Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Chrome is throwing false 'Malware' detection for Free Republic
7/29/2014

Posted on 07/29/2014 6:51:20 AM PDT by Lazamataz

click here to read article


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-104 last
To: John Robinson

As you know I work for the Fedgov, and the government schooled me pretty well on stuff to look out for: XSS, XSRF, MiM attacks, Link injection, image injection, SQL injection (obviously), and even cross-tab hijacks (which are EXTREMELY devious and VERY inventive) — in which a dead tab of yours is made to mock up a secure login page in your accessible browser visit history. That’s why I never re-login to a page if it expires. I will request a serve-up a new login page if I ever time out. That prevents the attack from the user perspective. The only way to prevent it programmatically is to close all but focused tabs, which is not only difficult but impractical. Of course, a polished firewall and refusing to allow Java helps with that one, too.

Now the one they are using lately is serving up malicious code inside images/videos/music, and hoping that they can hook into editing or ‘playback’ executables. If they can spoof Paint into running something embedded in a picture, for example, they just might get machine code running. It is tricky as hell to pull it off, but I’ve heard of one or two successful hacks using it.


101 posted on 07/30/2014 6:41:38 PM PDT by Lazamataz (First we beat the Soviet Union. Then we became them.)
[ Post Reply | Private Reply | To 99 | View Replies]

To: John Robinson

Here’s a mildly interesting and completely defensible, less dangerous technique some hackers are using. It relies too much on user cooperation to get it going. http://www.tgdaily.com/security-features/51056-embedded-malware-hidden-in-image-files

The really tricky ones are the ones that use image software itself as the hook, and they are particularly dangerous if various ‘semi-executable’ templates are used by the user.

It’s probably why Adobe keeps on sending me security patches. LOL


102 posted on 07/30/2014 6:46:28 PM PDT by Lazamataz (First we beat the Soviet Union. Then we became them.)
[ Post Reply | Private Reply | To 99 | View Replies]

To: John Robinson

PS: I love talking shop with a fellow professional. :)


103 posted on 07/30/2014 6:47:34 PM PDT by Lazamataz (First we beat the Soviet Union. Then we became them.)
[ Post Reply | Private Reply | To 99 | View Replies]

To: John Robinson

Thread hijack! Just a frien’ly lil’ test. “Hopefully not puking on unicode.” Cryptic ain’t it?

Copy-Pasted: “unnecessary”


104 posted on 07/31/2014 2:18:35 AM PDT by John Robinson
[ Post Reply | Private Reply | To 99 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 41-6061-8081-100101-104 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson