May 2017 Phishing 2-Step Verification
Reported by
markrose...@gmail.com,
May 31 2017
|
|||||||
Issue descriptionUserAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/603.2.5 (KHTML, like Gecko) Version/10.1.1 Safari/603.2.5 Steps to reproduce the problem: In April-May 2017 texts sent from numbers that start with "614-695-47..." have been associated with sending Google 2-step verification codes at the same time as 220-00 sent the same verification code: 614-695-4704, http://800notes.com/Phone.aspx/1-614-695-4704 614-695-4715, https://callername.com/61469547 614-695-4716, https://callername.com/61469547 614-695-4708, https://productforums.google.com/forum/#!topic/gmail/3hVJ4I0mjZM 614-695-4728, https://productforums.google.com/forum/#!topic/gmail/3hVJ4I0mjZM 614-695-4733, https://productforums.google.com/forum/#!topic/gmail/5DB3RJK7GxY 614-695-4735, https://productforums.google.com/forum/#!topic/gmail/5Qg10d_ucTo 614-695-4736, http://hyphenet.com/text-messages-asking-for-account-verification-codes-scam 614-695-4737, https://productforums.google.com/forum/#!topic/gmail/WWjr4XdS_hA 614-695-4751, http://www.okcaller.com/6146954751 and http://www.gettherecords.com/1/614-695-4751, https://callername.com/61469547 614-695-4756, https://productforums.google.com/forum/#!topic/gmail/3hVJ4I0mjZM 614-695-4761, https://callername.com/61469547 614-695-4782, https://productforums.google.com/forum/#!topic/gmail/-mQVSg4x798 614-695-4783, https://productforums.google.com/forum/#!topic/gmail/UDhowlJ6JrY 614-695-4793, http://www.okcaller.com/6146954793 and https://productforums.google.com/forum/#!topic/gmail/viVjbaUvFMA 614-695-4796, https://callername.com/61469547 614-695-4799, https://callername.com/61469547 614-695-4801, https://productforums.google.com/forum/#!topic/gmail/JFFqnfZ5rx0 614-695-4803, https://callername.com/61469547 614-695-6794, https://callername.com/61469547 When I open Chrome, type gmail.com in the url, hit enter, and then click Sign In, about 50% of the time the next page remembers my email address and auto-fills it in, and the other half of the time it doesn’t. Sometimes it remembers the email address but not the password. Sometimes it remembers the email address and the password. Sometimes it doesn’t remember the email address. Upon clicking Sign In, and finding it remember the email address and password, first it sends the verification code from 220-00. The next times the sign-in page remembers both the email address and password, it sends the same verification code from the 10 digit phone number. In the event of it remembering the email address and not the password, the user types in their password. What is the expected behavior? What went wrong? See entry above. Did this work before? N/A Chrome version: <Copy from: 'about:version'> Channel: n/a OS Version: OS X 10.10.5 Flash Version:
,
Jun 1 2017
Hey, So I think something malicious, clever, current, and widespread is happening, and I really don't know exactly how it's happening, but I think it should be investigated. I don't know if it's the browser, the sign-in page, my phone, or what. But today I googled and found more instances, with a wider range of numbers: 614-695-29##, Within the last 24 hours 12 marked unsafe, related to google verification code: http://www.okcaller.com/61469529 614-695-4728, https://productforums.google.com/forum/#!topic/gmail/156rqYeib0c 614-695-4782, http://spyoncaller.net/6146954782 614-695-32##, Within the last 2 days, 12 marked unsafe, related to google verification code: http://www.okcaller.com/61469532 614-695-4776, 18 marked unsafe in May 2017: http://www.okcaller.com/6146954776 The reason I think it's "phishing" is there are many reports of people experiencing this issue and losing access to all sorts of things, some including bank account attempts I believe. I haven't logged into gmail on my laptop for days now because my biological neural networks are telling me something's up. In chrome, I would do the following process about 30 times in a row, and get one of three results in a seemingly random sequence. Command N for a new window, gmail url, enter, the new sign-in page, and one of the three outcomes in the original post would occur. I compared the source code of the pages keeping track of whether chrome remembered my email address and/or password. At first I thought it was the nonce="" differences, cause one had + and / characters, but further investigation showed that wasn't a difference correlated to whether chrome remembered the email address. I also thought towards the end, the presence or absence of a hyphen in accounts.google.com\u0026v\u003d- was the difference, but seemingly not. Chrome is the entity that stores my passwords, so I thought it could be connected, and since this issue doesn't seem to fit into any category on the standard help pages, this forum seemed the best way to get a person to look into it. Furthermore, I don't even remember enabling two-step authentication, but I probably did since I have texts from the 220-00 number that date back months ago and vaguely remember doing so. It's not just that it's two messages but that one is from a 10-digit phone number that is marked suspicious or unsafe online in relation to this issue. How would the second number know the code? Traditional phishing would use social engineering to obtain the code, but if they know the code from when the 220-00 number sent it and are sending it, they wouldn't need that information. So what's left I think is when the user connects their email, password, code, and phone to sign in. It's tricky; I'm really not sure what's going on. But I think something's going on.
,
Jun 1 2017
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 1 2017
In the 2-Factor Phishing scenario, the attacker sends a message *asking you* to reply to a SMS message and provide the 2-Factor code that you received in another SMS message. In the scenario you've described in the original report, you're receiving two SMS messages from different numbers, both of which contain the same six digit code, and neither of these messages asks you to reply?
,
Jun 3 2017
Right, the text content is identical. I think only one text is triggered by the two step part. If it's the 10 digit number it uses the code from the last one google sent.
,
Jun 3 2017
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 6 2017
As far as I can tell, there is no Chrome-specific security issue here. Removing from the security queue (But keeping restricted for now).
,
Mar 21 2018
Mac triage: WontFix this. I don't know what's going on with the duplicate texts but the Chrome bug tracker is certainly the wrong place to track this issue. I'll forward this to Google security folks, though.
,
Jun 28 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by elawrence@chromium.org
, May 31 2017