Enterprise Newsletter
 
NEWSLETTERS
 

CIO.com updates, insights and advice on technology, management and your career.

 
 
 
LEADERSHIP
 
CIO Executive Programs
The Leader in Face-to-Face Education for Senior Executives

Offering regional and national programs, CIO (and CSO) events bring together some of the most respected names and thought leaders in information technology and security. Presented by CIOs and other senior level executives, these invitation-only programs offer timely topics and strong networking. Learn More »

 
CIO Executive Council
A Peer-Advisory Service and Professional Association for CIOs

Turn Geeks into Leaders

June 17, 11:30 AM - 12:30 PM U.S./ET (GMT-4)

Larry Bonfante, CIO of the U.S. Tennis Association, will discuss the skills and approaches that your rising IT leaders must learn to be effective in an executive capacity.

How to Handle Your New CEO: Managing Turnover at the Top

June 18, 11:00 AM - 12:00 PM U.S./Eastern (GMT-4)

Turbulent times have increased turnover at the top. Find out what Council CIOs have done to "break in" new CEOs—build relationships, set expectations, educate on the role of IT.

Mid-Market CIO Panel: Tips and Techniques for Improving Vendor Relationships

July 15, 4:00 PM - 5:00 PM U.S./Eastern (GMT-4)

We'll highlight relationship priorities and best practices identified in a Council study, and we'll interact with a CIO panel on the approaches they've used to improve strategic vendor partnerships.

Executive Competencies Assessment Tool

Assess Your Business Leadership Skills with the Council's new benchmarking tool. Rate yourself in change leadership, strategy, customer focus and more.

More / Register »

Learn more about the CIO Executive Council »



 
 
RESOURCE CENTER
 
 
 
SUBSCRIBE TO CIO
 
Are you involved in setting the direction for your company's IT budget or strategy?

Apply today for a FREE subscription to CIO Magazine!

 
 
 

Early Security Issues Tarnish Google's Chrome

Security researchers have reported finding vulnerabilities in Google's new Web browser a day after it was released in beta.

 

September 03, 2008 — IDG News Service —

Security researchers have reported finding vulnerabilities in Google's new Web browser a day after it was released in beta.

One vulnerability would allow hackers to crash the browser. Security researcher Rishi Narang described the issue on the SecuriTeam Web site and posted a proof of concept at Evilfingers. According to Narang, a hacker could build a malicious link that includes an undefined handler followed by a certain character. When a user clicks on the link, Chrome crashes.

Another, potentially more serious vulnerability could result in Chrome users downloading malicious code. The problem is due, in part, to the fact that Google uses an older version of WebKit, the open-source browser technology also used in Apple's Safari browser, that includes the vulnerability.

Discovered by researcher Aviv Raff, the problem lies in the way Chrome downloads files and the way Windows handles the downloaded files, he said.

Chrome's default setting downloads files into a folder. It then displays a download bar at the bottom of the browser page. Users click on the bar to open the file. If the file is an executable, Windows displays a warning, which can help users avoid inadvertently downloading malicious code.

If the file is a JAR (Java Archive), however, it isn't treated like other executables, Raff said. When a user clicks on that download bar, instead of displaying a warning, Windows automatically runs the file.

The problem is exacerbated by the way the download bar looks, Raff said. The bar appears to be part of the Web page. In a proof of concept that Raff posted, users might think they're clicking on a link or a button on the page, rather than opening up a downloaded file.

"This is again a sort of a 'blended threat'," he wrote in a blog post. "Two small issues in different products, when blended together, create a much larger problem."

He thinks Google might face other, similar issues in the future because Chrome uses technologies from different browsers, including Apple's Safari and Mozilla's Firefox.

"Security wise, it's very problematic," Raff wrote. "They'll have to track all security vulnerabilities in those features, and fix them in Chrome too. This will probably be only after those vulnerabilities were fixed by the other vendors or were publicly reported. It will put Chrome users at risk for a long time."

Google did not directly address questions about this vulnerability or whether it plans to make any changes to Chrome to prevent any potential problems. Instead, a Google spokeswoman said in a statement that, by default, Chrome downloads files into a separate folder instead of on the user's desktop as a way to avoid some security problems. In addition, she said that users can set the browser to ask where to save each file before downloading it.

 
 
Loading...
 
WHITE PAPERS

Investing in Business Analytics Technology

Find the answers to your questions about business anyalytics initiatives.
 

Document-Sharing Solutions

Examine the benefits and challenges that IT executives are facing and how they plan to control the changes.
 

How Can Your Organization Weather This Economic Storm?

IT executives are under intense pressure to cut costs, and that pressure is significantly increased by the current grim economic outlook.
 

Deliver Higher-Performing Technology Services with ITIL

Enable the business and your IT organization to cope with the effects of economic stress.
 

Making Data Center Infrastructures More Adaptive

Learn how administrators can tackle problems in ways that were previously impossible.
 

Server Management Tools Automate Capabilities and Improve Efficiency

In this white paper, Info-Tech covers the key considerations of server management tools to take the pain out of day-to-day provisioning, patching and operational support.
 

WEBCASTS

Webcast with Dan Vesset: Investing in Business Analytics Technology

What exactly is business analytics and why should you care? Dan Vesset of IDC and Gaurav Verma of SAS answer this a...
 

Enterprise Cloud Computing: Ready for Primetime?

The progression toward enterprise cloud computing is happening today, as industry leaders deploy technologies that ...
 

Preparing Your Business Services for the Future

Would you trust your network monitoring tools enough to know when something is truly halting a business service? Wh...
 

Enterprise System Management Challenges in Big Organizations with Eli Almog

In this Podcast with Eli Almog, Corporate Architect in BMC's CTO Office, discusses how IT managers can know when it...
 

A Down-to-Earth look at Cloud Computing

Is cloud computing going to take over the data center as we know it? Join us as we talk about cloud computing with...
 

BSM in the Field, Practical Insights from Peter Armaly

Have you thought about BSM, but haven't quite gotten the buy-in you need? Get down and dirty with BSM installations...
 

Resource Alerts

Get instant email notifications by topic when white papers, webcasts, and case studies are added to our library.

 
FEATURED SPONSORS
 
 
 
SPONSORED LINKS
 

Seven Ways ITIL Can Help You in an Economic Downturn

Maximizing the Business Value of the PC Infrastructure

Using Open Source to Deploy Web Applications

How Interactive Viewer Reduces the Effort to Meet Visualization Requirements

White Paper: 8 Key Ingredients to Building an Internal Cloud

Software Executives: Take Control of Your Organization's Code Quality

BPM ROI calculator

Oracle's Application Grid Technical Demo

Next-Generation Application Servers and Infrastructure

Application Infrastructure at Enterprise Organizations

Achieving Business Agility with Application Grid

Craft a Strategy to Lower Your Total Cost of Ownership

A Natural User Interface for Enterprise Applications

On-Demand HR for a Global Organization

Four steps to populate your CMDB.

Delivering Secure and Reliable Data through Spreadsheet Automation

Open Source BI: Inexpensive Solutions for Developers

Gartner Shares Predictions for 2009

Introducing the new HP ProLiant G6 server family

Accenture: Outsourcing for Competitive Advantage. More...

Better spam protection with Postini for just $1/user/mo

Introducing the new HP ProLiant G6 server family

infoBOOM! - The Mid-Sized Company CIO's Exclusive Community

Accenture IT Consulting: Logical meets technological. More . . .

The Fraudster Economy Model: Operating a Business in the Underground

Revolutionizing Enterprise Application Deployment

Learn how to managing client systems in the enterprise.

Cloud Computing: Read about VMware's compelling vision & set of products

Top-line Performance that's Bottom-line Efficient

How Open Source is Changing the Face of Enterprise Software

BPM Survey Results: The Real-World Analysis

Ready to Act: 3 Recommendations for Agile Processes

Oracle WebLogic Server Technical Demo

Data Grids and Service-Oriented Architecture

Achieving the Impossible: Unlimited Application Scalability

A Middleware Foundation for Application Grid

Next Generation Enterprise Applications

A Truly Global HCM System

Learn how to provide complete Business Service Management.

Increase ROI of Your Application Portfolio

Financial Institutions Need Rich Internet Applicatons

Forrester: Implementing Rich Internet Applications

"Enterprise-Proven" is the Prerequisite for Enterprise SaaS Portal Solutions

Accenture IT Consulting: Enabling high performance. More...

Top Five CIO Challenges

Insight makes it easy to spend your Microsoft subsidy check.

Five minute business analytics assessment. Immediate results.

Dangerous Collaboration Practices: 5 Ways IT Can Minimize Risk

Accenture: Outsourcing for uncertain times. Click to learn more.

The Case for Investing in Business Analytics Technology. Read white paper.