<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>eGuru &#187; Chrome</title>
	<atom:link href="http://eguru.info/tag/chrome/feed/" rel="self" type="application/rss+xml" />
	<link>http://eguru.info</link>
	<description>Modern business, books, travel, and technology</description>
	<lastBuildDate>Tue, 20 Jul 2010 11:06:12 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Memory exhaustion DoS vulnerability hits Google’s Chrome</title>
		<link>http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/</link>
		<comments>http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 10:28:17 +0000</pubDate>
		<dc:creator>Prithvi Mandava</dc:creator>
				<category><![CDATA[Google]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>

		<guid isPermaLink="false">http://eguru.info/?p=256</guid>
		<description><![CDATA[Aditya K Sood from the EvilFingers community, which disclosed the first Chrome DoS vulnerability at the beginning of the month, has released a proof of concept demonstrating a memory exhaustion DoS vulnerability affecting Google’s Chrome versions Chrome/0.2.149.30 and Chrome/0.2.149.29 : “The Google chrome browser is vulnerable to memory exhaustion based denial of service which can [...]]]></description>
			<content:encoded><![CDATA[<p>Aditya K Sood from the EvilFingers community, which disclosed <a href="http://blogs.zdnet.com/security/?p=1847">the first Chrome DoS vulnerability</a> at the beginning of the month, has released a <a href="http://www.evilfingers.com/advisory/Google_Chrome_Carriage_Return_Null_Object_Memory_Exhaustion_Remote_Dos_POC.html">proof of concept</a> demonstrating a <a href="http://www.evilfingers.com/advisory/Google_Chrome_Carriage_Return_Null_Object_Memory_Exhaustion_Remote_Dos.php">memory exhaustion DoS vulnerability affecting Google’s Chrome</a> versions Chrome/0.2.149.30 and Chrome/0.2.149.29 :<span id="more-256"></span></p>
<blockquote><p>“The Google chrome browser is vulnerable to memory exhaustion based denial of service which can be triggered remotely.The vulnerability triggers when Carriage Return(\r\n\r\n) is passed as an argument to window.open() function. It makes the Google Chrome to generate number of windows at the same time thereby leading to memory exhaustion. The behavior can be easily checked by looking at the task manager as with no time the memory usage rises high. The problem lies in the handling of object and its value returned by the javascript function. Once it is triggered the pop ups are started generating. The Google Chrome browser generate object windows continuously there by affecting memory of the resultant system. Probably it can be crashed within no time. User interaction is required in this.”</p></blockquote>
<p>What’s Google’s take on this flaw, and have they acknowledged it already? Zero Day asked the researchers.</p>
<p><strong>Q: This is the second DoS vulnerability that members from EvilFingers disclose. How is the second one different than the first one, and how would a remote attacker take advantage of it?</strong></p>
<p>A: Ideally, both are Denial of Service attacks. But second one is different for the matter that it does a memory exhaustion, or I would say “performance” peaks with the pop-ups. By default, all the pops are blocked by Chrome, but still the CPU usage jumps up to 98% and so does the memory consumption, therefore other processes will surely be affected. And then the PoC for the first one crashes the chrome right away without any reaction time to the user or any user way to prevent the loss of work. But with the second one, an experienced user can prevent the same and can save work of other tabs before resulting in a browser restart. Or put in another way, first one is a crash of all tabs, second one is a hang of tabs.</p>
<p><strong>Q: Since you’re responsibly disclosing the vulnerabilities that you find to Google, what is your opinion on their current response time and overall attitude towards the vulnerabilities that you’ve reported?</strong></p>
<p>A: Response time with the first one was well appreciable, as it was fixed within 24hrs though it took some days to roll out next 0.2.149.29 ‘patched’ version. For this newer DoS, the patch is yet to roll out and they have acknowledged the bug for now.</p>
<p>Has <a href="http://blogs.zdnet.com/security/?p=1847">Google’s Chrome level of exploitability</a> changed since the first DoS vulnerability? It may well be declining considering some recently published browser market-share statistics, clearly indicating that a lot of users seems to have given Chrome a try, and are back to their default browsers. According to <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9115341">published Chrome stats by Net Application</a> :</p>
<blockquote><p>“At the end of its third week of availability, Google Inc.’s Chrome accounted for 0.77% of the browsers that visited the 40,000 sites tracked by Net Applications, down from a 0.85% share the week before. “The trend line on Chrome still has a slight downward angle, and these weekly numbers reflect that,” said Vince Vizzaccaro, Net Applications’ executive vice president of marketing. Although Chrome popped above 1% within hours of its release, the new browser now reaches that mark only in the middle of the night, U.S. time, Vizzaccaro added.”</p></blockquote>
<p><a href="http://blog.statcounter.com/2008/09/chrome-latest-stats-globalusuk/">StatCounter’s latest Chrome stats of over 450M page views globally</a>, also indicate the introduction period and the slight decline afterwards. Chrome’s popularity is proportional with its level of exploitability, so keeping an eye on how many users stick with the (BETA) browser, will either increase or decrease it.</p>
<p><a href="http://blogs.zdnet.com/security/?p=1975" target="_blank">Source</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google’s-chrome/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome+-+http://b2l.me/aa48v7&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;title=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome&amp;desc=Aditya%20K%20Sood%20from%20the%20EvilFingers%20community%2C%20which%20disclosed%20the%20first%20Chrome%20DoS%20vulnerability%20at%20the%20beginning%20of%20the%20month%2C%20has%20released%20a%20proof%20of%20concept%20demonstrating%20a%20memory%20exhaustion%20DoS%20vulnerability%20affecting%20Google%E2%80%99s%20Chrome%20versions%20Chrome%2F0.2.149.30%20and%20Chrome%2F0.2.149.29%20%3A%0D%0A%E2%80%9CThe%20G" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;bm_description=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/&amp;t=Memory+exhaustion+DoS+vulnerability+hits+Google%E2%80%99s+Chrome" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://eguru.info/2008/10/memory-exhaustion-dos-vulnerability-hits-google%e2%80%99s-chrome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>High expectations from Google Chrome</title>
		<link>http://eguru.info/2008/09/high-expectations-from-google-chrome/</link>
		<comments>http://eguru.info/2008/09/high-expectations-from-google-chrome/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 04:14:13 +0000</pubDate>
		<dc:creator>Krishna Chaitanya Mandava</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[browser]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[IE]]></category>
		<category><![CDATA[IE6]]></category>
		<category><![CDATA[IE7]]></category>
		<category><![CDATA[Safari]]></category>

		<guid isPermaLink="false">http://eguru.info/?p=152</guid>
		<description><![CDATA[Some are calling Google&#8217;s new browser Chrome an &#8220;Internet Explorer killer.&#8221; Others venture further and call it a &#8220;Windows killer.&#8221; Whether Google&#8217;s newly launched browser has Microsoft quaking is unclear, but there&#8217;s no doubt that Google is serious about &#8220;organizing the world&#8217;s information&#8221;—and is prepared to shake up the status quo in the process. It [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-medium wp-image-153" title="google-chrome" src="http://eguru.info/wp-content/uploads/2008/09/google-chrome-300x244.jpg" alt="Google Chrome" width="300" height="244" /><span id="more-152"></span>Some are calling Google&#8217;s new browser Chrome an &#8220;Internet Explorer killer.&#8221; Others venture<img src="file:///C:/DOCUME~1/KRISHN~1.MAN/LOCALS~1/Temp/moz-screenshot-4.jpg" alt="" /><br />
further and call it a &#8220;Windows killer.&#8221; Whether Google&#8217;s newly launched<br />
browser has Microsoft quaking is unclear, but there&#8217;s no doubt that Google is serious about<br />
&#8220;organizing the world&#8217;s information&#8221;—and is prepared to shake up the<br />
status quo in the process.</p>
<p>It should come as little surprise that Google is entering the Web<br />
browser market. The search heavyweight already has a substantial stake<br />
in our online activities. Search, check! E-mail, check! Office<br />
documents, check! The list of Web applications offered by Google is<br />
both long and varied. With its goal of providing all of our online<br />
needs, it makes perfect sense that Google would step up and provide a<br />
Web browser built to accommodate its applications. With Chrome, Google<br />
is betting that more of us will move more of our computing from<br />
desktops to online, relying on the vast data centers known as &#8220;the<br />
cloud.&#8221; But can Google&#8217;s Web browser single handedly entice us to dump a<br />
favorite Web browser and our computer&#8217;s operating system?</p>
<p>Let&#8217;s start with the operating system. What&#8217;s your favorite flavor?<br />
Windows, OS X, Linux? Whichever your allegiance, for at least the next<br />
several years, you&#8217;ll need an operating system to boot your computer<br />
and store the applications that are still too large and unwieldy to run<br />
from inside the cloud. Take iTunes, Photoshop, or PowerPoint. While<br />
online equivalents exist, they just can&#8217;t match the processing power<br />
and functionality that come from the applications you run from your<br />
computer&#8217;s operating system.</p>
<h3>Segmenting Online Activities</h3>
<p>And, while Google Chrome&#8217;s strength comes in its ability to segment<br />
online activities—an open tab playing a live video stream won&#8217;t slow<br />
down the remainder of your Web browsing—it still needs an operating<br />
system at its foundation. For evidence that Google Chrome is not yet<br />
ready to replace an operating system, consider the browser&#8217;s<br />
limitations at launch. Despite two years of hard work, Chrome can&#8217;t run<br />
without Windows and it won&#8217;t run at all on Apple&#8217;s OS X or Linux.</p>
<p>Then comes the question of Chrome&#8217;s potential for wresting market<br />
share from Google&#8217;s rivals. Can Google really launch a new browser and<br />
expect to grab some of Internet Explorer&#8217;s 72% Web browser market share<br />
and Firefox&#8217;s 20%? Chrome certainly started off strong. On its opening<br />
days, according to analysts at Lehman Brothers, free downloads reached<br />
an astounding 2% of the market. Lehman predicts that the new browser<br />
could reach 15%-20% market share in just two years. In other words,<br />
it&#8217;s likely to be big, but not dominant.</p>
<p>What&#8217;s more, Google Chrome is not yet proven as a revolutionary Web<br />
browser. Google technicians emphasize that its architecture is<br />
different, and predict that it will handle computing intensive software<br />
applications better than its rivals. But most of the Web surfers who<br />
downloaded it on its first day came to face to face with a bare-bones<br />
browser with few of the add-ons and plug-ins available on the others.</p>
<h3>Brand of Gold</h3>
<p>What Chrome can boast is the Google brand. While not everything<br />
Google touches turns to shareholder gold, its brand works wonders. The<br />
company could launch a new brand of laundry detergent, and we&#8217;d likely<br />
clear grocery store shelves of the stuff. You can bet that Google&#8217;s<br />
fans will jump at the chance to download a Google-branded browser, so<br />
they can check their Gmail, look-up their Google Maps, and search for<br />
laundry detergent on Google.com.</p>
<p>It&#8217;s our infatuation with the Google brand, more than the technology<br />
inside, that will boost Chrome&#8217;s market share and further extend Google<br />
in our daily Web activities. As for being a Windows or Internet<br />
Explorer killer, don&#8217;t count on it. <img src="file:///C:/DOCUME~1/KRISHN~1.MAN/LOCALS~1/Temp/moz-screenshot-5.jpg" alt="" /></p>
<p>Source: <a href="http://www.businessweek.com/technology/content/sep2008/tc2008093_489920.htm?chan=technology_technology+index+page_top+stories">Business Week</a></p>


<div class="shr-bookmarks shr-bookmarks-expand shr-bookmarks-center shr-bookmarks-bg-shr">
<ul class="socials">
		<li class="shr-comfeed">
			<a href="http://eguru.info/2008/09/high-expectations-from-google-chrome/feed" rel="nofollow" class="external" title="Subscribe to the comments for this post?">Subscribe to the comments for this post?</a>
		</li>
		<li class="shr-delicious">
			<a href="http://delicious.com/post?url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Share this on del.icio.us">Share this on del.icio.us</a>
		</li>
		<li class="shr-digg">
			<a href="http://digg.com/submit?phase=2&amp;url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Digg this!">Digg this!</a>
		</li>
		<li class="shr-googlebuzz">
			<a href="http://www.google.com/buzz/post?url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;imageurl=" rel="nofollow" class="external" title="Post on Google Buzz">Post on Google Buzz</a>
		</li>
		<li class="shr-mixx">
			<a href="http://www.mixx.com/submit?page_url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Share this on Mixx">Share this on Mixx</a>
		</li>
		<li class="shr-reddit">
			<a href="http://reddit.com/submit?url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Share this on Reddit">Share this on Reddit</a>
		</li>
		<li class="shr-stumbleupon">
			<a href="http://www.stumbleupon.com/submit?url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Stumble upon something good? Share it on StumbleUpon">Stumble upon something good? Share it on StumbleUpon</a>
		</li>
		<li class="shr-technorati">
			<a href="http://technorati.com/faves?add=http://eguru.info/2008/09/high-expectations-from-google-chrome/" rel="nofollow" class="external" title="Share this on Technorati">Share this on Technorati</a>
		</li>
		<li class="shr-twitter">
			<a href="http://twitter.com/home?status=High+expectations+from+Google+Chrome+-+File: /data/app/webapp/functions.php<br />Line: 43<br />Message: Table 'b2l_shrinker.phurl_urls' doesn't exist&amp;source=shareaholic" rel="nofollow" class="external" title="Tweet This!">Tweet This!</a>
		</li>
		<li class="shr-diigo">
			<a href="http://www.diigo.com/post?url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;title=High+expectations+from+Google+Chrome&amp;desc=Some%20are%20calling%20Google%27s%20new%20browser%20Chrome%20an%20%22Internet%20Explorer%20killer.%22%20Others%20venture%0D%0Afurther%20and%20call%20it%20a%20%22Windows%20killer.%22%20Whether%20Google%27s%20newly%20launched%0D%0Abrowser%20has%20Microsoft%20quaking%20is%20unclear%2C%20but%20there%27s%20no%20doubt%20that%20Google%20is%20serious%20about%0D%0A%22organizing%20the%20world%27s%20information%22%E2%80%94and" rel="nofollow" class="external" title="Post this on Diigo">Post this on Diigo</a>
		</li>
		<li class="shr-misterwong">
			<a href="http://www.mister-wong.com/addurl/?bm_url=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;bm_description=High+expectations+from+Google+Chrome&amp;plugin=sexybookmarks" rel="nofollow" class="external" title="Add this to Mister Wong">Add this to Mister Wong</a>
		</li>
		<li class="shr-facebook">
			<a href="http://www.facebook.com/share.php?v=4&amp;src=bm&amp;u=http://eguru.info/2008/09/high-expectations-from-google-chrome/&amp;t=High+expectations+from+Google+Chrome" rel="nofollow" class="external" title="Share this on Facebook">Share this on Facebook</a>
		</li>
</ul>
<div style="clear:both;"></div>
</div>

]]></content:encoded>
			<wfw:commentRss>http://eguru.info/2008/09/high-expectations-from-google-chrome/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
