Google Chrome Hacked?
vupen.com
vupen.com
---
Hi everyone,
We are (un)happy to announce that we have officially Pwnd Google Chrome and its sandbox.
The exploit shown in this video is one of the most sophisticated codes we have seen and created so far as it bypasses all security features including ASLR/DEP/Sandbox, it is silent (no crash after executing the payload), it relies on undisclosed (0day) vulnerabilities discovered by VUPEN and it works on all Windows systems (32-bit and x64).
The video shows the exploit in action with Google Chrome v11.0.696.65 on Microsoft Windows 7 SP1 (x64). The user is tricked into visiting a specially crafted web page hosting the exploit which will execute various payloads to ultimately download the Calculator from a remote location and launch it outside the sandbox at Medium integrity level. Note: The Calculator is used here as an example, it can be replaced by any other payload.
While Chrome has one of the most secure sandboxes and has always survived the Pwn2Own contest during the last three years, we have now uncovered a reliable way to execute arbitrary code on any installation of Chrome despite its sandbox, ASLR and DEP.
This code and the technical details of the underlying vulnerabilities will not be publicly disclosed. They are shared exclusively with our Government customers as part of our vulnerability research services.
The video in question is http://www.youtube.com/watch?feature=player_embedded&v=c...
I both love and hate them. They are extremely talented and find absolutely awesome bugs that are hard to discover without a lot of work, and I hate them because they don't disclose their work unless it is for money. While I can understand that they have to make a living too, it just feels wrong to not protect everyone in the world when possible.
The net result is probably safer software for all.
Did the .gov pwn TPB and put their exploit up there?
Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack
I suppose it depends on the point of view, but having it exclusively in the hands of governments can easily mean it's limited to criminals who keep it secret and hack.
Why would a entity as big as "the government" would invest in breaking one browser used by a minority (~10%) of users in the web? Wouldn't it be much easier to just compromise their Internet connections?
I don't think that follows. Clearly there are folks in some governments who would fund finding zero day exploits so that they can use them to conduct cyber-warfare operations. Stuxnet comes to mind and the HBGary emails were telling in this regard. It seems there is a market for 0 day attacks that are not known to the manufacturer. So while Google would clearly give them $13,373 for the bug report but that is no doubt mouse nuts compared to what the someone would pay them while it's not in the 'known' state.
So I find Vupen's business model not unlike the business of creating munitions. No doubt profitable but not something I'd personally want to participate in.
It's pretty easy to argue that police only protect those who pay them.
If the police fail to respond to calls in the ghetto then the crime in the ghetto increases, for instance.
A big part of it was how the LAPD would only enforce laws in certain neighborhoods. The gangs were literally trained by the police that if they commit crimes on one side of a particular street, the laws will be enforced, but if they commit crimes on the ghetto side of the street, they will not be.
Sure they do, they discourage crime by finding and jailing criminals. Prevention is protection.
http://www.vupen.com/english/services/
"offensive security", yep. The guys are dirty like the Gary. Why a racket and government always means a happy marriage?
To profit? I believe most people would get into bed with the government if offered the correct incentives. I probably would, too. It's unfortunate, but that's how things work. Is it immoral not to relax your morals to, e.g., secure a better life for yourself and your family?
(Apologies for being meta, but I've recently begun studying morality/ethics so I'm exploring ideas for which I currently do not have answers. Suggestions/directions are appreciated.)
http://www.amazon.com/Lifes-Philosophy-Reason-Feeling-Deeper... http://en.wikipedia.org/wiki/Arne_N%C3%A6ss
relaxing more standards on par to being incompetent. only a little more damaging.
!)(@#*$!# cellphone keyboard.
They're an actual security company.
Hell, they don't even provide prices on their website, you can request quotes.
According to Wikipedia it is technically not extortion because the obtained information that is of value to google is not obtained "unlawfully" and doesn't seem to fall under the category "money, property or services". There seem to be some similarities though.
Erm... it's a traditional business model of security firms on the internets...
> If a security firm can "extort" google, what stops a lone hacker to put up a video of a chrome exploit on youtube and demand some arbitrary amount of money as compensation?
They're not extorting anything. They're not menacing google or anything like that, they have not obtained this information illegally, they've done security research and are releasing their findings to their clients because that's how they make their money. That's it.
These things should not in my opinion be disclosed to (the idiot skript kiddie segment of) the public before the vendors have been given a good long window to fix them.
I prefer what VUPEN does when compared to irresponsible discoveries by black hats who do not give a shit about the integrity of the installed product and privacy / safety / security of how many millions of users, who can then be screwed over by every skript kiddie and his dog because they released the info straight to the public.
Sure, if the vendor has absolutely ignored you and your loud demos of the bug, and won't respond to threats to release, you might release the exploit to a small segment of the IRREPROACHABLE VANILLA WHITE HAT security community with the intention that they might help persuade the vendor to take it seriously. That's about as far as I'd want go with releasing serious exploits. Although of course grey/black hat stuff is fun - look, mum, I have a cool exploit!
If VUPEN are sworn to secrecy by their Government customer, and cannot tell the vendor or help them fix the bug, maybe it's time to get a new Government and public service. Your Government (US arrogances with a captial G) is trying to pwn you and spy on you. Fuck that, the government should answer to the will of the people (and don't talk to me about the farce we call democratic election. Democracy is where (almost) all the people are deeply involved in determining policy, it's more like the ideal soviet system, really, which was not realized AFAIK.)
Anyway, isn't that why you're carting guns around all these years, in case your (US) Government turns nasty and starts pwning your ass up down right and left with a canoe? (Not that it wasn't already.) Yes indeed, guns!! However let it not be said that I am inciting violent revolution with this sarcastic post, as I don't believe in or wish to promote that or any violent act.
Poor Google, not enough money. LOL!
Sadly we can't verify that in this case. Because you know, we're not the CIA.
I would have thought if they really had a US govt / CIA / military / espionage customer, said customer would NOT want them to reveal ANYTHING about the exploit to Google nor the public, especially not its existance. So, they told us that there is an exploit, and now it's top hax0r news, might likely feature in mainstream news. Most sensible people will most likely hear of it, and will disable flash / plugins in chrome until someone fixes it. Any worthy target for netspionage with any money and brain will hear about it immediately, and quit using chrome for lynx, dillo, or something even simpler.
Anyone who uses such a large app as a modern over-engineered web HTML5 bugzilla-feeding browser is kissing security goodbye forever. GNU ls(1) may have security bugs FFS, do you think your browser doens't? Do they include Chrome or Firefox in the 'pretty secure' OpenBSD base install? No, no, they do not nor never will do this, although it is a most popular app!! (also because nearly all *BSD boxes become servers, but you get my drift.) Even if Chrome were regarded as an essential system service for every box to run, they would NOT include it! better the system grind to a halt by itself without yielding access.
Google will redouble Chrome's general security and sandbox security in a push-patch, and this will most likely break the hack. Or they will rediscover it. LOL at your short-lived hack, your Government _will_ be pleased that you disrespected their payment and trust, boasting about it everywhere, putting Google and their targets on red-alert.
The 'secret black ops' part of Government would not only be displeased, they would kick their ass so damn hard for revealing that there is an exploit, that they would not be able to discover more exploits for years due to severe ass damage pain.
They pay you to learn stuff so we can do espionage or whatever fuckdoggery they might be intending at poor Arab countries to steal their oil, or suchlike... Then this silly idiot hacker company posts 'woohoo we found an exploit, look at us: but we can't tell you how it works - 'tis just for our pals in the govt'. Then the presumably nasty branch of govt gets out the concrete mixer and applies the concrete slippers - national borders not being much of an obstacle - then tosses the talkative hackers into the middle of the pacific trench (there's deep water there). They are then eaten by those nasty deep-sea fish with big teeth, and lights on stalks to freak us out.
So anyway, this 'half-secret hack' business reeks deeply of bullshit to me.
For some real bullshit, forget everything else I said. Windows is the utter pinnacle of bullshit for security, full stop. I understand that certain few idiots among the population do use it for playing games, and watching porn, and trying to be hackers, and in offices, but seriously: if you use Windows, any edition of Windows, for your own security, you obviously have not a clue nor give a real fuck about your security at all. Your password is probably 'dog' or 'cat'. OS X and Linux are barely any better for security.
If you want real security, throw away all the public and commodity crap operating systems and build your own. Or pay someone smart to build it. If it takes you less than 5 years to debug it before deployment, or it's more than 100KB of code in total size, I guess you failed: it's not secure. I'll give you a hint. Every process in the system should have access to precisely nothing by default. Not even the CPU, not even the time of day. Every single resource that is needed must be introduced to the process's environment by a neighbor or parent process (if possible, and in most cases it should not be). The entire system, especially process / resource structure, privilege and connection must be visible as a nested, nodes-and-arcs graph, for the user / sysop to verify and check what the hell is going on in it. If there's no link from Chrome to your printer, and you've disabled changes to that part of the process structure, Chrome will not ever print anything unless there's a solar storm - or similar stimulus - that miraculously alters everything without crashing it. You ANTICIPATED THAT UNLIKELY EVENT, and made 3 or 4 systems running everying exactly the same, in parallel, in sync at each step. If one screws up due to solar fuckdoggery, throw it in the bin and swap in another (like RAID). They do this shit in planes I believe, not the swap in bit, until it lands. The solar demons won't miraculously pseudo-break them all at once in the SAME WAY.
Windows, Microsoft, Security - can you spot the odd one out? Can you see a juxtaposition here folks? Can you feel it? A disturbance ripples through the force, out through the local cluster (of galaxies) and back, because those three words were collected together in one place.
No amount of ill-acquired M$ money spent on Windoze security enhancements can break their appallingly bad track record for security holes, loss of privacy, and the happy virus cultivation ecosystems that Microsoft has consistently provided over the years with every version of Windows, almost from before viruses were invented. I think the first well-made and famous exploit came well before windows was conceived, I'd suggest Ken's cc hack. That's the first brilliant exploit I happen to know about - from the vendor himself, sly bastard. It's hard to believe he didn't go to jail for that, anyway, heh.
So yeah - VUPEN, Chrome, Windoze, haX0Rz working for the Big-G Government. LOL. Security Jokes all around. Chrome being the more respectable and secure among them in my opinion. And anyone who runs a nuclear reactor that depends for its stability or continued safe operation on a computer is a cow-tipping idiot too. Cars don't even. @stuxnet @.mil
Regardless, how they write is still offtopic.
And the vendor, I hope? Of course, we know HBGary was developing private exploits, but it wasn't exactly blogging about them.
> As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers.
Note also the "under contract with VUPEN" part of the disclosure bit.
Which countries? It does not specifically state US.
- Gov. and Law Enforcement Agencies in Countries Members or Partners of NATO, ANZUS or ASEAN
If you are interested in protecting your network, patches and workarounds are your first priority, not "proof of concept" exploits.
If you don't have access to the codebase (like a Safari or MSIE bug), then you pay VUPEN to disclose a firewall filter, or some other kind of deep packet inspection to disallow the code required to execute the vulnerability on your network. Again, pretty simple, in theory.
VUPEN plays a pretty tight game. The only way to get in on their action is money. You know this though, and I doubt our opinions differ on the matter. Unlike opensource, full-disclosure GitHub junkies, some people find enjoyment in financially benefiting on everything they stumble across. Just another side of the coin, and the argument about that topic is best left for other sites. :)
It makes it sound like if they crack your software, you only get disclosure if you are paying them money. However, I could be wrong.
“No, we did not alert Google as we only share our vulnerability research with our Government customers for defensive and offensive security,” Bekar wrote in response to an emailed request for comment. “Unfortunately, we are not aware of any mitigation to protect against these vulnerabilities.”
http://krebsonsecurity.com/2011/05/security-group-claims-to-...
Sounds to me like VUPEN is a cyberweapons dealer.
Edit: Then again, blogging about it also makes Google aware of the exploit. I'm sure they have tons of resources working on it that wouldn't have otherwise...
This is actually quite common in recent years for bug hunters and exploit developers. I can think of a dozen or so companies that do the same thing. Immunity is another example.
Trying to use a moral argument to get out of compensating someone when you have the resources to do so is shameful. Sorry, but this stuff is worth far more than the (up to) $3133 they are offering.
No More Free Bugs, as they say.
They can either pay a nominal fee for doing their security work for them, or they can hire some equally talented people and fund this type of research on their own internally. Fair is fair. There is no reason this isn't worth compensating but something like pagerank optimizations is.
What makes you think they don't already? You make it sound like Google doesn't give a shit about security. That clearly isn't the case.
That doesn't mean they're going to find everything, though.
At the end of the day, private companies are perfectly within their rights to do offensive research against Google products, to be selective about how they disclose their results, and to tell the public whatever they want about those results. As long as they aren't lying, there's nothing unethical about it.
Correction: not even well-paid Google employees did. They may yet be able, and an existence proof may be all the help they need to find and fix it. Don't give up hope yet.
I believe it'd be okay, and probably actually happens, for a private security consultant to do threat assessments for a (non-criminal) client, e.g. prepare a report for DHS on the security of U.S. oil installations. But it seems like they'd be crossing a line if they posted a press release trumpeting a major vulnerability they discovered, mentioning by name which company and approximately where the vulnerability was located, but then refused to disclose it to the company in question.
I'm not sure how much it survives, but I believe there was traditionally even a common-law "duty to warn" if you were aware of significant risks to someone's person or property.
The real reason your scenario is unlikely is just that Exxon practically owns the government, so they would change the laws or something to fuck you over.
But I mean what if you discovered a security vulnerability at McDonalds or something, a way to pick their locks. Why are you morally obligated to disclose it without compensation?
On which moral principle are you condemning them?
If you send a letter to a bank saying "I have found a breach in the kind of vault you use at your banks, I'm giving the details to some expert robbers but you can't have it unless you pay me $10m", with evidence you've done it, I'm pretty sure you will find yourself waking up at gunpoint at 6am, courtesy of the FBI.
Since unauthorised access of a computer is a crime in many places, I'm sure you can see the relevance, even if the consequences aren't as drastic. One hopes that we have misinterpreted this and that they have performed 'responsible disclosure' by telling Google all the details.
The 100% unhackable browser and OS... how much does it cost? I think the turnaround time is going to be infinite. I'm not sure what you're saying.
These companies have employees, who have a nice situation with a financial exchange of value. Let them do their own work. If I'm going to do something their employees should be doing, they're free to hire me or pay me as a consultant.
Think about the audacity of farmers, who make a profit for food, which you need to live. But nobody thinks like that for some reason.
Earning profit just means you've done something for someone who really wanted it done. It's a necessary signal.
> http://www.vupen.com/english/services/ > As the world leader in vulnerability research, VUPEN Security provides weaponized and highly sophisticated exploits specifically designed for Law Enforcement and Intelligence Agencies to help them achieve their offensive missions using tailored and unique codes created in-house by VUPEN for vulnerabilities discovered by our researchers. Note also the "under contract with VUPEN" part of the disclosure bit.
Process count in process explorer started with 5 and at the end of the demo, it looked like they have 8. That tells there are 2 extra processes that are created (discounting 1 for calc.exe).
I tried to see if pdf/flash creates new processes but I couldn't verify. Perhaps a chrome developer could get a clue about what is happening looking at the video.
Love the capital G.
Considering how non specific VUPEN are, I wouldn't be surprised if they're hiding this.
1) A remote code execution exploit in Chrome
2) A privilege elevation exploit allowing the hijacked browser process to break out of its mandatory access control jail
Number 1 is of necessity a bug in Chrome itself (or a plugin). Number 2 is probably a vulnerability in the Windows sandbox, but it could instead be that they found a way to successfully attack the small part of Chrome that runs outside low integrity mode. They weren't specific as to the details.
This is, again, at the very least a remote code execution hole in Chrome, and there's no fundamental reason Linux or OS X should be invulnerable to the same hole. That Chrome on Windows is less secure than on Linux or OS X would be the wrong thing to take from this; the point of this demo is that VUPEN accomplished the feat of bypassing all the security mechanisms protecting Chrome on Windows, whereas on the other platforms you have fewer of these mechanisms in the first place (no real ASLR on OS X, no Chrome sandboxing last time I checked on Linux).
They didn't say that the exploit didn't work on Mac or Linux, but one can only assume they tested those and weren't successful?
Or maybe not. I'm just saying, we can't assume either way.
But by all means, put on your tinfoil hats if that's more fun.
Google has/had the 'do no evil' in their philosophy, and disabling a scheme that misuses their software for cyber-warfare sounds like a good thing.
That still doesn't mean that it's not a chrome bug - the exploit may use flash to retrieve the payload, make use of flash-js communication, flash-chrome communication quirks etc.
It is not an accident that they hid Process Explorer after the exploit. They closed it before minimizing everything else intentionally. If you do not believe me follow the mouse pointer. The screencaster moved toward bringing Process Explorer top-level at 0:56 then realized it would show the entire thing and restored Chrome on top of it instead. With that in mind it is obvious that they do not want you to see what changed when it ran so instead we have to work with what is visible:
Process Explorer before: http://i.imgur.com/e31Rb.png
Process Explorer after: http://i.imgur.com/JfPTY.png
First item of interest is that Chrome shot up to over 400 MB of memory used which indicates that Flash is almost certainly involved.
Second, observe how long it takes for Calculator to start. Again, consistent with Flash being involved and Chrome delay-loading it.
Third, there are scroll bars on the tab. Big ones. This says there is an invisible item on the page taking up a lot of space which again points to Flash. I saved the exact same content to a file and look how small I can go without scroll bars: http://i.imgur.com/R0eqk.png
Fourth, flip back side by side through each photo and notice what disappears. The Windows search indexer disappears between screenshot A and B and this is what Vupen is intentionally covering up. You can still observe it indirectly based on the rows and colors at right. It is my understanding that the child processes of SearchIndexer.exe run at all times and not as some kind of cron but I do not use Windows so please correct me if I am wrong. At any rate they do disappear between A and B.
It would be very intelligent of them to blog post this as a Chrome sandbox bust (which is sort of newsworthy) and gain that link bait attention but, privately, use the exploit as the Flash and Windows vulnerability it most likely is.
Is this really the basis of your claim? A complete guess that a 400MB increase in memory must be due to a secret use of Flash?
The scroll bars on the tab are revealing, too. I may be guessing but it is an educated guess. Additionally, there were multiple claims so I would not call that specific data point a basis for a claim, singular.
> If you manage to make a single tab commit that much memory as a delta without Flash (remember, 13 MB to > 400 MB) please screenshot about:memory and get back to me.
I can understand this as a weak prediction, but it certainly doesn't work as a strong one. I can trivially make a tab use over a gigabyte of memory in recent Chromium by creating a gazillion nested objects in JavaScript. (I just did, in fact. If you really want the screenshot and/or source, say so and I'll post it somewhere.) Absent some default limit in V8 that I haven't encountered, I could presumably make it use unbounded memory. I can also create apparently-unbounded latency in a single tab's UI this way, by chewing up CPU in blocking JavaScript code, though this will eventually trigger the “page seems unresponsive” dialog box.
I would also tend to expect an exploit to potentially abuse the JavaScript engine by straining its limits, including things like pouring a large number of identical objects onto the heap to fill memory with exploitable patterns.
There is evidence that this is Flash. However, since everyone seems to want to attack individual parts of that evidence without applying Occam's Razor, I concede it could be something other than Flash. It could be Java, too. It could be a "standard browser exploit" too, whatever that is. Could be cosmic rays too.
The tendency to look for ways to prove me wrong with an alternate theory (which yours is) as opposed to acknowledging that multiple theories are possible with zero evidence aggravates me among technical people. In the absence of a disclosure we are both right.
Let's apply Occam's razor: a) There is no reason why Flash (or another plugin) needs to take up a large amount of space on the page. If I were to write a flash exploit, it'd be a 1x1 object with whatever ActionScript that triggers the vulnerability, no need for a large area. b) VUPEN is a bunch of extremely talented folks and I believe they have little to gain by posting a fabricated exploit video. c) The delay can also be caused by a rather advanced heap-grooming technique, it can be JS garbage collection invoked many times, it can literally be them trying the payload numerous times. Implying it's probably flash is just as speculative as we're being.
Relax man, no one's disagreeing with you to be an asshole, no one's trying to argue with you, we're all just speculating.
Actually, you can fix it, too: chromium is open source.
Good to see this tired claim getting its play in this thread. I wondered how long it would be until it showed up. I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.
I don't use Chrome or Windows, so I have almost negative personal interest in this story. However, some people probably do use Chrome and Windows, and those people's demands should be tempered by reality. If they didn't find this bug, why did they expect Google to?
I think everyone who says "go fix it, it's open-source" should instead be required to come back with a diff within 24 hours.
I think everyone should be required to give me a pony.
I love how you assert that literally anybody could check out Chromium and fix the sandbox, a sensitive security-essential part of the browser, with very little effort required to appreciate the source and all of the moving parts.
Not 100% sure, and I haven't tried it, but I suspect it would be possible using this bug: http://code.google.com/p/chromium/issues/detail?id=25047
Is this for a rollover, animation, or something else? (Mind posting a code snippet up somewhere?)
I have a hidden <img> tag and a <div>. In the timer callback I set the src= attribute of the <img> tag to the URI of the image plus the current time (e.g. "/image.png?v=123456789"), then in the <img> tag's onLoad I set the <div> tag's background-image style to the same value.
I was going to try using two <img> tags, and alternately hiding/showing them, but I doubt that will solve the caching issue. My current workaround is to keep the Chrome developer panel closed (which seems to store every resource loaded by a page regardless of any cache directives from the server) and have the page reload itself after 60 seconds of no user activity. Unfortunately, Chrome's memory usage still grows, only not quite as fast.
http://code.google.com/p/chromium/issues/detail?id=36142
It keeps getting punted. If you care, I recommend starring the issue.
So even if the exploit is using vulnerability in Flash, it still needs to escape the Flash sandbox in Chrome.
Chrome's historically performed extremely well in the competition, which is why it's notable they've actually found an exploit.
Considering the fact that they aren't going to publish the exploit, I just want to point out that this kind of thing could easily be fabricated. There are plenty of interests that benefit from unfortunate news about their competitors.