Security: Impossible to report long Phishing URL
Reported by
jourdain...@gmail.com,
May 1 2017
|
||||||
Issue description
,
May 1 2017
Thanks for the report! Data URIs are an interesting case for Phishing, and we've recently undertaken a number of measures to help users recognize their danger (including showing Not Secure in the security chip, and highlighting the protocol). In future versions of Chrome, we block top-level navigations to data URLs entirely. Having said that, we should ask the SafeBrowsing folks to robustify the https://safebrowsing.google.com/safebrowsing/report_phish/?hl=en page to ensure that it accepts URLs of any length that Chrome accepts (~2mb or something).
,
May 1 2017
,
May 1 2017
+meacer: data: URI phishing is now over, right? (Re #2)
,
May 1 2017
Yes, the blocking will hit stable in M60. Regarding the original report, I'm not sure submitting the data URL itself is going to help in terms of detection. I think SafeBrowsing uses the initiator of the navigation instead? jourdainpas@: If you happen to know the page that opened this data URL, you might want to submit that instead.
,
May 1 2017
In any case, this is not a security vulnerability per se, nor a bug in Chrome. It sounds like a potentially by-design limitation of the Safe Browsing URL intake service. Opening this bug up and assigning to noelutz to decide what, if anything, to do about the server-side issue.
,
May 2 2017
This is WAI. I'll create a bug to track the number of such errors we serve to make sure this isn't a trend.
,
May 3 2017
Thanks everyone, I'll close this out as WontFix since: 1) top level navigations to data URIs will be blocked in M60 2) WAI on the Safe Browsing side. :) |
||||||
►
Sign in to add a comment |
||||||
Comment 1 Deleted