5 ms·
I'm on the sign-in page for Google. I check out the URL, it's google.com. The padlock is there. I sign in. Whoops, must have typed my password in wrong. It
by 2bitencryption 10y ago
I'm on the sign-in page for Google.
I check out the URL, it's google.com. The padlock is there.
I sign in. Whoops, must have typed my password in wrong. It happens sometimes. So I type it in correctly.
...I just got phished.
The problem is that the behavior of this exploit mimics almost EXACTLY the expected behavior. The warning flags to even an educated user are not clear at all. It would be so easy to fall for this.
- jrockway 10y agoYour profile picture would go away on the second page though, which might be unusual. I recommend installing this extension, however: https://chrome.google.com/webstore/detail/password-alert/noondiphcddnnabmjcihcjfbhfklnnep?hl=en https://chrome.google.com/webstore/detail/password-alert/noo...
- kuschku 10y agoWhich might be unusual, unless you add an error message, as in this example: https://cdn.kuschku.de/ServiceLogin/video.mp4 https://cdn.kuschku.de/ServiceLogin/video.mp4
- djsumdog 10y agoWoah, thanks for the video. That makes the issue more apparent. Still, couldn't you do the same thing with the standard OAuth flow for Google/Facebook/Twitter? Also, cool profile photo. :-P
- aftbit 10y agoIt looks like your domain is flagged for phishing in my Chrome. :(
- kuschku 10y agoYes, that's why I removed the link, too. Now I just have to wait a few days until it's not flagges anymore. Did I mention how much I hate Google, and their "automate everything" stance, especially regarding flagging of content?
- pwinnski 10y agoI lack the patience to create a video (kudos!), but I'm still not seeing how this is any more of a vulnerability than just sending someone to that page in the first place? It's not on a google.com URL, which seems immediately obviously to me. It might help that I always enter my password via command-\, never typing it. So even if I was really not paying any attention, and didn't realize the domain had completely changed, and that my username had disappeared (which still seems unlikely), command-\ wouldn't fill in my credentials, because it's not google.com. That last page is phishing, for sure. And it's going to fool some number of people, for sure. I'm struggling to think of how that's something Google should do something about though.
- kuschku 10y agoGoogle obviously thinks it shouldn’t happen – that’s why they have a whitelist in the first place. This is just a simple whitelist bypass. But the issue is: How do you check the page you are on is the correct one? You might check everything the first time, but after that?