New issue
Advanced search Search tips

Issue 759358 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Aug 2017
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: 2
Type: Bug-Security



Sign in to add a comment

I have hackers and have had since 2015

Reported by xfinityw...@gmail.com, Aug 27 2017

Issue description

UserAgent: Mozilla/5.0 (X11; CrOS x86_64 9460.73.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.134 Safari/537.36
Platform:  Google Chrome	59.0.3071.134 (Official Build) (64-bit) Revision	0 Platform	9460.73.1 (Official Build) stable-channel banon Firmware Version	Google_Banon.7287.313.0 ARC	4176793 JavaScript	V8 5.9.211.41 Flash	26.0.0.137 /run/imageloader/PepperFlashPlayer/libpepflashplayer.so User Agent	Mozilla/5.0 (X11; CrOS x86_64 9460.73.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.134 Safari/537.36 Command Line	/opt/google/chrome/chrome --ppapi-flash-path=/opt/google/chrome/pepper/libpepflashplayer.so --ppapi-flash-version=26.0.0.102 --ui-prioritize-in-gpu-process --use-gl=egl --gpu-sandbox-failures-fatal=yes --enable-logging --log-level=1 --use-cras --enable-wayland-server --arc-availability=installed --user-data-dir=/home/chronos --max-unused-resource-memory-usage-percentage=5 --login-profile=user --has-chromeos-keyboard --default-wallpaper-large=/usr/share/chromeos-assets/wallpaper/oem_large.jpg --default-wallpaper-small=/usr/share/chromeos-assets/wallpaper/oem_small.jpg --default-wallpaper-is-oem --guest-wallpaper-large=/usr/share/chromeos-assets/wallpaper/guest_large.jpg --guest-wallpaper-small=/usr/share/chromeos-assets/wallpaper/guest_small.jpg --enable-prefixed-encrypted-media --enable-consumer-kiosk --enterprise-enrollment-initial-modulus=15 --enterprise-enrollment-modulus-limit=19 --login-manager --policy-switches-begin --default-tile-height=1024 --default-tile-width=1024 --disable-boot-animation --disable-cloud-import --disable-display-color-calibration --disable-gesture-requirement-for-media-playback --disable-new-korean-ime --disable-new-zip-unpacker --disable-office-editing-component-extension --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=true --enable-proximity-auth-proximity-detection --disable-offer-store-unmasked-wallet-cards --disable-pinch --disable-quic --disable-single-click-autofill --disable-sync-app-list --enable-use-zoom-for-dsf=false --enable-webfonts-intervention-v2=disabled --disable-gesture-editing --load-media-router-component-extension=0 --mark-non-secure-as=non-secure --nacl-debug-mask=*://* --reduced-referrer-granularity --disable-smart-virtual-keyboard --touch-events=disabled --ui-disable-partial-swap --v8-cache-options=none --v8-cache-strategies-for-cache-storage=none --disable-virtual-keyboard-overscroll --wallet-service-use-sandbox=0 --enable-features=SafeSearchUrlReporting --disable-features=ArcBootCompletedBroadcast,ArcUseAuthEndpoint,AutofillCreditCardLastUsedDateDisplay,AutofillUpstreamRequestCvcIfMissing,CredentialManagementAPI,EmojiHandwritingVoiceInput,GamepadExtensions,GuestViewCrossProcessFrames,MaterialDesignBookmarks,MaterialDesignSettings,MediaRemoting,MediaRemotingEncrypted,MemoryAblation,PrintPdfAsImage,PrintScaling,QuickUnlockFingerprint,QuickUnlockPin,RunAllFlashInAllowMode,ServiceWorkerNavigationPreload,WebPayments,WebUSB,drop-sync-credential,enable-password-force-saving,token-binding --policy-switches-end --vmodule=*arc/*=1,*chromeos/login/*=1,auto_enrollment_controller=1,*plugin*=2,*zygote*=1,*/ui/ozone/*=1,*/ui/display/manager/chromeos/*=1,power_button_observer=2,webui_login_view=2,lock_state_controller=2,webui_screen_locker=2,screen_locker=2 Executable Path	/opt/google/chrome/chrome Profile Path	/home/chronos/u-350492a16f6183dab66c5bca11f2791d9d142662 Variations	241fff6c-4eda1c57 6345b824-3d47f4f4 3095aa95-3f4a17df 6c43306f-ca7d8d80 7c1bc906-f55a7974 d43bf3e5-bd7cd813 ba3f87da-a2598ccd cf558fa6-48a16532 5ca89f9-3f4a17df f3499283-7711d854 98be3390-d93a0620 9e201a2b-1359b0af 9bd94ed7-b1c9f6b0 9773d3bd-ca7d8d80 b22b3d54-1c15b2e9 99144bc3-3cc2175e 9e5c75f1-40093a1 f79cb77b-3d47f4f4 b7786474-d93a0620 27219e67-b2047178 23a898eb-e0e2610f 4ea303a6-2e46ed91 64224f74-5087fa4a 56302f8c-2f882e70 de03e059-e65e20f2 b2f0086-93053e47 3ac60855-486e2a9c f296190c-9eabb163 4442aae2-e1cc0f14 ed1d377-e1cc0f14 75f0f0a0-6bdfffe7 e2b18481-75cb33fc e7e71889-4ad60575 828a5926-b1fd37f8

Steps to reproduce the problem:
1. opening the development inspection page
2. 
3. 

What is the expected behavior?
I expected no errors and secure pages 

What went wrong?
I get an event listener(s) always writing script and using document write.Also the browser os wont update I still have version 59 also the adobe flash wont update all of this has alot to do with the hackers writing scripts to hide the extension

Did this work before? Yes I think it was 57 when I bought this chromebook 15

Chrome version: 59.0.3071.134  Channel: stable
OS Version: 9460.73.1
Flash Version: Shockwave Flash 26.0 r0

yes I cannot see why these certificates which are invalid keep being used
 
Status: WontFix (was: Unconfirmed)
Seeing text in the Developer Tools is not an indication of malicious activity. Depending on which Chromebook you have, it's possible that 59 is the latest available version. You can check by clicking the status area, where your account picture appears. Click Settings About Chrome OS. In the "About" window that appears, click Check for and apply updates. Your Chromebook will start to install any available updates.

It's generally quite difficult to get any sort of malicious code on a Chromebook, but if you've installed a malicious browser extension and cannot remove it, you may wish to "Factory Reset" your Chromebook by following these steps: https://support.google.com/chromebook/answer/183084?hl=en

If you're having problems with "Invalid certificates" after these steps, please follow the steps in https://textslashplain.com/2017/03/30/get-help-with-https-problems/ to gather the "Error Code" and "Diagnostic Information" from the error page, and paste that into this issue.
Project Member

Comment 2 by sheriffbot@chromium.org, Dec 5 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment