Bugtraq mailing list archives

Re: Google Chrome Automatic File Download


From: Juha-Matti Laurio <juha-matti.laurio () netti fi>
Date: Thu, 4 Sep 2008 13:53:51 +0300 (EEST)

This issue was assigned to BID31000:
http://www.securityfocus.com/bid/31000

Juha-Matti

Razi Shaban [razishaban () gmail com] wrote:
On 2 Sep 2008 22:58:27 -0000, nerex () live com <nerex () live com> wrote:
> Google's Chrome (BETA) allows files (e.g. executable files) to be automatically downloaded to the user's computer 
without any user prompt.
>
>  To check the flaw, open a URL that points to an executable file.
>
>  nerex
>

There's a huge difference between downloading and running. If a file
that is unwanted is auto-downloaded, just delete it. No harm done.


--
Razi



Current thread: