<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Search results for 'app:weblogs' matching tags 'chrome' and 'Security'</title><link>http://msmvps.com/search/SearchResults.aspx?q=app:weblogs&amp;tag=chrome,Security&amp;orTags=0&amp;o=DateDescending</link><description>Search results for 'app:weblogs' matching tags 'chrome' and 'Security'</description><dc:language>en-US</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Security agencies rally against Google Chrome</title><link>/http://myitforum.com/cs2/blogs/rtrent/archive/2008/09/12/security-agencies-rally-against-google-chrome.aspx</link><pubDate>Fri, 12 Sep 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1647672</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5658&amp;amp;zoneid=71" href="http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5658&amp;amp;zoneid=71"&gt;http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5658&amp;amp;zoneid=71&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122340" width="1" height="1" alt="" /&gt;</description></item><item><title>Google updates beta browser</title><link>/http://myitforum.com/cs2/blogs/rtrent/archive/2008/09/09/google-updates-beta-browser.aspx</link><pubDate>Tue, 09 Sep 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1647259</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;Chrome gets an update to fix the Google developers’ security oversights…&lt;/p&gt;  &lt;p&gt;&lt;a title="http://googlechromereleases.blogspot.com/2008/09/beta-release-0214929.html" href="http://googlechromereleases.blogspot.com/2008/09/beta-release-0214929.html"&gt;http://googlechromereleases.blogspot.com/2008/09/beta-release-0214929.html&lt;/a&gt;&amp;#160;&lt;/p&gt;  &lt;p&gt;In the post they iterate how important it is that you keep their updater program on your computer.&amp;#160; Unfortunately, they don’t mention that you can only get rid of the updater program manually.&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;“Automatic updates are a key security feature in helping to ensure the safety of Google Chrome users.”&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Actually, I think uninstalling is probably the best security measure at this point.&amp;#160; Don’t run this browser on a production computer.&amp;#160; Of course, we all know that about beta products right?&amp;#160; I mean, you’re not running the Gmail beta (or any other Google beta) on your production computer, are you?&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122198" width="1" height="1" alt="" /&gt;</description></item><item><title>More goodness…Chrome installs outside of the Vista protected zone</title><link>/http://myitforum.com/cs2/blogs/rtrent/archive/2008/09/05/more-goodness-chrome-installs-outside-of-the-vista-protected-zone.aspx</link><pubDate>Fri, 05 Sep 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646910</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;&lt;a href="http://blog.noop.se/archive/2008/09/05/google-chrome-plays-outside-of-vista-security-zones.aspx"&gt;Google Chrome plays outside of Vista Security Zones&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122097" width="1" height="1" alt="" /&gt;</description></item><item><title>Chrome keeps track of your finances</title><link>/http://myitforum.com/cs2/blogs/rtrent/archive/2008/09/05/chrome-keeps-track-of-your-finances.aspx</link><pubDate>Fri, 05 Sep 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646878</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;With a few utterly simple keywords like balance, account and Sept., everything from balance information, account numbers and even how much you spent at Costco can be pulled up.&lt;/p&gt;  &lt;p&gt;&lt;a title="http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5599&amp;amp;zoneid=71" href="http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5599&amp;amp;zoneid=71"&gt;http://www.myitforum.com/absolutenm/templates/IndustryNews.aspx?articleid=5599&amp;amp;zoneid=71&lt;/a&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=122088" width="1" height="1" alt="" /&gt;</description></item><item><title>Google Chrome Crashes with All Tabs</title><link>/http://myitforum.com/cs2/blogs/rtrent/archive/2008/09/03/google-chrome-crashes-with-all-tabs.aspx</link><pubDate>Wed, 03 Sep 2008 05:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1646608</guid><dc:creator>Anonymous</dc:creator><description>&lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Software:     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Google Chrome Browser 0.2.149.27     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Tested:     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Windows XP Professional SP3     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Result:     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Google Chrome Crashes with All Tabs     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Problem:     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;An issue exists in how chrome behaves with undefined-handlers in chrome.dll version      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;0.2.149.27. A crash can result without user interaction. When a user is made to visit      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;a malicious link, which has an undefined handler followed by a &amp;#39;special&amp;#39; character,      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;the chrome crashes with a Google Chrome message window &amp;quot;Whoa! Google Chrome has crashed.      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Restart now?&amp;quot;. It lies in dealing with the POP EBP instruction when pointed out by the      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;EIP register at 0x01002FF4.     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;     &lt;p&gt;&amp;#160;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;Proof of Concept:     &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="font-family:&amp;#39;Courier New&amp;#39;;font-size:10pt;"&gt;&lt;a href="http://evilfingers.com/advisory/google_chrome_poc.php"&gt;http://evilfingers.com/advisory/google_chrome_poc.php&lt;/a&gt;      &lt;p&gt;&lt;/p&gt;   &lt;/span&gt;&lt;/p&gt;&lt;img src="http://myitforum.com/cs2/aggbug.aspx?PostID=121978" width="1" height="1" alt="" /&gt;</description></item></channel></rss>