Issue metadata
Sign in to add a comment
|
Spam site bypass anti spam anti flood meccanism, switching between normal alert, to chrome plugin install request, opening new window and hooking onbeforeunload
Reported by
alessio....@gmail.com,
Feb 19 2017
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36 Steps to reproduce the problem: 1. Keep attention please 2. to this site: http://p9328ujeiw1.ru/umbryto/it/index.php?Repair 3. Try to exit without close chrome What is the expected behavior? What went wrong? No way to shoutdown the page Did this work before? N/A Chrome version: 56.0.2924.87 Channel: stable OS Version: 10.0 Flash Version: Shockwave Flash 24.0 r0 I think it would be a regression of "plugin manager"; thx a lot
,
Feb 20 2017
Thanks for the report! Hey meacer/avi: #1 is a great example of a horrible combination of modal prompts and extension install prompts that somehow combine in such a way that it's impossible to do anything other than install the extension or kill chrome. It's worth testing the link to see the behavior, just be careful not to add the extension. There may be existing bugs about this so we can de-dupe this if needed. I reported the website to sbops.
,
Feb 21 2017
,
Feb 21 2017
,
Feb 23 2017
Both pages seem to be down. @alessio.dimaria, raymes: Did you have a copy of the pages by any chance?
,
Feb 28 2017
Ping :) I don't think there is much we can do without the POCs. I'm closing the bug as wontfix, but happy to reopen if you can provide details. Did the attack involve the page opening fake install dialogs, then switching the buttons to trick the user to accept the dialog?
,
Mar 3 2017
I'll post another link, That servers appears and disappears, But please, there are many behaviours of redirected pages, and i don't know what there is in the http headers, I'll use a proxy to give you a .dat Thx
,
Mar 12 2017
Found another url, same thing, please in resources look at "humir.png" http://h12uhrj21.ru/tesliand/it/index.php?Repair
,
Mar 12 2017
Another link: http://h12uhrj21.ru/tesliand/it/index.php?Repair
,
Mar 12 2017
Found another link: http://h12uhrj21.ru/tesliand/it/index.php?Repair If i attach files my comments appear as "Deleted"..?
,
Jun 6 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 6 2017
Here all data about the session
,
Jun 6 2017
You're crazy, i was not able to upload Details about this issue in last months for security restriction on this bug report.
,
Jun 6 2017
@alessio.dimaria: The bug was automatically opened up by a bot. You should have been able to access the bug since you are the reporter. Was that not the case?
,
Jun 6 2017
Sorry, looks like your comments #8, #9 and #10 were marked as spam which is why I didn't notice them. Not sure if that was the spam filter or someone else marked them as such.
,
Jun 7 2017
,
Jun 21 2017
meacer: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 5 2017
meacer: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 26 2017
,
Sep 6 2017
,
Oct 18 2017
,
Oct 24 2017
Is there any work to do here any more? I know our behaviors have changed a bit around prompts in the last few releases. Typically we track sites like these as abuse issues rather than security bugs, but this one is currently tagged at Medium severity without a working repro.
,
Nov 8 2017
There are bunch of different things going on here: 1. The page tries to clickjack extension install dialog by first showing a fake prompt, then showing the real prompt with the buttons switched. This is being fixed in bug 394518 (we already have a delay on Windows before the user can accept the dialog) 2. The page steals focus by showing alerts. Avi has been doing a lot of work in this area: - Tabs showing alert dialogs can now be killed - There is an intent to deprecate and remove for alert() activating tabs (https://groups.google.com/a/chromium.org/forum/#!topic/blink-dev/5ia5klTZjwA) 3. The page uses inline install while in fullscreen mode. This was blocked in bug 488143 , though there is still follow up work in bug 695266 and bug 734396. 4. There is an audio playing while inline install dialog is display. This is bug 659724 . 5. Inline install dialogs should ideally be throttled. This is bug 581763 and bug 697569. Some of these have been fixed and others are already tracked, so I don't think there is anything left to do in this bug. As such I'm closing it. Also note that most of these bugs were reported before this one, except bug 695266, bug 734396 and bug 697569. Bug 695266 and bug 734396 were filed as direct follow ups to bug 488143 . alessio.dimaria@: Please let me know if I missed anything.
,
Feb 15 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by alessio....@gmail.com
, Feb 20 2017