New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 667277 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 598812
Owner:
Last visit > 30 days ago
Closed: Nov 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Exe file downloaded through Adobe Flash won't trigger Windows Security Warning

Reported by pepi...@gmail.com, Nov 21 2016

Issue description

Download Protection Bypass bug, please use the "Security - " template.

VULNERABILITY DETAILS
".exe" files downloaded through Adobe Flash content won't trigger a Security Warning when later executed on Windows (like this Warning, http://woshub.com/how-windows-determines-that-the-file-has-been-downloaded-from-the-internet/), contrary to what happens on normal file downloads or with the same flash downloader on Firefox and Microsoft Edge. This maybe a "Download Protection Bypass" bug as well.

VERSION
Chrome Version: Versão 54.0.2840.99 m (64-bit) stable
Operating System: Windows 10 Pro fully updated as of 11/21/2016
Adobe Flash Player 23.0.0.207

REPRODUCTION CASE
I attached two files for reprodution: a flash file (downloader.swf) and a html file (index.html). They should be hosted into a webserver, along with an exe file for download, and you should edit the html file with the exe file direction. I have them hosted at my webserver, you can access through briefwikipedia.com/downloader/index.html. 

I also attached the print1.png, where you have the output of the message.exe (downloaded through my webserver) when downloaded using Chrome through the attached webpage, and print2.exe when downloaded using Microsoft Edge (sorry, it's in portuguese but you should have the idea).
 
index.html
130 bytes View Download
downloader.swf
277 KB Download
print1.png
4.6 KB View Download
print2.png
33.0 KB View Download
Owner: natashenka@google.com
natashenka@, do you know if this is correct behavior or not? Thanks.
Cc: asanka@chromium.org
I believe this is dupe of  Issue 598812 .
Can someone add me to that issue? Otherwise I don't have permission to access it.

Comment 4 by asanka@chromium.org, Nov 21 2016

Mergedinto: 598812
Status: Duplicate (was: Unconfirmed)
Not a download protection bypass since we still pass these files through SafeBrowsing. But yeah, this is a dup of  issue 598812  for the MOTW issue.
Project Member

Comment 5 by sheriffbot@chromium.org, Mar 18 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment