New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 616424 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Bypass Download Protection on Saving Page

Reported by gregory....@gmail.com, Jun 1 2016

Issue description

VULNERABILITY DETAILS
Malicious test binary [https://testsafebrowsing.appspot.com/s/content.exe] get saved to disk when saving a webpage referencing the binary as a resource [Eg:- image]. 

The filename of the page can be named in such a way to entice the user to view the contents of the saved "<pagename>_files" folder, and execute any contents within. This poses a security risk.

VERSION
Chrome Version: 51.0.2704.63 m (Stable)
Operating System: Windows (All)

REPRODUCTION CASE
1. Visit http://grpdmp.tk:27275/gchrome1/_FREE_DEMO.html
2. Save Page (Complete)
3. Malcicious test file gets typically saved to "C:\Users\<username>\Downloads\_FREE_DEMO_files\content.exe"
4. The html file can be modified to prompt for content.exe download on reopening locally [which isn't blocked].


 

Comment 1 by f...@chromium.org, Jun 2 2016

Cc: jialiul@chromium.org
Components: UI>Browser>SafeBrowsing
Status: Available (was: Unconfirmed)
Thanks for the report!

jialiul@, I could swear I've seen this before but I can't find a related bug while searching. Do you know if there is already a bug related to this?
Mergedinto: 599224
Status: Duplicate (was: Available)
Thanks for reporting gregory.panakkai@! 
We are fully aware of this problem and working on a fix. 

Mark as duplicate. 
Project Member

Comment 3 by sheriffbot@chromium.org, Sep 9 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 4 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment