New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 600609 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

Download Protection: RDP files are not checked on Windows

Reported by resea...@nightwatchcybersecurity.com, Apr 5 2016

Issue description

VERSION
Chrome Version: 49.0.2623.110 (Official Build) m (32-bit)
Operating System: Windows 2012 R2; version 6.3.9600

REPRODUCTION CASE
RDP files can be malicious:
https://technet.microsoft.com/library/security/ms15-082

Example file:
https://github.com/hjgode/rdmInject/blob/master/RDMinjectDLL/default.rdp

 
Labels: -Restrict-View-SecurityTeam Restrict-View-Google
Owner: ----

Comment 3 by asanka@chromium.org, Apr 15 2016

The RDP file doesn't carry a payload. MS15-082 calls this out as "[allows RCE] if an attacker first places a specially crafted dynamic link library (DLL) file in the target user’s current working directory and then convinces the user to open a Remote Desktop Protocol (RDP) file."

The payload is carried in the DLL file, which SafeBrowsing already considers to be supported and dangerous.

Comment 4 by vakh@chromium.org, Apr 15 2016

Status: WontFix (was: New)
Re #3, asanka@: yes, thanks for pointing that out. This makes this attack ineffective.

research@nightwatchcybersecurity.com: Thanks for reporting the issue. I'm marking the issue as WontFix for the reasons stated in #3 and #4.
Please feel free to add more information to the issue if there's a way to use malicious RDP files without placing another binary on the user's machine first.
Cc: ya...@nightwatchcybersecurity.com

Comment 6 by vakh@chromium.org, Mar 10 2017

Labels: -Restrict-View-Google Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 7 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment