Thursday, May 18, 2017

My results of POC Stealing Windows Credentials Using Google Chrome

I was reading an article written by Bosko Stankovic from Defence Code Titled Stealing Windows Credentials Using Google Chrome and in it he had a POC that in theory could lead Chrome web browser to download malicious code and simply opening the folder would lead to running the malicious code.

In his article he stated that Chrome gave no warning that something was being downloaded. In my case I was warned so I sent him a email with my results, The strange thing is that in his email it seems we are running the same version of chrome --- Version 58.0.3029.110 (64-bit)

Here are my results:


Highlighting the text andd selecting go to page results:



I have made Video of my results.




Note: My poor old laptop is very slow
Note 2: Sorry about having to use Flash I don't think I have any control over the format of video used

Two Links to the authors website with different results than mine.

No comments:

Post a Comment