New issue
Advanced search Search tips

Issue 663521 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

traffic Interception

Reported by vzm...@gmail.com, Nov 8 2016

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.87 Safari/537.36

Steps to reproduce the problem:
1. Enable Chrome Data saving https://goo.gl/EVKH15
2. Open site http://music.mosmetro.ru/
3. Opens porn site, url remains the same

What is the expected behavior?
Opens the website mosmetro

What went wrong?
When the data save options from Google offers a porn site if you disable site options open as it should

Did this work before? N/A 

Chrome version: 54.0.2840.87  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: Shockwave Flash 23.0 r0
 
chrome_2016-11-09_01-08-01.png
183 KB View Download
chrome_2016-11-09_01-10-02.png
1.2 MB View Download

Comment 1 by vzm...@gmail.com, Nov 8 2016

I try to reproduce the problem by using a different VPN service can not be played.

The problem only occurs if the option to save the data from Google
Status: WontFix (was: Unconfirmed)
Hi, thank you for your report - I've forwarded this report to the relevant team inside of Google.

Since this isn't a bug directly in Chromium, I'm going to close this report wontfix, but the Data Saver team should take a look and fix this on their end if there's a bug. I'll post a comment here when I hear back from them, thanks!
Hi, I heard back from some of the Data Saver folks, and it appears that the site is actually sending that porn page to Google servers. Unfortunately, there is little we can do to change this :-(

Comment 4 by vzm...@gmail.com, Nov 9 2016

Hello, thanks for the answer, I will try to contact the development team music.mosmetro.ru write after receiving a response.
Thanks, have a nice day!
One more update: The Data Saver team has pushed a workaround to not go through Google servers for that site, so it should hopefully display properly with Data Saver enabled now. Thanks for contacting the music.mosmetro.ru team - let us know if they change anything on their end, and I'd be happy to relay that to the Data Saver team.

Comment 6 by vzm...@gmail.com, Nov 10 2016

Thank you.

The answer to my letter team music.mosmetro.ru:

"Yes, thank you! Our developers have already dealt with this problem!
Thanks a lot for your help!"

Unfortunately, when solve the problem and decide whether it I do not know.

I asked to tell me if they fixed a problem.
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 15 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment