New issue
Advanced search Search tips

Issue 668931 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Sneaky Redirect on Google Chrome to website with malicious Java Script trying to steal passwords

Reported by yuuta...@gmail.com, Nov 28 2016

Issue description

Hi, I'm trying to reach a real live person because this is a real problem and not one that can be fixed by the Help Forum.

Today I tried to look for a website (Dollheart.com) and did a Google search (dollheart) to try to find it.  The search results listed the correct website as the first choice and the URL given was the correct URL.  I clicked on the link and was passed through www.goodsellwholesaler[.]com which is trying to run a PHP program on s95.cnzz.com, and runs a very long and clearly malicious JavaScript program (original source over 1,500 lines, more than 26,800 lines when pretty-printed to be human-readable), then redirects to www.livefornight[.]com. (My husband Kennis discovered this when I complained to him about what had happened, as my husband has been working in Cyber Security and knew how to properly look into the two URLs I was redirected to.)  My husband said he saw that the PHP program was specifically trying to steal passwords including those for Google, FaceBook, Bank of America, LastPass, and many other popular websites and Password managers.  The malware is not on Dollheart.com, because if I type Dollheart.com directly into my browser address bar, I do not get redirected and the actual site doesn't contain malware, the problem is specifically "sneaky redirection" via Google Search.

Thank you in advance for your time,
Rachel Koldewyn (yuutafan@gmail.com)

 
Status: WontFix (was: Unconfirmed)
Hi,

Thanks for submitting this. I took a look, and it seems like this happens on browsers other than Chrome (including Firefox). I believe it actually is a problem with Dollheart.com, because when I look at the network requests, it is the dollheart.com website that is actually redirecting you (Chrome opens dollheart.com, but dollheart.com immediately tells Chrome to go somewhere else).

This indicates that the website itself may have been hacked - when it sees someone coming from a Google search, it takes you to the goodsellwholesaler website, but when people type Dollheart.com in directly, it doesn't and goes to the original site.

Can you contact the owners of the website to let them know this is happening? We can't actually do anything about this, because Chrome (and Google search) are simply doing what the website is telling us to - in this case, I'm quite sure the website is compromised and they need to try and fix this issue.
Project Member

Comment 2 by sheriffbot@chromium.org, Mar 6 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment