Google Chrome: Turn off automatic downloads immediately

Google Chrome users in Windows should immediately disable automatic downloads in the browser to protect authentication data from a newly discovered new threat.

The Chrome browser is currently the most popular browser on desktop devices. It is configured to automatically transfer secure files to the user's system without prompt by default.Google Chrome

Any file downloaded by Google Chrome users passes Google's Safe Browsing checks to be automatically moved to the default folder s.

The new attack, detailed in the Defense Code website, uses Google Chrome's auto-download behavior with Windows Explorer Shell command files that have the .scf file extension.

The malicious script comes in the form of plain text that includes instructions, and limited commands. What's interesting is that it can load e.g from a remote server.

The biggest problem is that Windows will process these files as soon as you open the folder where they are stored and that these files appear without extension in Windows Explorer regardless of the settings. This means that attackers could easily hide the file behind a covert file name, such as .jpg.

Attackers use an SMB server location for the icon. What happens next is that the server asks for authentication and the system will provide it. Researchers note that cracking passwords is over , unless it is of a complex type.

The situation is even worse for Windows 8 or 10 users who authenticate with a Microsoft account, as the account will give the attacker access to online services such as Outlook, OneDrive or Office 365 if they are used by user. There is also the possibility of reusing it access to non-Microsoft websites.

Read more

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).