MS Finds Security Flaw In Google Chrome Frame
Christmas Shopping writes with this excerpt from Kaspersky Labs' threatpost: "Back in September, when Google launched the Google Chome Frame plug-in for Internet Explorer users, Microsoft immediately warned that the move would increase the attack surface and make IE users less secure. Now comes word that a security researcher in the Microsoft Vulnerability Research (MSVR) has discovered a 'high risk' security vulnerability that could allow an attacker to bypass cross-origin protections."
"Google has hurried out a patch," he adds.
MS Finds Security Flaw In Google Chrome Frame
Timothy, you owe me a new Transformers t-shirt. I just spat coffee all over myself.
I am willing to bet good money that Microsoft formed a team responsible for finding bugs in Google frame just to discredit them.
It may be 7 digits, but at least it's a semiprime
And not wait another week until it's patch-Tuesday.
Not a good day for google...first a OS that can only run web apps...completely rejected by the community...& now this...
MS has security researchers ?
Don't they have anything better to do than nitpick with an addon that 0.001% of the user base has ?
Come on !
The Cloud - because you don't care if your apps and data are up in the air.
Internet Explorer less secure? This is really possible?
Religion: The greatest weapon of mass destruction of all time
MS is VERY good at finding security flaws, in everyone else's products. It is their own products they completely overlook.
And this story once again proves that MS could improve its public image instantly with one simple statement. SILENCE. MS, really, hire a lawyer as your public relations advisor. A good lawyer who always tells his clients to "SHUT THE FUCK UP".
I had just about forgotten about all the bugs in MS software... and this made me remember the entire long list of highly exploitable bugs unpatched for months or even years. Great job.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
Anything that helps this product improve ultimately helps that adoption of HTML5. Thank you, Microsoft! ;)
Now, can you please fix the sanitiser in the IE8 output encoding?
So quick to point out mistakes in others software, but so slow to fix your own.
Finally had enough. Come see us over at https://soylentnews.org/
Google makes IE less secure, users switch to real Chrome, google (somehow) profits!
... the ``glass house'' security team. Stones complimentary from the house.
they can see the wood for the trees
who didn't see this coming? :)
Does MSIE suffer from this exploit?
In its attempt to make google look bad and to discourage usage of the plugin, Microsoft looks at it with great scrunity, possibly examining it in greater detail than their own software.
This is a good thing because it means that more errors are found more quickly and solved more timely.
At the same time, the error sounds less severe than what's in IE right from the start anyway...
The Chrome Frame was never a good idea for security. By making it opt-in for sites, like an other plugin, it dramatically increased the attack surface of IE. Now any attacker can exploit holes in IE, holes in the frame, or holes coming from the interactions between the two. If you want the features of the Chrome Frame in a more secure package, use Chrome.
I am TheRaven on Soylent News
About damn time MS found a flaw in it's own software.
Not only does this unholy merge of browsers increase the surface area for attack (though the idea of someone from Microsoft complaining about that is highly ironic), but like other Google software it brings in the Google updater.
For example, FTA: "All users should be updated automatically,"
Google updater allows a web page to push an update on you without any notification. I don't know what the security restrictions on that are, but I can't see what advantage that has over providing a separate update program that would justify the risks.
Google seems to be in the same state of denial about secure design that Microsoft was in in 1997. Let's hope they catch on... Microsoft really never has recovered from that era.
Once we end all of this open standards silliness, and get you to do your internet business with safe, secure ActiveX and .Net, security woes will be a thing of the past!
We have early word that the security vulnerability goes by the name "Internet Explorer". Details are thin at this time, but we'll have more as the story develops. Janet, back to you in the studio.
So Microsoft found a security problem in another company's software? Damn... maybe 2012 *is* real! The end is nigh!
Scientia est Potentia
If only MS would be so proactive on their own stuff.
I hadn't the slightest objection to his spending his time planning massacres for the bourgeoisie... (P.G. Wodehouse)
Microsoft didn't make any noise about this at all. The only reason you know MS discovered it was because google credited them in the update. So what exactly would shutting up do? Would you prefer them not to have told google at all perhaps?
The search technology company has shipped a new version of the Google Chrome Frame (version 4.0.245.1) with a patch for the vulnerability.
Case closed.
Makes you wish IE flaws were so short-lived.
I am putting myself to the fullest possible use, which is all I can think that any conscious entity can ever hope to do.
"...a security researcher in the Microsoft Vulnerability Research"
Well at least they realise that Chrome is a vulnerability to Microsoft. Sadly for them, I doubt this announcement will stop the profit leak.
about removing the log from your own eye before removing the mote from your neighbours eye.
http://www.coolforsale.com/ Christmas is around the corner: And old customers can also enjoy the gifts sent by my company in a can also request to our company. Gifts lot,Buy more get the moreOnly this site have this treatmentOur goal is "Best quality, Best reputation , Best services". Your satisfaction is our main pursue. You can find the best products from us, meeting your different needs. Ladies and Gentlemen weicome to my coolforsale.com.Here,there are the most fashion products . Pass by but don't miss it.Select your favorite clothing! Welcome to come next time ! Thank you! http://www.coolforsale.com/productlist.asp?id=s76 (Tracksuit w) ugg boot,POLO hoody,Jacket, Air jordan(1-24)shoes $33 Nike shox(R4,NZ,OZ,TL1,TL2,TL3) $35 Handbags(Coach lv fendi d&g) $35 Tshirts (Polo ,ed hardy,lacoste) $16
free shipping
competitive price
any size available
accept the paypal
Thanks
Why can't vendors implement their own Patch Tuesdays? That is, Microsoft would release patches any time, and large vendors would simply allow them to accrue until their internal "Patch Tuesday" came around, at which time they'd test and apply the patches.
The vulnerability that the patch fixes is often disclosed along with the patch. So by the time the vulnerability becomes public, the script kiddies are likely already exploiting the vulnerability against targets with their own patch schedules.
that MS cannot find bugs in their products if they spend all the time looking for vulnerabilities in competitors products.
You can tell WSUS to queue up and wait for approval before rolling any patches out -- the rest of us can get our patches when they're ready.
body massage!
coolforsale.com chinese sweatshop spam scam illegal copies
(Join the campaign to trash this asshole, get Google to associate his site with everything that is bad about the web).
What's "chome"? "Back in September, when Google launched the Google Chome Frame plug-in for Internet Explorer users..."
http://threatpost.com/en_us/blogs/microsoft-finds-security-flaw-google-chrome-frame-111909
original post
I wonder how much time & money they invested in finding a google bug than their own software?
My guess is more than the entire budget allowed for IE6.
... Microsoft security researcher confirms advantages of open source transparency
http://www.coolforsale.com/ Christmas is around the corner: And old customers can also enjoy the gifts sent by my company in a can also request to our company. Gifts lot,Buy more get the moreOnly this site have this treatmentOur goal is "Best quality, Best reputation , Best services". Your satisfaction is our main pursue. You can find the best products from us, meeting your different needs. Ladies and Gentlemen weicome to my coolforsale.com.Here,there are the most fashion products . Pass by but don't miss it.Select your favorite clothing! Welcome to come next time ! Thank you! http://www.coolforsale.com/productlist.asp?id=s76 [coolforsale.com] (Tracksuit w) ugg boot,POLO hoody,Jacket, Air jordan(1-24)shoes $33 Nike shox(R4,NZ,OZ,TL1,TL2,TL3) $35 Handbags(Coach lv fendi d&g) $35 Tshirts (Polo ,ed hardy,lacoste) $16 free shipping competitive price any size available accept the paypal Thanks
Perhaps MS should be more concerned about their own protocols.
"Most secure Os ever;
What ever your firewall is set to, you can get remotly smashed via IE or even via some broadcasting nbns tricks (no user interaction)
How funny."
http://g-laurent.blogspot.com/2009/11/windows-7-server-2008r2-remote-kernel.html
This is nothing new, M$ always blames others for their own crappy, insecure software. It is M$ that cals bugs "features" in M$ Windoze and all of M$'s software. Then M$ places the blame the their own addicts for the short fallings of M$ software. Shit, M$ has even blamed distributers of non-free software as well as free software distributers for all problems in M$ Windoze. So it should come as no surprise M$ is now blaming Google especially after $weatyB has threatened to fucking kill Google.
--
Friends don't help friends install M$ junk.
Friends do assist M$ addicted friends in committing suicide.
More likely, someone at a management meeting said "What does this mean to us?" and no one had an answer, so someone with that responsibility said "I'll form a team to go look at it." He got together with his highly paid coworkers over a 3 hour power lunch with martinis and found someone who wouldn't blink during the "I don't have funding or responsibility in this area" game, and assigned the investigation to them.
This person asked his team to conduct a technical review of the implementation, and in the process the team found a potential security risk.
That sounds more like big business operation to me, from a fortune <15 employee. Microsoft was #44 in 2008, so probably operates like big business.
Less likely is "Let's spend money on highly paid technical folks looking for ways to make a headline people will forget in a week." Possible, but less likely.
I'm sure more in Chrome will appear in upcoming months. But MS is hardly blameless in criticising another another company's security.
In the long runt his constant bitching will make both products stronger.
In Soviet Russia, Microsoft finds your bugs!
Seems to me that some computer desktops are starting to be a corporate warzone.
In other words: *All your desktop are belong to us*
Absolutely true. As a web-developer, let me clue you (the grandparent) in... ASP is a server side programming language used to create HTML based web pages on the fly. It is exactly the same kind of technology as PHP... it's on the server and, and the client has no knowledge of it. All it gets is HTML, and it doesn't care whether it was static or created by PHP or ASP on the fly.
And just to add to the chorus, I have viewed many a webpage that was generated by ASP using firefox.
Beware of bugs in the above code; I have only proved it correct, not tried it.
How did MS communicate the bug to Google? .vs. patch
race.
Were they polite and inform Google so that the issue could be addressed in a timely update or was it communicated in a public way enabling hackers to race google in an exploit
Truth is stranger than fiction, but it is because Fiction is obliged to stick to possibilities; Truth isn't. Mark Twain.