Language Selection

English French German Italian Portuguese Spanish

Google Chrome Browser Exhibits Risky Behavior

Filed under
Software

Google (NSDQ: GOOG)'s Chrome browser may have been designed with security in mind, but that hasn't immunized it from security concerns.

Robert "RSnake" Hansen, CEO of SecTheory, a computer security consulting firm, has identified a vulnerability in Chrome that allows JavaScript code to execute when a user views the source code of a Web page using the view-source: directive.

Hansen's blog post about the vulnerability includes a proof-of-concept Web link that, for Chrome users, triggers the flaw and uses JavaScript to present a dialog box that says, "If you can see this, use another browser...seriously."

While any link can trigger JavaScript in this way, this particular issue could provide a building block for a social engineering attack against a Web developer.

Google is planning to fix the issue shortly. "We believe this behavior does not introduce any particular risk for the vast majority of users who do not use view-source: to browse Web pages," said a company spokesperson in an e-mailed statement. "We're working to more accurately align the view-source: page with expected behavior."

rest here




More in Tux Machines

Games: RUINER, xoEl Empire, Outlast Deluxe Edition, Albion Online and Auto Age: Standoff

Java JDK 9 Finally Reaches General Availability

Java 9 (JDK 9) has finally reached general availability! Following setbacks, Java 9 is officially available as well as Java EE 8. Read more

What Is DNF Package Manager And How To Use It

​A package file is an archive which contains the binaries and other resources that make software and the pre and post installation scripts. They also provide the information regarding dependencies and other packages required for the installation and running of the software. Read
more

FSFE: ‘German public sector a digital laggard’

With their lacklustre approach to free software, German public services remain behind other European member states, says the Free Software Foundation Europe (FSFE). When asked, the current governing parties’ say they support free software, but their statements are contradicted by the lack of action, the advocacy group says. In early September, the FSFE published its analysis of the free software policies put forward by the main political parties on the ballot, in preparation for Germany’s parliamentary elections on 24 September. This analysis (in German) is far more detailed than an earlier report generated by the Digital-O-Mat, a web portal set up to focus on political parties’ positions on 12 digital topics. Read more New release: ISA² interoperability test bed software v1.1.0