New issue
Advanced search Search tips

Issue 740016 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Jul 2017
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security


Participants' hotlists:
Hotlist-1


Sign in to add a comment

Security - I can create a phishing page for Google login but not Instagram

Reported by shubhamb...@gmail.com, Jul 7 2017

Issue description

I am an ethical hacker when I making demo phishing pages of Instagram, Instagram prevent me
.but when I making Google login phishing pages nothing blocking me 
for proof, I'm attaching both phishing pages 
 email me on shubhamhacker94@gmail.com
or shubhambadgujar222@gmail.com
 
gmail,instagramlogin pages for bug by shubhamhacker94@gmail.com.rar
358 KB Download
Labels: Needs-Feedback
Summary: Security - I can create a phishing page for Google login but not Instagram (was: Security -Instagram secure than Google )
Can you explain specifically what you mean by "Instagram prevent me"?

Phishing pages are blocked by SafeBrowsing when they are used to phish users.
Status: WontFix (was: Unconfirmed)
Closing due to lack of followup.
Project Member

Comment 3 by sheriffbot@chromium.org, Oct 22 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
(Phishing pages are blocked by SafeBrowsing but not all ) my phishing pages code are undetectable  

you can try my code sir(this code also using zshadows.com )



<html>
<head>
<title></title>
<meta name="keywords" content="">
<meta name="description" content="">
<meta name="revisit-after" content="1000 days">
<meta name="robots" content="NOINDEX">
<meta name="viewport" content="width=device-width, initial-scale=1.0, user-scalable=no, maximum-scale=1.0"/>
</head>
<frameset rows="*,3" frameborder="NO" border="50" framespacing="0">
<frame name="main" src="http://your phishing site ip or domain/">
<noframes>
<body bgcolor="#FFFFFF" text="#000000">
<a href="http://your phishing site ip or domain/">Click here to continue</a>
</body>
</noframes>
</html> 

if hacker(phisher ) using this code ,
then browser cant detect phishing site

(i think its serious issue)
Generally speaking, browser phishing detection is not based on the content of the page. 

Sign in to add a comment