back

by jay_kyburz·14y ago·view on hn ↗
Hey Scribd and or Google Chrome team.

I was just tricked into clicking an ad that simply said "play now" underneath the first slide. I thought it was going to start a slide show of the presentation. Scribd, if you are going to let just anybody advertise on your site you need to clearly mark what is an ad and what isn't.

Google team, clicking the add opened a tab that when attempting to close opened a custom dialog with two buttons at the bottom. "leave now" and "cancel" (or something like that). The page had populated that dialog with a bunch of text and ascii art pointing to the cancel button.

I didn't feel confident enough to click either buttons on this dialog because I thought be may have been some co-oped permissions dialog.I was unable to close the tab. I ended up using the task manager to kill chrome.

I took the time to make a note here because it's been ages (5 years perhaps) since I had to deal with this kind of crap. Has it always been around and I just haven't seen it or is there a resurgence these days.

3 comments
It's stuff like this that forces people to use AdBlock.
What? You killed Chrome because of what? What is a custom dialog? How is a "custom dialog" going to create a vulnerability?
There is a long history of such dialogs being used to exploit browsers and cause the execution of arbitrary code. For instance, such a dialog may be used to generate a true user click event, which the browser may then treat differently than an event that can be faked by Javascript. This entices malware developers to create dialogs in which you'll click on something, they don't really care what, they just need an authentic click.

Yes, it shouldn't do anything, but that doesn't mean it won't. I've hard-killed my browser for the same reason a couple of times.

Oh the plight of a Windows user.

I know what you're talking about with click jacking. The implication that a "true click" is any more likely to allow a JavaScript exploit to escape the browser sandbox is complete and utter bullshit. If you can give me one example, I won't scowl at the fact that 6 other people downvoted me without saying why.

Think about why, if the attacker already has enough control over the page to put up a transparent iframe and bind a click event to it, why not just do the thing the attacker is trying to attack you with?

And the answer is, the browser will stop them. It treats stuff that sources from a click differently. If it didn't, there would be no "clickjacking", the attackers would simply redirect you to the desired URL. The very existence of the term is evidence. It doesn't escape the sandbox, it gets raised privs from the sandbox by design.

What?

What on Earth does this have to do with vulnerabilities in the browser? Like I said, show me a single example of a vulnerability that is only exploited via a "true click". They DO NOT EXIST. It's hogwash.

I'll say again, I know what you're talking about. It is NOT relevant in this discussion about vulnerabilities.

Please show me an example otherwise.

What made you believe this is the support site for either Scribd or Google Chrome?
The guy who founded Scridb is here as well as tons of googlers.
As well as a ton of AdBlock users who'd prefer discussion of the presentation's content, and have no idea about the obtrusive adverts others mention ...
So what are they doing following this particular sub-thread and giving other people condescending advice?

Why aren't they busy reading other sub-threads where the presentation's content is discussed?

I am also here, and read a lot of what happens on HN; but, if my users decide to start using this as a support site for Cydia, especially so in aside comments on stories that are not even about Cydia, I will be sad: there are more appropriate and efficient channels for that sort of thing.
Not for Google products.

If you are not Internet famous I imagine you could do a lot worse than HN comments.