Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

google chrome vulenrabilites

The wait is over for new version of Google Chrome! Chrome 41 or 41.0.2272.76 has been released for download with major fixing of 13 high-severity and 6 medium-severity vulnerabilities identified by experts & researchers, with more than 50 other issues of security has been addressed including:

  • A number of new apps/extension APIs
  • Lots of under the hood changes for stability and performance

Google handed out a total of $14,500 to the researchers and experts for identifying these Google Chrome Vulnerabilities, including a write flaw in media (CVE-2015-1212), a type confusion in v8 bindings (CVE-2015-1217) & a use-after-free in v8 bindings (CVE-2015-1216).

Still the Safest Browser?

A total of 51 Google Chrome Vulnerabilities have been discovered and fixed over the past version release. But still Google Chrome comes out to be the safest browser of all. With the recent news of Adobe Flash Player Vulnerabilities being discovered in the wild, Chrome was not Vulnerable to any of them! Also, the latest vulnerability found in SSL/TLS dubbed as FREAK, doesn't affect the Google Chrome Browser. Again, The previous year Hit news affecting millions of Facebook and Android users, Android SOP Vulnerability, also remained untouched from Chrome Browser! But other browsers such as Mozilla Firefox and Opera remained vulnerable to one or other vulnerability out of these.

Money Matters

Google has a system for rewarding the reporting of security flaws called as the 'Security Reward Program' under which Google has paid close to $1.5 million alone in 2014 to various third-party researchers for identifying vulnerabilities. Google has also scrapped it's annual marque event known as "Pwnium" with Tim Willis, chrome Security Team declaring in a blogpost.

If a security researcher was to discover a Pwnium-quality bug chain today, it's highly likely that they would wait until the contest to report it to get a cash reward. This is a bad scenario for all parties. It's bad for us because the bug doesn't get fixed immediately and our users are left at risk , the blogpost stated.

Though it looks a lucrative option for researchers but Tim cautioned about Google's lawyers opinion about this round the clock program being experimental and discretionary with range of cash awards from a min of $500 upto a maximum of $50,000.

Technical Details

This update includes 51 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chromium security page for more information.

[$7500][456516] High CVE-2015-1212: Out-of-bounds write in media. Credit to anonymous. [$5000][448423] High CVE-2015-1213: Out-of-bounds write in skia filters. Credit to cloudfuzzer. [$5000][445810] High CVE-2015-1214: Out-of-bounds write in skia filters. Credit to cloudfuzzer. [$5000][445809] High CVE-2015-1215: Out-of-bounds write in skia filters. Credit to cloudfuzzer. [$4000][454954] High CVE-2015-1216: Use-after-free in v8 bindings. Credit to anonymous. [$3000][456192] High CVE-2015-1217: Type confusion in v8 bindings. Credit to anonymous. [$3000][456059] High CVE-2015-1218: Use-after-free in dom. Credit to cloudfuzzer. [$3000][446164] High CVE-2015-1219: Integer overflow in webgl. Credit to Chen Zhang (demi6od) of NSFOCUS Security Team. [$3000][437651] High CVE-2015-1220: Use-after-free in gif decoder. Credit to Aki Helin of OUSPG. [$2500][455368] High CVE-2015-1221: Use-after-free in web databases. Credit to Collin Payne. [$2500][448082] High CVE-2015-1222: Use-after-free in service workers. Credit to Collin Payne. [$2000][454231] High CVE-2015-1223: Use-after-free in dom. Credit to Maksymillian Motyl. [449610] High CVE-2015-1230: Type confusion in v8. Credit to Skylined working with HP's Zero Day Initiative. [$2000][449958] Medium CVE-2015-1224: Out-of-bounds read in vpxdecoder. Credit to Aki Helin of OUSPG. [$1000][446033] Medium CVE-2015-1225: Out-of-bounds read in pdfium. Credit to cloudfuzzer. [$1000][456841] Medium CVE-2015-1226: Validation issue in debugger. Credit to Rob Wu. [$1000][450389] Medium CVE-2015-1227: Uninitialized value in blink. Credit to Christoph Diehl. [$1000][444707] Medium CVE-2015-1228: Uninitialized value in rendering. Credit to miaubiz. [$500][431504] Medium CVE-2015-1229: Cookie injection via proxies. Credit to iliwoy.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.