As social engineering has become the dominant method of malware distribution, browser makers started designing more robust and recognizable UIs in order to help end users make aware choices while surfing the Web. In this process, creating trusted notification mechanisms played a crucial role: nowadays any modern browser is able to identify potentially dangerous or sensitive action requested by a webpage (file downloading, plugin installation, granting privileges to websites) and prompt a dialog box or a notification bar to require explicit confirmation from the user. Even though these improvements led to a greater degree of assurance, the notification mechanisms are far from being 100% safe: in this presentation the speaker will show how notification bars in major browsers (Chrome 24, IE9, IE10) can be abused with little (or even no) social engineering, leading to users security compromise and even to conducting trivial code execution on the victim's machine. Rosario Valotta is an IT security professional with over 12 years’ experience. He has been actively finding vulnerabilities and exploits since 2007 and has released a bunch of advisories and new attack techniques, including: - Nduja Fuzzer: an innovative fuzzer leveraging on DOM Levels 2 and 3 APIs that proved to be effective in discovering several 0-day vulnerabilities in major browsers - Cookiejacking, a new attack technique to steal any cookie on Internet Explorer (presented at HITB2011AMS and Swiss Cyber Storm 2011) - Nduja connection, the first cross webmail XSS worm - Memova exploit, affecting over 40 million users worldwide - Outlook web access for Exchange CSRF vulnerability - Information gathering through Windows Media Player vulnerabilities The complete list is on the blog: http://sites.google.com/site/tentacoloviola/.Rosario Valotta Rosario Valotta