Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-05 Thread hannibal
n3td3v wrote: On Thu, Sep 4, 2008 at 5:46 PM, Chris Pritchard [EMAIL PROTECTED] wrote: I don't think it's your list, and even if it was, you didn't have to be so rude about it Its Gadi Evron's list because Mossad told him to make it so. Who's really in control of the propaganda

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-05 Thread M . B . Jr .
Sent: Tuesday, September 02, 2008 7:51 PM To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] Google Chrome Browser Vulnerability Hi, --- Software: Google Chrome Browser 0.2.149.27 Tested: Windows XP Professional SP3

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-05 Thread n3td3v
On Fri, Sep 5, 2008 at 8:10 PM, hannibal [EMAIL PROTECTED] wrote: We all know that Evron is a moronic jew, who cares? How should the community deal with Gadi Evron emails? Should we be shooting for a complete ban of cyber politics as well as normal politics which is already banned? If people

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-04 Thread Juha-Matti Laurio
@lists.grok.org.uk Subject: [Full-disclosure] Google Chrome Browser Vulnerability Hi, --- Software: Google Chrome Browser 0.2.149.27 Tested: Windows XP Professional SP3 Result: Google Chrome Crashes with All Tabs Problem: An issue

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-04 Thread Fionnbharr
] Google Chrome Browser Vulnerability Hi, --- Software: Google Chrome Browser 0.2.149.27 Tested: Windows XP Professional SP3 Result: Google Chrome Crashes with All Tabs Problem: An issue exists in how chrome behaves with undefined

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-04 Thread Chris Pritchard
Subject: Re: [Full-disclosure] Google Chrome Browser Vulnerability dear god people, I've got null ptr derefs in firefox but I don't make full disclosure posts about them. I care about them nearly as much as vulnz in a browser no one uses for more than 5 minutes. Get the fuck off my list. 2008/9/4

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-04 Thread The Mad Hatter
On Thursday 04 September 2008 13:46:33 Chris Pritchard wrote: I don't think it's your list, and even if it was, you didn't have to be so rude about it I -- as well as many others in the list I'm sure -- have given up on this thread. As usual, its popularity is propotional to how much it

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-04 Thread n3td3v
On Thu, Sep 4, 2008 at 5:46 PM, Chris Pritchard [EMAIL PROTECTED] wrote: I don't think it's your list, and even if it was, you didn't have to be so rude about it Its Gadi Evron's list because Mossad told him to make it so. Who's really in control of the propaganda on this mailing list, Gadi

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Andrew Farmer
On 02 Sep 08, at 21:48, Paul Ferguson wrote: - -- James Matthews [EMAIL PROTECTED] wrote: The same thing happened to safari when it came out on windows. Well, no kidding. :-) Maybe the flaws that will hound Chrome are due to the fact that it uses Safari as a codebase? WebKit != Safari.

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Andrew Farmer [EMAIL PROTECTED] wrote: On 02 Sep 08, at 21:48, Paul Ferguson wrote: - -- James Matthews [EMAIL PROTECTED] wrote: The same thing happened to safari when it came out on windows. Well, no kidding. :-) Maybe the flaws that will

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread silky
On Wed, Sep 3, 2008 at 5:37 PM, Paul Ferguson [EMAIL PROTECTED] wrote: Okay, well you cannot deny this is a lackluster starting point. I hope Google can use this inauspicious starting point to build the advertising empire they desire. I for one do not welcome the advertisement overlords.

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread n3td3v
On Wed, Sep 3, 2008 at 8:52 AM, silky [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 5:37 PM, Paul Ferguson [EMAIL PROTECTED] wrote: Okay, well you cannot deny this is a lackluster starting point. I hope Google can use this inauspicious starting point to build the advertising empire they

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Urlan
PT: FODA-SE! 1) Perdao, mas eu nao vi em nenhum lugar voce ajudando em coisa alguma. 2) Eu falo e escrevo em portugues, estou no Brasil. Obrigado mas eu nao quero postar coisas em ingles para quem quer que seja ler. Urlan On Wed, Sep 3, 2008 at 12:18 AM, The Mad Hatter [EMAIL PROTECTED] wrote:

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Anders Klixbull
shut the fuck up From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Urlan Sent: 3. september 2008 14:37 To: The Mad Hatter Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Google Chrome Browser Vulnerability PT: FODA-SE! 1

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Urlan
Sorry for my mistake. Urlan 2008/9/3 Fabio N Sarmento [ Gmail ] [EMAIL PROTECTED] So what fuck are you doing here? This list speak english, if you dont want to, get out. 2008/9/3 Urlan [EMAIL PROTECTED] PT: FODA-SE! 1) Perdao, mas eu nao vi em nenhum lugar voce ajudando em coisa alguma.

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Fabio N Sarmento [ Gmail ]
So what fuck are you doing here? This list speak english, if you dont want to, get out. 2008/9/3 Urlan [EMAIL PROTECTED] PT: FODA-SE! 1) Perdao, mas eu nao vi em nenhum lugar voce ajudando em coisa alguma. 2) Eu falo e escrevo em portugues, estou no Brasil. Obrigado mas eu nao quero postar

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Valdis . Kletnieks
On Wed, 03 Sep 2008 10:04:43 BST, n3td3v said: I think the world's biggest hacker HD Moore HD is incredibly talented, and deserves a round of applause for Metasploit. However, a minute's thought will show that we don't have a fucking *clue* who the world's biggest hacker is. We have plenty of

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Razi Shaban
On 9/3/08, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: ... I'd place bets that whoever it is, they're on the RBN payroll... ... If they really were the biggest hacker, why on earth would they work for a large group that would merely dull their shine and take from their profits, etc. No, the

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread n3td3v
On Wed, Sep 3, 2008 at 5:06 PM, [EMAIL PROTECTED] wrote: I'd place bets that whoever it is, they're on the RBN payroll... I thought a high ranking security professional like yourself would stick to facts, not the latest disinformation handed out by so-called trusted security professionals.

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread redb0ne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Wed, 03 Sep 2008 14:47:22 -0400 n3td3v [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 5:06 PM, [EMAIL PROTECTED] wrote: I'd place bets that whoever it is, they're on the RBN payroll... I thought a high ranking security professional like

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Rishi Narang
PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rishi Narang Sent: Tuesday, September 02, 2008 7:51 PM To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] Google Chrome Browser Vulnerability Hi, --- Software: Google Chrome Browser

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread n3td3v
On Wed, Sep 3, 2008 at 8:01 PM, [EMAIL PROTECTED] wrote: On Wed, 03 Sep 2008 14:47:22 -0400 n3td3v [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 5:06 PM, [EMAIL PROTECTED] wrote: I'd place bets that whoever it is, they're on the RBN payroll... I thought a high ranking security

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread redb0ne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Even though I had the vulnerability 4 hrs well before the real publication of the bug and had the exploit along with the some crash details like int 3 Kernel Exception/Trap @ 0x01002FF3, different attack cases, exceptions of http/ftp and further

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Shyaam
This is an out of bounds memory read that crashes the browser. It is a major exaggeration to call this a vulnerability, especially considering this is a beta browser. Not that others haven't already said it, but people never seem to learn that a browser crash is a stability issue, not a

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread redb0ne
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 My judgment is telling me to just ignore this, but I'll entertain it with one response. On Wed, 03 Sep 2008 20:04:34 -0400 Shyaam [EMAIL PROTECTED] wrote: This is a healthy discussion. This topic leads to a very good question. When do we call a bug

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread Shyaam
Out of bound array accesses can be vulnerabilities because they can in some cases result in code execution, but not in this case. In this case, it is just an integer underflow that causes a conditional to evaluate to true that shouldn't have and a byte or two of memory being read out of

[Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Rishi Narang
Hi, --- Software: Google Chrome Browser 0.2.149.27 Tested: Windows XP Professional SP3 Result: Google Chrome Crashes with All Tabs Problem: An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread n3td3v
On Wed, Sep 3, 2008 at 12:50 AM, Rishi Narang [EMAIL PROTECTED] wrote: Proof of Concept: http://evilfingers.com/advisory/google_chrome_poc.php You didn't manage to jail break the entire browser, thats whats unique about Chrome, each tab is in jail, so the entire application doesn't crash. The

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Rishi Narang
PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rishi Narang Sent: Tuesday, September 02, 2008 7:51 PM To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] Google Chrome Browser Vulnerability Hi, --- Software: Google Chrome Browser

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread silky
On Wed, Sep 3, 2008 at 10:13 AM, Larry Seltzer [EMAIL PROTECTED] wrote: Holy crap, a crash bug in a beta browser! oh fuck off with referring to it as beta. beta is just a lame tag so you can release something that you don't entirely trust. imho if it's beta keep it fucking private. if it's

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread n3td3v
On Wed, Sep 3, 2008 at 1:28 AM, Rishi Narang [EMAIL PROTECTED] wrote: Hello Larry, Ya, a beta browser (though I forgot to mention it) but, is there any product from Google not in Beta ;) Thanks, our searches are not through a beta search engine. Anyways, it's just an attempt to make it a

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Jardel Weyrich
I'd recommend you to read http://en.wikipedia.org/wiki/Software_release_life_cycle#Beta On Tue, Sep 2, 2008 at 9:35 PM, silky [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 10:13 AM, Larry Seltzer [EMAIL PROTECTED] wrote: Holy crap, a crash bug in a beta browser! oh fuck off with

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread n3td3v
On Wed, Sep 3, 2008 at 1:58 AM, silky [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 10:55 AM, Jardel Weyrich [EMAIL PROTECTED] wrote: I'd recommend you to read http://en.wikipedia.org/wiki/Software_release_life_cycle#Beta i'd recommend you re-read my post, and even that link. beta does

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Giancarlo Razzolini
n3td3v escreveu: On Wed, Sep 3, 2008 at 1:58 AM, silky [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 10:55 AM, Jardel Weyrich [EMAIL PROTECTED] wrote: I'd recommend you to read http://en.wikipedia.org/wiki/Software_release_life_cycle#Beta i'd recommend you re-read my post,

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread n3td3v
On Wed, Sep 3, 2008 at 3:01 AM, Giancarlo Razzolini [EMAIL PROTECTED] wrote: Discover it by yourself. Aren't you the bad ass guy of security? I'm just a member of the public, unemployed and stupid... maybe you can help me be badass... although i'd rather be a goodass, cause being badass is

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Urlan
Por que todo esse alvoroço por causa de um bug na versão beta?! Viagem... Urlan On Tue, Sep 2, 2008 at 11:21 PM, n3td3v [EMAIL PROTECTED] wrote: On Wed, Sep 3, 2008 at 3:01 AM, Giancarlo Razzolini [EMAIL PROTECTED] wrote: Discover it by yourself. Aren't you the bad ass guy of security?

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread The Mad Hatter
On Tuesday 02 September 2008 23:28:33 Urlan wrote: Por que todo esse alvoroço por causa de um bug na versão beta?! pt: não seja tão imbecil en: don't be such a moron you are lame twice; first for posting in portuguese, then for giving a stupid negative contribution to the thread. if you don't

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread James Matthews
/ Contributing Editor, PC Magazine [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Rishi Narang Sent: Tuesday, September 02, 2008 7:51 PM To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] Google Chrome Browser

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- James Matthews [EMAIL PROTECTED] wrote: The same thing happened to safari when it came out on windows. Well, no kidding. :-) Maybe the flaws that will hound Chrome are due to the fact that it uses Safari as a codebase? See also: