返回   华枫论坛 > ◆ 工作学习◆ > IT交流



发表新主题 回复
 
只看楼主 主题工具
旧 Sep 15th, 2008, 16:45     #1
hardywang
在青麦地上跑着 / 雪和太阳的光芒
级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时级别:97 | 在线时长:9894小时 | 升级还需:102小时
 
hardywang 的头像
 
注册日期: Jul 2004
住址: Kilimanjaro
帖子: 9,428
积分:24
精华:16
hardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond reputehardywang has a reputation beyond repute
发送 ICQ 消息给 hardywang
默认 【转帖】据说Google Chrome的口令管理器也有问题

http://www.p2pnet.net/story/16889

Google Chrome security flaws
p2pnet news view Products | Security:- Ooops.

“Google Chrome’s password manager failed more tests than any other browser I’ve tried,” says Chapin Information Services’ Robert Chapin in a p2pnet Reader’s Write.

Now, “Google’s shiny new Web browser is vulnerable to a carpet-bombing vulnerability that could expose Windows users to malicious hacker attacks,” says ZDNet, going on:

“Just hours after the release of Google Chrome, researcher Aviv Raff discovered that he could combine two vulnerabilities - a flaw in Apple Safari (WebKit) and a Java bug discussed at this year’s Black Hat conference - to trick users into launching executables direct from the new browser.

“Raff has cooked up a harmless demo of the attack in action, showing how a Google Chrome users can be lured into downloading and launching a JAR (Java Archive) file that gets executed without warning.”

Raff’s proof-of-concept code shows how two mouse clicks are all that’s needed to plant malware on Windows desktops, says the story, also pointing out the user-agent shows Chrome is in fact WebKit 525.13 (Safari 3.1), an outdated/vulnerable version of that browser.

“Apple patched the carpet-bombing issue with Safari v3.1.2,” ZDNet says, adding some Windows Vista users are reporting downloaded files are, “automatically dropped on the desktop, setting up a scenario where a combo-attack using this unpatched IE flaw could be used in attacks”

Stay tuned.
帅哥 hardywang 当前离线  
回复时引用此帖
发表新主题 回复


发帖规则
不可以发表新主题
不可以发表回复
不可以上传附件
不可以编辑自己的帖子

启用 BB 代码
论坛启用 表情符号
论坛启用 [IMG] 代码
论坛禁用 HTML 代码



所有时间均为格林尼治时间 -4。现在的时间是 17:19

请尊重文章原创者,转帖请注明来源及原作者。
凡是本站用户自行发布的任何信息,皆不代表本站的立场,
华枫网站不确保各类信息的正确性和可靠性,也不承担由此而导致的任何直接或间接损失以及任何法律责任。

Copyright © 1999-2024 Chinasmile