Scammers Bite Chrome Users With Forgotten 2014 Bug (betanews.com)
"Tech support scammers have started exploiting a two-year-old bug in Google Chrome to trick victims into believing their PC is infected with malware," reports security researcher Sophos. It begins by freezing the browser, BrianFagioli reports, sharing an article from Beta News:
These bad guys pose as Microsoft tech support and display an in-browser message that says the user's computer is infected with "Virus Trojan.worm! 055BCCAC9FEC". To make matters worse, Google has apparently known about the exploit for more than two years and simply failed to patch it. "The bug was discovered in Chrome 35 in July 2014 in the history.pushState() HTML5 function, a way of adding web pages into the session history without actually loading the page in question. The developer who reported the issue published code showing how to add so many items into Chrome's history list that the browser would effectively freeze", says Sophos...
"Users can either close Chrome using the Task Manager or, in cases where the browser is using up so much processor power that Task Manager doesn't appear, by rebooting the computer. The chances of encountering this particular scam are small -- it's only been spotted on a single website -- but its existence underlines how small bugs that don't seem terribly important may nevertheless be abused by cybercriminals down the line."
"Users can either close Chrome using the Task Manager or, in cases where the browser is using up so much processor power that Task Manager doesn't appear, by rebooting the computer. The chances of encountering this particular scam are small -- it's only been spotted on a single website -- but its existence underlines how small bugs that don't seem terribly important may nevertheless be abused by cybercriminals down the line."
Please take the time to be informed about the real perpetrators of the 9/11 attacks. Before you say that the attacks were over 15 years ago and don't matter, consider that they continue to define foreign policy and domestic surveillance to this day. What if everything you think you know about 9/11 is built upon lies? Surely that would be reason enough to reconsider continued support of domestic counterterrorism and foreign policy. You've been told that 9/11 was carried out by Muslim extremists, but the truth is that it was perpetrated by Jews who were operating under the command of Mossad.
In the days prior to 9/11, FBI agents in New York detained Mossad agents who were conducting surveillance of the World Trade Center towers. Agents at the New York City field office were instructed to release the Mossad agents they had detained, which occurred a few days prior to the attacks. Although the reasons for releasing the Mossad operatives remain classified, it is generally believed that Israel threatened to create an international incident if the operatives were not freed.
This was accompanied by unusual options trading of airline stocks in Jewish-led financial firms on Wall Street in the days leading up to 9/11, standing to profit from a sharp decline in the stock prices of United Airlines and American Airlines. No such options were purchased for the other airlines at the time. How could this possibly be explained without prior knowledge by Jews of the 9/11 attacks a few days later.
Although a few thousand Jews were employed at the World Trade Center, no Jews were killed in the 9/11 attacks. Instead, all of the Jewish employees used leave time or otherwise failed to show up for work on 9/11. Although far fewer Jews worked at the Pentagon, the same occurred there, with no Jews present at the site on 9/11. This cannot be explained through chance, but only advance knowledge shared with the Jewish workers at both places. Indeed, the same thing occurred at the United States Capitol, widely speculated as the destination of the fourth plane that crashed in Pennsylvania. Warnings about the attacks were announced in advance at synagogues in New York City and Washington, alerting Jews not to show up for work on 9/11, a fact corroborated by multiple rabbis.
Several of the purported 9/11 attackers are still alive, a fact that is widely confirmed by multiple sources. Therefore, the supposed Muslim attackers cannot be responsible for 9/11. However, east coast flight schools reported training several Israeli citizens prior to the attacks and instructors indicated that the pilots were uninterested in learning how to land. The money to pay for flying lessons was traced back through banks to Israeli-owned firms operating in the United States. Although the true origins of the laundered money cannot be confirmed, it certainly implies that Jews, quite possibly working for the Israeli government, funded the 9/11 attacks.
Voice recordings of the 9/11 attackers from the cell phone calls made by passengers on the four planes clearly indicate that the attackers had Israeli accents. Furthermore, they can be heard praying to Yahweh, not to Allah, again implicating Jews in the attacks. This is confirmed by the cockpit voice recorder recovered from the crashed plane in Pennsylvania.
FBI agents investigating the 9/11 attacks wrote reports implicating Mossad agents, reports that were subsequently modified with the original versions suppressed. This has been confirmed by retired FBI agents who worked at both the Washington headquarters and the New York field office.
There can no longer be any doubt that Jewish operatives were responsible for the 9/11 attacks. Those attacks were a false flag operation, funded and orchestrated by the Israeli government. Israel subsequently pressured the United States to cover up the Israeli involvement in 9/11. The attacks were both retaliation for attempts of the United States to improve relations with Arab nations in the Middle East while subsequently turning the United States aga
Yandex, their Russian competitor was pushing their Yandex Browser with these scamvertisements for years.
How many times you saw this on android? A popunder comes with "Delete viruz in 5..4..3..2..1." and then your phone hangs. If you click on it, it opens that Yandex browser in google market.
TRUMP TRUMP TRUMP!!!
Care to try to explain how all those links to kiddie-porn sites got on your computer in a courtroom?
How does it benefit the user to let websites push "visited" URLs into a browsers history? I expect my browser's history to only include sites I've actually visited.
when will people realize Google use things like that to steal information from users? Your Android for example. For god sake, they even have a troll departament on Google. Probably being paid by Hillary to conspire against Trump right now.
I work in tech support for a local managed service provider in a small city. We have several dozen business clients in the region (we don't handle private users). We are not a large operation by any measure. We get at least 2 calls a week about someone's computer having a virus that turns out to be this. Most of the time it seems to come from websites that are typo-squatting. If we are seeing that volume of complaints it can't be rare.
We use IE 8 so should be fine ... sheww
HTMl 5 is too scary right now
http://saveie6.com/
project somewhere dise4ses. The may do, may noT Asshole about.' One with THOUSANDS of see. The number
I normally browse using firefox with noscript and uMatrix, but occasionally when I want to view a video, I'll fire up Chrome and copy/paste the link there. Did that for an article at latimes.com two weeks ago and got served up some malware advertisement that did exactly this. I was impressed. You wouldn't expect that a reputable site like latimes.com would allow malvertizements, and you wouldn't expect that chrome would have an easily exploitable javascript vulnerability. Had to use process explorer to kill chrome.
"This is Windows calling, your computer have virus". Those a-holes just don't give up.
Like any good bug, it starts with a brain freeze.
Therefore it must be invulnerable to virus, malware and everything else!
Can this work for domains other than the one running the script? If so, this sounds pretty nasty, as not only could it be used for scammers, but to seed somebody's internet history with "bad" links. You want to incriminate somebody in viewing illegal images/downloads/etc, just seed their browser history.