I guarantee that phishers and malware writers will soon be using this bar for the forces of evil.

    Wouldn't it be easy to change the appearance of the bar so that it's obviously not part of the browser? How about making it pink, or changing the logo on the left to something distinctly un-Chromeish?

    TNW has just opened a smelly kettle of fish -- and from now on, I suggest you all read your Chrome alerts carefully before clicking.

     

    The Next Web uses cheap JavaScript hack to fool you into installing an extension, heralds new age of phishing attacks originally appeared on Download Squad on Tue, 13 Jul 2010 12:00:00 EST.

    No votes yet
    • 425 reads
    • Feed: Download Squad
    • Original article

    Post new comment

    • Web page addresses and e-mail addresses turn into links automatically.
    • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
    • Lines and paragraphs break automatically.
    • E-Mail addresses are hidden with reCAPTCHA Mailhide.
    • You may insert videos with [video:URL]

    More information about formatting options

    CAPTCHA
    This question is for testing whether you are a human visitor and to prevent automated spam submissions.

    Google Chrome Browser is a community site for users and developers of the Google Chrome browser.
    Google™ is a Trademark of Google Inc. All other company and product names may be trademarks of the respective companies with which they are associated.
    Google Chrome Browser site is not affiliated with or sponsored by Google Inc.
    Google Chrome Browser site is built on the Drupal open source content management system.