Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:20851
HistoryNov 11, 2008 - 12:00 a.m.

Google Chrome Break

2008-11-1100:00:00
vulners.com
28

Address spoofing. Already patched. It's in the news last month.

Just a reminder, XCON'08 is coming in a week - check http://xcon.xfocus.org/

greetz to drewcopley, drorshalev, zwell, liuyuer, lqa21, and, of course
all@topsec


http://liudieyu.com/kissofthedragon.32168816196486005/

To be viewed with Google Chrome

Last tested
Wednesday, October 29, 2008 at 9:53:18 AM (time zone: UTC/GMT +8 hours)
Up-to-date Google Chrome (version: 0.2.149.30)

Contents
Address spoofing.

  1. Address is displayed "bbb.org".
  2. Contents are not from bbb.org(contents are manipulated).

http://twitter.com/liudieyu

Google Chrome is still "virgin" - Right now only had a bunch of D.o.S,
and, a buffer overrun if user saves the attacker's webpage.