New issue
Advanced search Search tips

Issue 767502 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Download Protection Bypass: .torrent files can be modified to bypass Full Ping

Reported by bjornbjo...@gmail.com, Sep 21 2017

Issue description

VERSION
Chromium Version: 60.0.3112.113 (Developer Build) 64-bit
Operating System: Ubuntu 16.04.3 LTS 64-bit

REPRODUCTION CASE

a Full Ping of a .torrent file can be avoided by renaming the filename extension to .btapp, .btinstall, .btkey, .btsearch or btskin, 
e.g. x.torrent -> x.btapp.
transmission(default Ubuntu torrent program) opens the renamed files as .torrent files. Chromium does not check this filename extensions.

im attaching my test files.
 
ubuntu-14.04.5-desktop-amd64.torrent
41.5 KB Download
ubuntu-14.04.5-desktop-amd64.iso.btskin
41.5 KB Download
ubuntu-14.04.5-desktop-amd64.iso.btsearch
41.5 KB Download
ubuntu-14.04.5-desktop-amd64.iso.btkey
41.5 KB Download
ubuntu-14.04.5-desktop-amd64.iso.btinstall
41.5 KB Download
ubuntu-14.04.5-desktop-amd64.btapp
41.5 KB Download

Comment 1 by vakh@chromium.org, Sep 21 2017

Cc: nparker@chromium.org
Labels: SafeBrowsing-Triaged
Owner: vakh@chromium.org
Status: Started (was: Unconfirmed)
Thanks for reporting the issue.
Verified that the report reporos for all the reported extensions.

Comment 2 by vakh@chromium.org, Sep 21 2017

Labels: M-63 OS-Linux Pri-2

Comment 3 by vakh@chromium.org, Oct 3 2017

I'm focusing on some other work at the moment but I'll come back to this on or before 10/12. Sorry for the delay here.

Comment 4 by vakh@chromium.org, Oct 12 2017

Cc: -nparker@chromium.org vakh@chromium.org
Owner: nparker@chromium.org
Project Member

Comment 5 by bugdroid1@chromium.org, Oct 27 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/8add59a69da35f2cc0c3585fa44cac696a3d003c

commit 8add59a69da35f2cc0c3585fa44cac696a3d003c
Author: Nathan Parker <nparker@chromium.org>
Date: Fri Oct 27 23:07:31 2017

Add a number of new download_file_types, and some enums we were missing.

Add btapp, btbtskin, btkey, btinstasll, btsearch,
    dhtml, dhtm, dht, shtml, shtm, sht, vdx, vsx,
    vtx, vsdx, vssx, vstx, vsdm, vssm, vstm.

Fix up enums that weren't correct before, an remove some platform_settings
that are set to the defaults anyway.

Bug:  771469 ,  767502 ,  762702 
Cq-Include-Trybots: master.tryserver.chromium.linux:closure_compilation
Change-Id: I4114c35e3f1a56a067f9b61bb54bfe3a8a801531
Reviewed-on: https://chromium-review.googlesource.com/736161
Commit-Queue: Nathan Parker <nparker@chromium.org>
Reviewed-by: Luke Z <lpz@chromium.org>
Reviewed-by: Varun Khaneja <vakh@chromium.org>
Reviewed-by: David Trainor <dtrainor@chromium.org>
Cr-Commit-Position: refs/heads/master@{#512338}
[modify] https://crrev.com/8add59a69da35f2cc0c3585fa44cac696a3d003c/chrome/browser/resources/safe_browsing/download_file_types.asciipb
[modify] https://crrev.com/8add59a69da35f2cc0c3585fa44cac696a3d003c/content/browser/download/download_stats.cc
[modify] https://crrev.com/8add59a69da35f2cc0c3585fa44cac696a3d003c/tools/metrics/histograms/enums.xml

Status: Fixed (was: Started)
Pushed via component update.
Project Member

Comment 7 by sheriffbot@chromium.org, Nov 2 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
i was wondering if this bug qualifies for the Chrome Reward Program?
Project Member

Comment 9 by sheriffbot@chromium.org, Feb 8 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 10 by vakh@chromium.org, Feb 8 2018

Re #c8: Unfortunately reporting file extensions that we don't send the ping for does not qualify for a VRP reward under the rules of the VRP program:

From https://www.google.com/about/appsecurity/chrome-rewards/index.html
"The extension of the binary file must be one of those that Chrome already tracks. This list can be found here: download_file_types.asciipb"

Sign in to add a comment