5 ms·
Why do you need a safe sandbox to view a phishing site? Afraid the site's design could hypnotise you into entering your credit card details?
by veave 3y ago
Why do you need a safe sandbox to view a phishing site? Afraid the site's design could hypnotise you into entering your credit card details?
- Sander_Marechal 3y agoPhishing sites are often also loaded with malware
- veave 3y agoAfraid the site's design could hypnotise you into double clicking the exe and accepting the browser's, MotW and smartscreen warning dialogs?
- nkrisc 3y agoMore worried about 0-day browser exploits. If you know a site is malicious, why risk it?
- NoobPretender 3y agoAnd the malware magically gets installed on your computer...how?
- function_seven 3y agoHere are 3 CVEs I randomly found from just this year. There are a handful of these every year. https://nvd.nist.gov/vuln/detail/CVE-2023-3079 https://nvd.nist.gov/vuln/detail/CVE-2023-3079 https://nvd.nist.gov/vuln/detail/CVE-2023-37450 https://nvd.nist.gov/vuln/detail/CVE-2023-37450 https://nvd.nist.gov/vuln/detail/CVE-2023-32439 https://nvd.nist.gov/vuln/detail/CVE-2023-32439
- iamflimflam1 3y agoI guess you've never heard of browser exploits?
- NoobPretender 3y agoDidn't think about that, good point
- NullPrefix 3y agoIf you don't run adblocker pretty much any website is loaded with malware. New York Times was infecting people with Bahama botnet some years ago. What's stopping other (non)shady websites from doing just the same?
- ikekkdcjkfke 3y agoI want to browse the net with only bitmaps being sent to me. I do not want to execute your javascript or markup or make requests other than what i have initiated. Please god someone make a docker container i can spin up on a throwaway computer that renders pages and sends bitmaps of the site to my main computer Edit: even better, every tab is a separate container instance, i close tab, it nukes the container
- deleted 3y ago[deleted]
- jasomill 3y agoTo render pages on a throwaway computer and send only bitmaps, connect to the throwaway computer via VNC and run an ordinary browser. As for improving on tab isolation over what existing browser sandboxes already offer, lightweight virtualization a la Firecracker seems like a more useful increment than containerization, and, assuming each tab has a similar VNC-like connection to its browser VM, virtualization would also make the whole "throwaway computer" setup less necessary to provide a meaningful security improvement.
- IIsi50MHz 3y agoSounds a bit like WebRenderingProxy.
- deleted 3y ago[deleted]
- nargek 3y agoMultiples reasons actually. 1. To bypass your corporate proxy (ok, not the best reason); 2. urlscan also allows you to pivot easily and find the same phishing kit as they have a nice database of scans; 3. urlscan also allows you to see the website from different proxies, which can be useful if there is geofencing. It isn't that simple and threat actors are far from being dumb :)
- heipei 3y agoI would say that you don't absolutely need a service like urlscan.io to look at a single suspicious URL, but running a URL through our sandbox will create a point of time snapshot that you can share with others, compare to existing scans and use as evidence for further actions like takedown. Disclaimer: I'm the CEO of urlscan.io
- bryanrasmussen 3y agothe phishing attempt from the url that looks like it comes from your bank can also have exploits to attack your browser, other than getting you to enter your credit card details.
- loxdalen 3y agoI would be worried about CSRF and other potential exploits..