New issue
Advanced search Search tips

Issue 789611 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security


Show other hotlists

Hotlists containing this issue:
XXX


Sign in to add a comment

After visiting a web site, Chrome redirects me to a random site

Reported by peter.ko...@gmail.com, Nov 29 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36

Steps to reproduce the problem:
1. In non-private mode, go to theice.info; Ice rink site is loaded (this is expected)
2. Visit 3dnews.ru
3. Try to go to theice.info; a random site is loaded (not what I expect)
4. Deleting Chrome user fixes the problem; however all user settings are lost

What is the expected behavior?
See above

What went wrong?
Something went wrong. 

Did this work before? N/A 

Chrome version: 62.0.3202.94  Channel: stable
OS Version: 10.0
Flash Version: n/a

User-specific profiles are not a good feature
 
Labels: Needs-Feedback
This is unlikely to be a bug in Chrome. The likely explanations are:

1. You have installed a malicious browser extension, or
2. The site has a malicious advertisement that redirects based on other criteria.

If you can reproduce this issue, can you attach a log file by following these steps? https://dev.chromium.org/for-testers/providing-network-details

Comment 2 by palmer@chromium.org, Nov 29 2017

Also, please give us a list of the extensions you have installed. You can see them by browsing to chrome://extensions/. Thank you!
1. No browser extensions are installed (I removed all of them). 
2. Deleting the Chrome user helps until next time I visit 3dnews.ru
3. Log file attached. The problem appears around line 2633 with 302 and redirect to a garbage site
chrome-net-export-log.json
697 KB View Download
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 29 2017

Cc: elawrence@chromium.org
Labels: -Needs-Feedback
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Hrm. I think you're referring to this:

1690: URL_REQUEST
http://theice.info/
t=3286 [st=   0]    URL_REQUEST_DELEGATE  [dt=0]
t=3286 [st=   0]   +URL_REQUEST_START_JOB  [dt=52]
                    --> load_flags = 37120 (MAIN_FRAME_DEPRECATED | MAYBE_USER_GESTURE | VERIFY_EV_CERT)
                    --> method = "GET"
                    --> url = "http://theice.info/"
t=3306 [st=  20]        HTTP_TRANSACTION_SEND_REQUEST_HEADERS
                        --> GET / HTTP/1.1
                            Host: theice.info
                            Connection: keep-alive
                            User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36
                            Upgrade-Insecure-Requests: 1
                            Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8
                            Accept-Encoding: gzip, deflate
                            Accept-Language: en-US,en;q=0.9,ru;q=0.8
t=3306 [st=  20]     -HTTP_TRANSACTION_SEND_REQUEST
t=3306 [st=  20]     +HTTP_TRANSACTION_READ_HEADERS  [dt=31]
t=3306 [st=  20]        HTTP_STREAM_PARSER_READ_HEADERS  [dt=31]
t=3337 [st=  51]        HTTP_TRANSACTION_READ_RESPONSE_HEADERS
                        --> HTTP/1.1 302 Found
                            Date: Wed, 29 Nov 2017 22:30:58 GMT
                            Server: Apache
                            Location: http://traffico-news.ru/108h4
                            Content-Length: 213
                            Keep-Alive: timeout=5
                            Connection: Keep-Alive
                            Content-Type: text/html; charset=iso-8859-1

...right?

Possibilities:

 1. The site in question is compromised and the server periodically redirects visitors to a different site, or
 2. There's an attacker on the network that is watching for non-encrypted HTTP requests and sending those requests to the other site

Neither of these scenarios reflects a bug in Chrome. Unfortunately, the certificate used by https://www.theice.info is invalid and thus you don't have a good way of connecting to the site securely to rule out a network-based attacker.
Labels: -Restrict-View-SecurityTeam allpublic
Status: WontFix (was: Unconfirmed)
I can reproduce this behavior from Texas, so this isn't a local network issue. This site appears to be compromised. 

If your request sends "ru" (Russian language) in your browser's Accept-Language, the site redirects to the unrelated site. If your Accept-Language does not include "ru", it sends you to the legitimate www site.
SiteCompromised.png
10.3 KB View Download
Yes, 302 redirect to traffico and then to another site.
The issue is isolated to Chrome: Edge on the same computer does not exhibit the behavior and if I remove the user profile the www.theice.info works fine until I visit 3dnews.ru.
 
Yes, the issue seems to be related to compromised www.theice.info site and presence of the Russian language. I can reproduce it from a REST client and removing the Russian language from the language list in Chrome fixes the redirect.
Visiting 3dnews.ru and answering "Never translate Russian" prompt adds the Russian language to the language list in Chrome and exposes the problem with the compromised site.
Thank you for quick responses!

Sign in to add a comment