5 ms·
Seems like a trap backfired -> https://www.google.com/support/forum/p/Chrome/thread?tid=687e9c4e6f11e35f&hl=en https://www.google.com/support/forum/p/Chrome/thr
by majmun 15y ago
Seems like a trap backfired -> https://www.google.com/support/forum/p/Chrome/thread?tid=687e9c4e6f11e35f&hl=en https://www.google.com/support/forum/p/Chrome/thread?tid=687...
BTW I have to agree if vulnerable flash is included in default installation of chrome that is essentially the same thing as pwning chrome.
- justinschuh 15y agoI wouldn't say it backfired, but after releasing we did discover that some Flash obfuscators used on games behave almost identically to a JIT spray attack. This is a shame because their obfuscation technique doesn't really add any value, but it does hurt performance, consume very large amounts of memory, and negatively impact stability. We've adjusted the detection to accommodate, and will make further adjustments as necessary.
- ootachi 15y agoIf causing crashes isn't backfiring, then I don't know what is.
- kevingadd 15y agoIn the future you should consider not adding code like this to your browser, since it doesn't really add any value either.
- othermaciej 15y agoBased on what Justin said, it sounds like what they tried to add is a defense against JIT spray attacks, not just a detector, which, if effective, would actually be pretty valuable. JIT spray attacks are pretty dangerous, because they defeat many of the usual protections against exploiting buffer overflows for code execution (e.g. DEP and ASLR on Windows). So it certainly would be valuable to try to defend against these kind of attacks, if that is what the Chrome folks were doing. Apparently it was not effective in the end, but we may never know, since VUPEN doesn't plan to disclose how they escaped the Chrome sandbox.
- justinschuh 15y agoYeah Maciej, that's the gist. The VUPEN guys told us it was effective at preventing the JIT spray, so they used an information leak to bypass ASLR/DEP.
- daeken 15y agoI'm curious as to how you're doing JIT spray detection. Do you have any info on this?
- js2 15y agoSee the links from http://news.ycombinator.com/item?id=3689491 http://news.ycombinator.com/item?id=3689491 - the bug in particular has some helpful commit comments, then read through http://src.chromium.org/viewvc/chrome/trunk/src/webkit/plugins/npapi/webplugin_delegate_impl_win.cc?view=markup http://src.chromium.org/viewvc/chrome/trunk/src/webkit/plugi...
- hammersend 15y agoWhat would you suggest as an alternative? Not bundle flash? Then people will just download it anyway and many will end up with an old vulnerable version. At least with this the user can stay updated automatically with Chrome. The alternative is a net security net negative.
- deleted 15y ago[deleted]
- majmun 15y agoso i heard that java applets are similair vulnerability mess , so why not also bundle java with chrome? for net gain.
- mayanksinghal 15y agoBecause Java applets are not that popular anymore so there isn't much of a need. Javascript graphic apps are still slow, lack the smoothness and an experienced developer community that would build new games/apps or port old ones. As sad as it may be to accept it, flash is more popular and fully featured than most alernatives. Who knows, Unity3D will substitute it for games, HTML5 Video /Sound for playing videos. While that happens, we will soon realize that Unity3D is another plugin-in-browser solution and might be (and I am just speculating here) vulnerable to issues similar to flash; while content providers will stop pushing video content because of lack of DRM like technology with HTML5 Videos. Please note that I am NOT supporting/rejecting any of the mentioned technologies; this is just a reply to a straw man argument.
- majmun 15y agoI don't know about java being unpopular according to this site (first i could find in google) -> http://www.statowl.com/plugin_overview.php http://www.statowl.com/plugin_overview.php it has 75% of market share, second to flash with 95%. if you have some other numbers I would like to hear it.
- 15y ago
- fruchtose 15y agoTo their credit, they pushed a fix the very next day. I would call that very minimal collateral damage. Google took responsibility in a timely manner for a non-critical bug.