New issue
Advanced search Search tips

Issue 841470 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug



Sign in to add a comment

"Save Link As" for Python/bat/cmd files does not trigger warnings

Reported by milinkov...@gmail.com, May 9 2018

Issue description

VERSION
Chrome Version: 66.0.3359.139 Stable (64-bit) +  67.0.3396.30 Dev (64-bit)
Operating System: Windows 10 Pro 1803 Build 17134.1

REPRODUCTION CASE
1. Open sample.html
2. Right click on any link and select "Save Link As". Click "Save"
3. Execute the downloaded .py/.bat file, which should download the sample pua.exe from https://testsafebrowsing.appspot.com/s/pua.exe ( Files are embedded as data URLs in the html file )
4. Confirm that "pua.exe" is in your Downloads folder

I am not sure if this is expected behavior for these file types, but since the settings for these files ( seen at https://cs.chromium.org/chromium/src/chrome/browser/resources/safe_browsing/download_file_types.asciipb ) are similar to those for "exe" or "zip" files, for which this doesn't happen, I figured I'd ask. I understand these are text files, and it might annoy developers if they got a prompt every time they downloaded a .py file, but these are also ( conditionally ) executable files, especially python files, which won't trigger the UAC prompt. 

The Download Protection Ping increments, but since these are text files, they can easily be changed and don't require signing, so I wasn't sure if this would be considered dangerous or not.


 
sample.html
620 bytes View Download

Comment 1 by vakh@chromium.org, May 11 2018

Labels: SafeBrowsing-Triaged

Comment 2 by vakh@chromium.org, May 11 2018

Status: WontFix (was: Unconfirmed)
OP -- thanks for the report.

As you noted, the download protection ping gets incremented for these files.
That also means that we send a hash of the file to Safe Browsing service to verify that the file is safe to download and execute.
If the file contents change, then a different hash would be sent to Safe Browsing service, and Chrome may get a different verdict for the file.

As such, this is working as intended so marking it as WontFix.
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 18

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment