<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Chrome on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/chrome/</link>
    <description>Recent content in Chrome on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 06 May 2021 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/chrome/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Analysis of HSTS Caches of Different Browsers</title>
      <link>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</link>
      <pubDate>Thu, 06 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</guid>
      <description>&lt;p&gt;I recently stumbled upon a strange behavior in my Firefox: I visited an&#xA;HTTPS-enabled website that I had visited before and saw that my Firefox&#xA;connected insecurely via HTTP. I found that strange because nowadays, most&#xA;websites set the&#xA;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security&#34;&gt;HSTS&lt;/a&gt;&#xA;header, which is supposed to force the browser to connect via HTTPS. I checked&#xA;whether this website set the HSTS header – and it did. This means my Firefox was&#xA;ignoring/forgetting about the HSTS header right after my visit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cisco: Magic WebEx URL Allows Arbitrary Remote Command Execution – Project Zero</title>
      <link>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</link>
      <pubDate>Tue, 24 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/cisco-magic-webex-url-allows-arbitrary-remote-command-execution-project-zero/</guid>
      <description>&lt;p&gt;Tavis did it again[1]. As stated in the title it is possible to remotely execute commands via the Chrome extension for the popular meeting software Cisco WebEx. This post summarizes the most relevant information for you.&lt;/p&gt;&#xA;&lt;p&gt;A test page with working &lt;a href=&#34;https://bugs.chromium.org/p/project-zero/issues/attachmentText?aid=267784&#34;&gt;demo code&lt;/a&gt; is available to check for the issue on Windows systems [2]. From our point of view the Chrome extension is affected by this issue as well as the Firefox extension as both extension APIs are quite similar. However, Mozilla blocked the FireFox plugin to protect users from the risk of being exploited through the plugin[3][4]. IE seems to be fine thanks to Cisco’s decision to invoke the WebEx Meeting Center via e.g. ActiveX.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
