[.08] Add a phishing template for Google Chrome
Posted: Wed Aug 28, 2013 1:56 pm
Chrome should have a template for the "Safe Browsing" anti-phishing files.
------------
Note to tzuk...
The variable '%Tmpl.Chrome%' can't be used, since it points to the folder underneath "User Data":
Tmpl.Chrome=%Local AppData%\Google\Chrome\User Data\Default
------------
I would recommend that all Chrome users allow access to the Chrome "Safe Browsing" (anti-)phishing files.
And, just as the phishing template for Firefox has some security type files added to it, I have added a setting to this template to allow Chrome to update it's "Certificate Revocation Lists" file, when sandboxed.
[Template_Local_Google_Chrome_Phishing_DirectAccess]
Tmpl.Class=Local
Tmpl.Title=Allow direct access to Google Chrome phishing files
OpenFilePath=chrome.exe,%Local AppData%\Google\Chrome\User Data\Safe Browsing*
OpenFilePath=chrome.exe,%Local AppData%\Google\Chrome\User Data\Certificate Revocation Lists
(Dragon and Iron users can check to see if they have those files, and revise the template to use 'dragon.exe' or 'iron.exe' in place of 'chrome.exe')
------
The above template will allow sandboxed Chrome to keep these files updated, outside of the sandbox:
Safe Browsing Download Whitelist
Safe Browsing Extension Blacklist
Safe Browsing Bloom
Safe Browsing Bloom Prefix Set
Safe Browsing Cookies
Safe Browsing Cookies-journal
Safe Browsing Csd Whitelist
Safe Browsing Download
Certificate Revocation Lists
------------
Note to tzuk...
The variable '%Tmpl.Chrome%' can't be used, since it points to the folder underneath "User Data":
Tmpl.Chrome=%Local AppData%\Google\Chrome\User Data\Default
------------
I would recommend that all Chrome users allow access to the Chrome "Safe Browsing" (anti-)phishing files.
And, just as the phishing template for Firefox has some security type files added to it, I have added a setting to this template to allow Chrome to update it's "Certificate Revocation Lists" file, when sandboxed.
[Template_Local_Google_Chrome_Phishing_DirectAccess]
Tmpl.Class=Local
Tmpl.Title=Allow direct access to Google Chrome phishing files
OpenFilePath=chrome.exe,%Local AppData%\Google\Chrome\User Data\Safe Browsing*
OpenFilePath=chrome.exe,%Local AppData%\Google\Chrome\User Data\Certificate Revocation Lists
(Dragon and Iron users can check to see if they have those files, and revise the template to use 'dragon.exe' or 'iron.exe' in place of 'chrome.exe')
------
The above template will allow sandboxed Chrome to keep these files updated, outside of the sandbox:
Safe Browsing Download Whitelist
Safe Browsing Extension Blacklist
Safe Browsing Bloom
Safe Browsing Bloom Prefix Set
Safe Browsing Cookies
Safe Browsing Cookies-journal
Safe Browsing Csd Whitelist
Safe Browsing Download
Certificate Revocation Lists