Issue metadata
Sign in to add a comment
|
Security: Exe file downloaded through Adobe Flash won't trigger Windows Security Warning
Reported by
pepi...@gmail.com,
Nov 21 2016
|
||||||||||||||||||||||
Issue descriptionDownload Protection Bypass bug, please use the "Security - " template. VULNERABILITY DETAILS ".exe" files downloaded through Adobe Flash content won't trigger a Security Warning when later executed on Windows (like this Warning, http://woshub.com/how-windows-determines-that-the-file-has-been-downloaded-from-the-internet/), contrary to what happens on normal file downloads or with the same flash downloader on Firefox and Microsoft Edge. This maybe a "Download Protection Bypass" bug as well. VERSION Chrome Version: Versão 54.0.2840.99 m (64-bit) stable Operating System: Windows 10 Pro fully updated as of 11/21/2016 Adobe Flash Player 23.0.0.207 REPRODUCTION CASE I attached two files for reprodution: a flash file (downloader.swf) and a html file (index.html). They should be hosted into a webserver, along with an exe file for download, and you should edit the html file with the exe file direction. I have them hosted at my webserver, you can access through briefwikipedia.com/downloader/index.html. I also attached the print1.png, where you have the output of the message.exe (downloaded through my webserver) when downloaded using Chrome through the attached webpage, and print2.exe when downloaded using Microsoft Edge (sorry, it's in portuguese but you should have the idea).
,
Nov 21 2016
,
Nov 21 2016
Can someone add me to that issue? Otherwise I don't have permission to access it.
,
Nov 21 2016
Not a download protection bypass since we still pass these files through SafeBrowsing. But yeah, this is a dup of issue 598812 for the MOTW issue.
,
Mar 18 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by kerrnel@chromium.org
, Nov 21 2016