3 ms·
They talk about URLs and MD5 (binary files). Chrome, Safari and Firefox use Google Safe browsing which target malicious pages, rather than malicious files. Mali
by jusob 14y ago
They talk about URLs and MD5 (binary files). Chrome, Safari and Firefox use Google Safe browsing which target malicious pages, rather than malicious files. Malicious pages (HTML, JavaScript) is typically hosted on a different domain that the malicious executable. For my experience, GSB focuses on the malicious HTML/JavaScript. If it is blocked, the user never gets to the malicious executable. if NSS feeds URLS of the malicious executable, it is possible GSB miss them. But this would not be a real world case.
I tested GSB and IE about 2 years ago which a much smaller sample set. There was very little overlap between what they block. So I would be curious how the URLs were gathered.