首页
社区
课程
招聘
[讨论]Chrome沙箱宣告被攻破
发表于: 2011-5-10 21:19 2678

[讨论]Chrome沙箱宣告被攻破

2011-5-10 21:19
2678
新闻来源:vupen.com
来自法国的安全研究机构VUPEN宣称他们突破了chrome的沙箱保护,ASLR/DEP保护也一同被突破。突破利用 了未公布的漏洞,下面的视频向我们做了演示。只要访问特定构造的网页,用于演示的计算器就运行了。 VUPEN宣称漏洞代码将不会被公布,只会提供给他们的政府合作伙伴,所以我们并不清楚chrome的开发团队是否被通知漏洞信息。

官方声明:
http://www.vupen.com/demos/VUPEN_Pwning_Chrome.php

[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法

收藏
免费 0
支持
分享
最新回复 (3)
雪    币: 3171
活跃值: (76)
能力值: (RANK:250 )
在线值:
发帖
回帖
粉丝
2
厉害啊,支持一个 ,我还在纠结yuange的魔术师
2011-5-10 21:27
0
雪    币: 50
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
3
真的很惊讶啊
2011-5-10 22:18
0
雪    币: 171
活跃值: (10)
能力值: ( LV2,RANK:10 )
在线值:
发帖
回帖
粉丝
4
everyone,

We are (un)happy to announce that we have officially Pwned Google Chrome and its sandbox.

The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR/DEP/Sandbox (and without exploiting a Windows kernel vulnerability), it is silent (no crash after executing the payload), it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64).

The video shows the exploit in action with a default installation of Google Chrome v11.0.696.65 on Microsoft Windows 7 SP1 (x64). The user is tricked into visiting a specially crafted web page hosting the exploit which will execute various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox (at Medium integrity level).

While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any default installation of Chrome despite its sandbox, ASLR and DEP.

For security reasons, the exploit code and technical details of the underlying vulnerabilities will not be publicly disclosed. They are exclusively shared with our Government customers as part of our vulnerability research services.

Update: The exploit works on both Chrome versions 11.x and 12.x. It was also tested with Chrome v11.0.696.68 and v12.0.742.30.

还得谷歌翻译下!
2011-5-20 17:54
0
游客
登录 | 注册 方可回帖
返回
//