[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Google Chrome Break

Address spoofing. Already patched. It's in the news last month.

Just a reminder, XCON'08 is coming in a week - check http://xcon.xfocus.org/

greetz to drewcopley, drorshalev, zwell, liuyuer, lqa21, and, of course all@topsec



To be viewed with Google Chrome

Last tested
Wednesday, October 29, 2008 at 9:53:18 AM (time zone: UTC/GMT +8 hours)
Up-to-date Google Chrome (version:

Address spoofing.
1. Address is displayed "bbb.org".
2. Contents are not from bbb.org(contents are manipulated).


Google Chrome is still "virgin" - Right now only had a bunch of D.o.S, and, a buffer overrun if user saves the attacker's webpage.