Download of Clickonce Application in Chrome marked as Malicious File - google-chrome

It seems that the latest update of Google Chrome 44 to 45 is blocking clickonce applications.
Our clickonce application is working fine and is in production for over weeks.
This morning we got reports that when users tried to download our application it straight end up in the Downloads tab with following message: "[...].application may harm your browsing experience, so Chrome has blocked it. Recover malicious file". After clicking that message a confirmation dialog is shown and if that gets accepted the user can download the application file.
Is anyone else having the same experience with their clickonce applications and do you have any idea how to get around with it?
Thanks for any ideas / help!
(I have sadly not enough reputation to post images, sorry for that)
Elia

It looks like it might have just been raised in the Chromium issue tracker:
https://code.google.com/p/chromium/issues/detail?id=532952
Quoting from there:
My understanding is that if Google has not scanned the file because it is unreachable or isn't aware of it (no public links so it can't be crawled), Chrome will block the application."

In latest version things are worse: There is only Suppress button next to the message "xxx may harm your browsing experience, so Chrome has blocked it" with no links for "recover". The trick is to click on Show all downloads button on far right. There you will see the link for recovering the file that Chrome unnecessarily deemed as malicious.

Related

Cloud Shell: Editor is not loading in incognito mode

So I have been following the following step for past few months:
Log in to Google Cloud Console from Chrome's incognito mode
Activate Cloud Shell
From there, I usually opened Editor and managed my files in a new window
Today while I was following the above steps, this issue raised up:
Basically, I cannot open editor anymore. I have already went through similar posts, and my issue is that I am using incognito where browser extensions or cookies shouldn't be an issue.
I am facing this problem for the first time and if anyone knows what is the cause or any suggestions would be appreciated.
EDIT:
For now Microsoft Edge InPrivate Mode is working for me. I am still interested in fixing the issue for Chrome.
Have reported the issue in Issue Tracker. Please "start" for more attention.
This started happening recently because third-party cookies stopped being supported in Incognito mode as of Chrome 83. Third-party cookies are required for the editor to work because of the way the open-source Theia IDE is integrated into Cloud Shell. The team is exploring various fixes, but in the mean time the following workaround should work:
In Incognito Mode, click on the crossed out 'eye' icon on the address bar.
Click on 'Site not working?'
Click on 'Allow cookies'
Safari problem stems from the same issue, but I am not certain if a similar workaround exists.
I've encountered the same issue myself (I tried this on Chrome running on both ChromeOS and MacOS) - it looks like a bug so in this case I'd recommend reporting it on Google's Issuetracker (you can even put a link to this post).
UNfortunately it looks like it's not just the Chrome browser. I tried this on Safari 13.1 and found the issue you described is also present.
I didn't check other browsers but IssueTracker is the way to go. And be patient :)

Google Apps scripts called from Google sites now (suddenly) returning 404 error

I have a Google site (https://sites.google.com/site/kitchenergaffers/) which has many pages where scripts are launched. This morning (18 August 2020 EDT) I see that none of the script pages are working and the script seems to be reporting a 404 error of some sort.
The scripts interact with a series of Google sheets
Here is an example of one such page
https://sites.google.com/site/kitchenergaffers/home/general-gaffers-information/publish/directory-of-results?display=directory
=============
404. That's an error.
The requested URL /accounts was not found on this server. That's all we know.
There are many pages that run the same script, and some pages that have different scripts.
All scripts are set to run Anonymously, anyone can execute
Nothing on the site or within the scripts code or Sheets has changed to create this issue.
UPDATE: Although the error comes up using Chrome browser when logged into the creator account, or my personal account if I open an incognito window they run correctly!
UPDATE2: My PC suffered a Windows update yesterday that may be related however, my Chromebook shows the same problem. This problem does not happen if I use Edge browser.
UPDATE3: If I log out of all my accounts, and only sign in to one of them, the problem does not happen. Once I log into an additional account, the problem recurs. Signing out of all, then back into one only is then necessary.
as of 15:00EDT 20 August the issue seems to be resolved. I am not sure if it was something I did experimentally or what, but it has gone.
As it seemed to be related to my account and using Chrome I turned off sync, cleared cookies (also disabling Chrome extensions and bookmarks it seems) then "repaired" or reenabled extensions, resync'd to get the bookmarks from the Chromebook or phone and tried again.
The issue seems to have been resolved - maybe by these actions :)

Unable to log into Bitbucket on Chrome

When i tries to log in to Bitbucket (web-based version controller) on Chrome (google chrome web browser), i consistently get,
Oops, you've made a malformed request.
If you came here from a link we sent you, please contact support.
This can happen on Chrome. (works fine on Chrome incognito) This issue occurred when i try resetting my password.
then, i founded a solution from Atlassian Cloud Support. this
but, that's not resolve my problem.
In my research, it seems that people have experienced this error before, but none of worked solution i didn't found.
Any help some else is appreciated!
Thanks.
First thing - try to log into BitBucket in another browser, or in incognito mode:
Windows: ctrl + shift + n
Mac: cmd + shift + n
If it doesn't work then your best bet is to contact Atlassian support.
But if it works, then it's a big chance that an extension is causing the issue.
What you should do is disable all your extensions (type in the URL bar: chrome://extensions) and re-enable each extension, one by one, until you find the culprit.
For me it was this extension causing the problem:
Library Detector v5.6.0
I hope this helps you.
As snishalaka mentioned, https://poperblocker.com/ caused my atlassian Oops, you've made a malformed request problem. Disable it then login. Finally, you can turn on again.
As mentioned in the comments, just click 'Allow Popups' in the site in your popup blocker plugin and it will work fine.
Because it works in incognito, it sounds like there's some bad caching or something along those lines. Navigate to Bitbucket, open developer tools (menu -> More Tools -> Developer Tools), navigate to the Application tab, and in the top section of the left pane, click Clear storage. Now in the right pane, you should see several checkboxes and a "Clear site data" button. Click that, reload the page, and try again.
I had the same issue, couldn't login to Atlassian with Chrome. Strangely it was working on incognito. This lead me to checking my Chrome Extensions. One of the extensions I had installed, which was deactivated in incognito, was causing the issue. After removing it, everything went back to normal.
There may be several reasons for this issue. One was, account created earlier and now that was inactive. Other reason can be, login mail used in other bitbucket workspace(in other organization you worked before). So better to send this question to Atlassian support to resolve.
You can raise a question using below form.
ask bitbucket question
search other bitbucket questions
Well the issue for me was due to utorrent extension, soon after i disabled that it started working fine.

Links in Google searches and Inbox mails get rewritten to lnkr.us

I have switched off every extension except uBlock Origin (edit: now I tried disabling that too) and this still happens: links in Google searches and Inbox mails get rewritten to lnkr.us. I have checked with developer tools and this is not in the HTML source. This happens on click. Then uBlock Origin brings up the "document blocked" tab, I close it and if I click again, it goes straight to where it should. I am quite clueless as to what can cause this. I have seen others complaining and pinning it on this extension or that but as I said: I have disabled all my extensions. I am on Linux and hopefully malware free.
Looks like this:
https://lnkr.us/get?sourceId=5&uid=50639x1413x&format=go&host=icontent.us&out=http%3A%2F%2Flink.freedompopaccount.com%2Fu.d%3FZ4GuEv3xXUytsV84j81iW%3D3361&ref=https%3A%2F%2Finbox.google.com%2Fu%2F0%2F
A most curious example of this is:
http://mail-archives.apache.org/mod_mbox/httpd-users/201601.mbox/%3CCA+gyi+0DXFUBw5NYoyKFsvn-zxJ_65KJS_S8UxSHgHzSqsfNUQ#mail.gmail.com%3E
where the mangled URLs got into the mailing list archive.
Another is:
https://www.reddit.com/r/urbanplanning/comments/471v0k/the_distorted_dna_of_your_community/
The real question is: how can I debug what happens. I can read C, I have used gdb but I am no master of it to say the least.
Edit: nothing unusal on chrome://plugins either.
Edit2: sometimes it's icontent.us ; apparently that has been there for a year now, check https://twitter.com/baio1980/status/557236850486960128 the link there.
Edit3: I think this doesn't happen in Incognito mode so it might be an extension still but how can an extension stay alive after ticking it off on the Extensions screen?
Edit4: I have created a new ~/.config/google-chrome directory , disabled syncing extensions, reinstalled all my extensions and this doesn't happen now. My apps and plugins are the same.
I have created a new ~/.config/google-chrome directory , disabled syncing extensions, reinstalled all my extensions and this doesn't happen now. My apps and plugins are the same.

Google Chrome Client Certificate Popup

I'm implementing a mutual authentication for my client in order to solve not having to continually whitelist some of the agencies with a dynamic ip. The process works fine in all browsers that I've tried in the Windows environment (Windows 7).
The problem is that there is a popup for every time that the user goes to the site. On most browsers, this is a one time occurrence, when you first go to the site for the day. On Google Chrome, however, the popup occurs on what appears to be every POST/GET request. I found how to disable the popup for IE and FF with this link: http://docs.threerings.org.uk/wiki/Certificates_without_prompting, but there is still the problem with Chrome.
I've tried to install the certificate into the Trusted Root Certification Authorities, but I get an error message, "The import failed because the store was read-only, the store was full, or the store did not open correctly.".
If anyone has an idea on what I can do to get around the pop-up for Chrome, it would be greatly appreciated.
This is what you're looking for:
http://www.chromium.org/administrators/policy-list-3#AutoSelectCertificateForUrls
I could tell you how to do it exactly, but my honest opinion is that this is something you have to work out yourself. You need to know what is going on because you are more than likely to run into bugs (not bugs per-se but some undesired or unwanted results).
I have to admit that Google Chrome and Chromium are great browsers, but when it comes to client certificates, they have a lot of improvements to be made.
Just some extra info on this that may help people.
The first part references the CFBundleIdentifier which you can find in the Contents folder then info.plist. Click you Application and then show package contents then you should see it.
So I had to do this for Chromium for Tizen debugging below worked obviously use your CN name.
defaults write org.chromium.Chromium AutoSelectCertificateForUrls -array-add -string '{"pattern":"*","filter":{"ISSUER":{"CN":"Entrust Certification Authority"}}}'