New issue
Advanced search Search tips

Issue 693967 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Nov 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Spam site bypass anti spam anti flood meccanism, switching between normal alert, to chrome plugin install request, opening new window and hooking onbeforeunload

Reported by alessio....@gmail.com, Feb 19 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36

Steps to reproduce the problem:
1. Keep attention please
2. to this site: http://p9328ujeiw1.ru/umbryto/it/index.php?Repair
3. Try to exit without close chrome

What is the expected behavior?

What went wrong?
No way to shoutdown the page

Did this work before? N/A 

Chrome version: 56.0.2924.87  Channel: stable
OS Version: 10.0
Flash Version: Shockwave Flash 24.0 r0

I think it would be a regression of "plugin manager"; thx a lot

 

Comment 2 by raymes@chromium.org, Feb 20 2017

Cc: a...@chromium.org
Components: Platform>Extensions Blink>WindowDialog
Labels: Security_Severity-Medium Security_Impact-Stable
Owner: mea...@chromium.org
Status: Assigned (was: Unconfirmed)
Thanks for the report!

Hey meacer/avi: #1 is a great example of a horrible combination of modal prompts and extension install prompts that somehow combine in such a way that it's impossible to do anything other than install the extension or kill chrome. 

It's worth testing the link to see the behavior, just be careful not to add the extension. There may be existing bugs about this so we can de-dupe this if needed.

I reported the website to sbops. 
Project Member

Comment 3 by sheriffbot@chromium.org, Feb 21 2017

Labels: M-57
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 21 2017

Labels: -Pri-2 Pri-1

Comment 5 by mea...@chromium.org, Feb 23 2017

Both pages seem to be down.

@alessio.dimaria, raymes: Did you have a copy of the pages by any chance?

Comment 6 by mea...@chromium.org, Feb 28 2017

Status: WontFix (was: Assigned)
Ping :) I don't think there is much we can do without the POCs. I'm closing the bug as wontfix, but happy to reopen if you can provide details.

Did the attack involve the page opening fake install dialogs, then switching the buttons to trick the user to accept the dialog?
I'll post another link, 
That servers appears and disappears,
But please, there are many behaviours of redirected pages, and i don't know what there is in the http headers,

I'll use a proxy to give you a .dat

Thx

Found another url, same thing, please in resources look at "humir.png"
http://h12uhrj21.ru/tesliand/it/index.php?Repair
Traffic.dat
47.6 KB Download
Traffic Resources.tar
334 KB Download
Another link:
http://h12uhrj21.ru/tesliand/it/index.php?Repair


Traffic Resources.tar
334 KB Download
Traffic.dat
47.6 KB Download
Found another link:
http://h12uhrj21.ru/tesliand/it/index.php?Repair

If i attach files my comments appear as "Deleted"..?


Project Member

Comment 11 by sheriffbot@chromium.org, Jun 6 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Here all data about the session
Traffic Resources.tar
383 KB Download
You're crazy, i was not able to upload Details about this issue in last months for security restriction on this bug report.
Labels: -allpublic Restrict-View-SecurityTeam
Status: Assigned (was: WontFix)
@alessio.dimaria: The bug was automatically opened up by a bot. You should have been able to access the bug since you are the reporter. Was that not the case?
Sorry, looks like your comments #8, #9 and #10 were marked as spam which is why I didn't notice them. Not sure if that was the spam filter or someone else marked them as such.
Project Member

Comment 16 by sheriffbot@chromium.org, Jun 7 2017

Labels: -M-57 M-59
Project Member

Comment 17 by sheriffbot@chromium.org, Jun 21 2017

meacer: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 18 by sheriffbot@chromium.org, Jul 5 2017

meacer: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 19 by sheriffbot@chromium.org, Jul 26 2017

Labels: -M-59 M-60
Project Member

Comment 20 by sheriffbot@chromium.org, Sep 6 2017

Labels: -M-60 M-61
Project Member

Comment 21 by sheriffbot@chromium.org, Oct 18 2017

Labels: -M-61 M-62
Is there any work to do here any more? I know our behaviors have changed a bit around prompts in the last few releases.

Typically we track sites like these as abuse issues rather than security bugs, but this one is currently tagged at Medium severity without a working repro.
Status: WontFix (was: Assigned)
There are bunch of different things going on here:

1. The page tries to clickjack extension install dialog by first showing a fake prompt, then showing the real prompt with the buttons switched. This is being fixed in bug 394518 (we already have a delay on Windows before the user can accept the dialog)
2. The page steals focus by showing alerts. Avi has been doing a lot of work in this area:
- Tabs showing alert dialogs can now be killed
- There is an intent to deprecate and remove for alert() activating tabs (https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/5ia5klTZjwA)
3. The page uses inline install while in fullscreen mode. This was blocked in  bug 488143 , though there is still follow up work in bug 695266 and bug 734396.
4. There is an audio playing while inline install dialog is display. This is  bug 659724 .
5. Inline install dialogs should ideally be throttled. This is  bug 581763  and bug 697569.

Some of these have been fixed and others are already tracked, so I don't think there is anything left to do in this bug. As such I'm closing it.

Also note that most of these bugs were reported before this one, except bug 695266, bug 734396 and bug 697569. Bug 695266 and bug 734396 were filed as direct follow ups to  bug 488143 .

alessio.dimaria@: Please let me know if I missed anything.
Project Member

Comment 24 by sheriffbot@chromium.org, Feb 15 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment