New issue
Advanced search Search tips

Issue 840800 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2018
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

periodic loading in the background "https://getcntr.ru/gms/?state=3"

Reported by mrserovs...@gmail.com, May 8 2018

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.139 Safari/537.36

Steps to reproduce the problem:
When using Chrom browser 2 months ago began to observe a bug. Approximately once per hour, for 5-10 minutes, the video card started to get very hot. Mining, but who? When working in another browser, the problem is not observed. Disabling and removing all extensions in Google Chrome did not help. Antiviruses with a full scan and nothing found. The other day working in Excel with a lot of data Winds hung. At that moment, one window was opened by Chromium. apparently Windows reloaded all the processes. And for 5 seconds there was one more separate window with Chrome browser with the open page https://getcntr.ru/gms/?state=3. When I visit this page, I understand that active mining begins. As it became clear from the statistics of attendance of this resource, this is the problem of the Eurasian segment. I looked at the forums, in Russia many people start to abandon Chrome in favor of other browsers, because chrome strongly heats the card. But apparently the reason for the vulnerability is that it allows the attacker to run a hidden chrome process for "quiet" mining.

What is the expected behavior?

What went wrong?
periodic loading in the background "https://getcntr.ru/gms/?state=3" and heating of the video card

Did this work before? N/A 

Chrome version: 66.0.3359.139  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

BitCoint is evil
 
The target tab is indeed a coin-mining site, however, closing the tab seems to stop the mining and I wasn't able to see any sort of persistence mechanism.
Status: WontFix (was: Unconfirmed)
Unfortunately this does not constitute a vulnerability in Chrome, nor is it in violation of our SafeBrowsing policies, so there's nothing much we can do here.

Do you have any idea if this is potentially related to a piece of unwanted software that was inadvertently installed on your computer, or is it related to any specific site you frequent?
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 15

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment