Google Chrome Browser Cracked



web hosting

Vupen Security, a group specializing in vulnerability research, claims to have broken through the Google Chrome browser as well as the sandbox thus denting claims regarding the security of the browser. A video was recently released on Vupen’s website displaying the exploit from Google Chrome v11.0.696.65 using Microsoft Windows 7 SP1 (x64). The exploit is also effective on Google Chrome versions 11.x and 12.x

The Exploit

A user visiting the page is tricked into thinking they are at the correct web page that hosts the exploit which executes a variety of actions that end in downloading the Calculator from a remote location to externally launch it from Google Sandbox.

Technical Details

According to Vupen, the exact details of the breach including the code have not been publicly disclosed and will only be shared with their government customers to prove the effectiveness of their services. The exploit has been noted as one of the most sophisticated codes as it completely bypasses all security features such as ASLR/DEP/Sandbox.

Also, the vulnerability does not crash following the execution of the exploit and it relies on zero-day vulnerabilities found by Vupen Security while working within a Windows system. Chrome is said to be one of the most secure sandboxes in the industry. Vupen is the first to find a reliable method of executing code on a default installation regardless of the security measures.

Chrome Security Features

Chrome was developed with advanced security technologies like Safe Browsing, auto updates and sandboxing to protect its users from malicious activities. Therefore, the browser shows the user a warning message before they visit the website. Meanwhile, the sandbox feature adds protection by eliminating web pages that leave malicious programs on a local computer while monitoring web activities.

The Vupen Team

Furthermore, the software analyzes and patches known flaws and other vulnerabilities. The Vupen Security team is dedicated to uncovering new vulnerabilities across widely used software to assist vendors with the elimination of vulnerabilities resulting in an airtight software program. However, since Vupen is under contract with the vendor, they are never allowed to release the exact technical details found with the security exploit.

Although it was difficult, cracking the Google Chrome web browser will significantly help the company improve security to make it almost impossible for any hacker to develop an exploit. In this situation, Vupen has definitely done their job well by helping the largest search engine company in the world.

Tags: , , , , ,

Protecting Your Site from DDoS Attacks

web hosting

Web hosting security is an extremely complex technical field, as it is constantly evolving. Every time someone finds an exploit or a security loophole, the web hosting company has to counteract that action with a security measure. Thus, what is true this...

Jun 16th, 2010 Read more

Healthy Website Security Practices

web hosting

Perhaps the most important aspect of operating an online business is keeping your investments secure at all times. The internet is a very dangerous place, especially for business that conduct hundreds or thousands of dollars in eCommerce each and every...

May 5th, 2010 Read more

Use Captcha To Keep Spammers At Bay

web hosting

One of the first and most annoying things that can happen to a new web site owner is being blasted with spam.  There is a dilemma presented when wanting to have potential customers or clients contact you or your company.  Either your email has to be...

Nov 6th, 2009 Read more

Web Hosting Security at Risk: Are you?

web hosting

It seems as if new web hosting companies are emerging on the scene everyday and almost all of them are trying to ease the rising fears of security breaches.  The efforts and reassurance are warranted when considering that any website is vulnerable to...

May 26th, 2009 Read more

Protect Your Site From Maliciously Activities

web hosting

Thousands of vulnerable websites are exploited everyday.  In many cases, your site can be victimized without you having the slightest clue.  Unfortunately, there are also instances in which your site can be used in malicious ploys without being directly...

May 7th, 2009 Read more

Cross Site Scripting: The Underestimated Website Attack

web hosting

Cross site scripting or simply XSS, is one of most common threats facing website owners today.  This exploit occurs at the application layer, usually targeting scripts embedded in a web page from a client-side browser rather than the server-side.  In...

Apr 9th, 2009 Read more

Fighting Back Against Website Attacks

web hosting

Despite all the advancements that have been made in information security, hacking attacks continue to be a major problem, inflicting damage on some of the biggest companies.  Every year, it seems as if we hear a story where some major company has been...

Feb 19th, 2009 Read more

Stay in Touch with the Geeks

Our Community

Facebook
2274 Fans
Twitter
1422 Followers
FeedBurner
60 Subscribers

Submit News

Do you have an exciting story and want the world to hear it?

Submit a Story

  • 15K monthly visitors
  • PageRank 6
  • Alexa 11,000