https://adisspr.mfcr.cz/ - Phishing site
Reported by
lubos.m...@gmail.com,
Oct 18 2016
|
||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.59 Safari/537.36 Steps to reproduce the problem: 1. Open https://adisspr.mfcr.cz/ 2. See that the page loads as if everything were OK. What is the expected behavior? The page should report the equivalent of https://support.mozilla.org/en-US/kb/troubleshoot-SEC_ERROR_UNKNOWN_ISSUER at Firefox What went wrong? The phishing page above – designed to steal sensitive tax data from the small businesses – plays with a wrong certificate and configurations. Firefox notices that the issuer is unknown and the page is unsafe; Chrome fails. Did this work before? N/A Chrome version: 54.0.2840.59 Channel: stable OS Version: 10.0 Flash Version: Shockwave Flash 23.0 r0 https://adisspr.mfcr.cz/ is basically a phishing page designed to fake the official country's electronic tax portal https://adisepo.mfcr.cz/
,
Oct 18 2016
Mozilla declined to certify the CA: https://bugzilla.mozilla.org/show_bug.cgi?id=643398
,
Oct 18 2016
The fact that the alleged phishing site shares the same ETLD+1 (mfcr.cz) and certificate issuer as the claimed legitimate site suggests that it is unlikely to be a phishing site.
,
Oct 19 2016
,
Oct 19 2016
Thanks for your answers. I didn't even realize it was possible for browsers to separately certify CAs.
,
Oct 20 2016
Tested the issue on windows-7, Mac-10.11.4 and Linux ubuntu-14.04 with using chrome stable version 54.0.2840.59 and latest canary 56.0.2895.0 with below steps 1.opened chrome 2.Navigated to page https://adisspr.mfcr.cz/ 3.could not observed any security warning which noticed in other browser(Firefox) This is non-regression issue observed from earlier version of chrome M-30.0.1550.0.Hence marking it as untraiged to get addressed
,
Oct 20 2016
elawrence -- Is the current warning state WAI? I do get an SSL error on Linux 54.0.2840.59. I can't tell if this is a phishing site -- it doesn't appear to ask for any credentials AFAIKT.
,
Oct 20 2016
+elawrence for prev comment
,
Oct 20 2016
The website asks for upload of files and various credentials etc. at http://adisspr.mfcr.cz/adistc/adis/idpr_pub/eet/eet_sluzby.faces where one can get by clicking at "ELEKTRONICKÁ EVIDENCE TRŽEB" on the main adisspr.mfcr.cz web page.
,
Oct 20 2016
@nparker re #8: Chrome uses the platform's Trusted Root store on Windows and Mac. On Linux, as far as I know, it ends up using NSS' root certificate database (also used by Firefox). So, yes, I'd expect this to show a cert error on Linux only.
,
Oct 20 2016
Given that both addresses are in the same IP block owned by "Ministerstvo financi", this is either a legitimate site or the most clever phish I've ever seen. Hostname: adisspr.mfcr.cz IP: 185.16.183.177 ISP: Ministerstvo financi Organization: Ministerstvo financi Hostname: adisepo.mfcr.cz IP: 185.16.183.158 ISP: Ministerstvo financi Organization: Ministerstvo financi
,
Oct 20 2016
It may be a legit site managed, but may be used for phishing other stuff. In either event, I suggest we WontFix/WAI this. - For the SafeBrowsing side, use the public information to find out why it was flagged for SB - For it not causing an SSL error on some platforms, that's also WAI The only thing which would be problematic is if the SSL error is masking the SafeBrowsing checking. That would be a bug.
,
Oct 20 2016
Re: #12: To clarify, this site is NOT blocked by Safe Browsing. The reporter suggested that it should be, on account of the fact that he saw an error page when navigating to the site in Firefox. Firefox is showing the error page because the root certificate is not in Firefox's trust store. We have no indication that the site in question is unsafe, but most of us neither speak Czech or have significant knowledge of the Czech tax authorities.
,
Oct 20 2016
Ah, I was basing this on the tag. In that case, I just suggest we close this WontFix/WAI.
,
Oct 20 2016
Changing to WontFix, as above. |
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by elawrence@chromium.org
, Oct 18 2016Labels: -Type-Bug-Security -Restrict-View-SecurityTeam Type-Bug
Owner: zbutler@chromium.org
Summary: https://adisspr.mfcr.cz/ - Phishing site (was: https://adisspr.mfcr.cz/)