Issue metadata
Sign in to add a comment
|
After visiting a web site, Chrome redirects me to a random site
Reported by
peter.ko...@gmail.com,
Nov 29 2017
|
||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 Steps to reproduce the problem: 1. In non-private mode, go to theice.info; Ice rink site is loaded (this is expected) 2. Visit 3dnews.ru 3. Try to go to theice.info; a random site is loaded (not what I expect) 4. Deleting Chrome user fixes the problem; however all user settings are lost What is the expected behavior? See above What went wrong? Something went wrong. Did this work before? N/A Chrome version: 62.0.3202.94 Channel: stable OS Version: 10.0 Flash Version: n/a User-specific profiles are not a good feature
,
Nov 29 2017
Also, please give us a list of the extensions you have installed. You can see them by browsing to chrome://extensions/. Thank you!
,
Nov 29 2017
1. No browser extensions are installed (I removed all of them). 2. Deleting the Chrome user helps until next time I visit 3dnews.ru 3. Log file attached. The problem appears around line 2633 with 302 and redirect to a garbage site
,
Nov 29 2017
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" to the cc list and removing "Needs-Feedback" label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 29 2017
Hrm. I think you're referring to this: 1690: URL_REQUEST http://theice.info/ t=3286 [st= 0] URL_REQUEST_DELEGATE [dt=0] t=3286 [st= 0] +URL_REQUEST_START_JOB [dt=52] --> load_flags = 37120 (MAIN_FRAME_DEPRECATED | MAYBE_USER_GESTURE | VERIFY_EV_CERT) --> method = "GET" --> url = "http://theice.info/" t=3306 [st= 20] HTTP_TRANSACTION_SEND_REQUEST_HEADERS --> GET / HTTP/1.1 Host: theice.info Connection: keep-alive User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36 Upgrade-Insecure-Requests: 1 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,image/apng,*/*;q=0.8 Accept-Encoding: gzip, deflate Accept-Language: en-US,en;q=0.9,ru;q=0.8 t=3306 [st= 20] -HTTP_TRANSACTION_SEND_REQUEST t=3306 [st= 20] +HTTP_TRANSACTION_READ_HEADERS [dt=31] t=3306 [st= 20] HTTP_STREAM_PARSER_READ_HEADERS [dt=31] t=3337 [st= 51] HTTP_TRANSACTION_READ_RESPONSE_HEADERS --> HTTP/1.1 302 Found Date: Wed, 29 Nov 2017 22:30:58 GMT Server: Apache Location: http://traffico-news.ru/108h4 Content-Length: 213 Keep-Alive: timeout=5 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 ...right? Possibilities: 1. The site in question is compromised and the server periodically redirects visitors to a different site, or 2. There's an attacker on the network that is watching for non-encrypted HTTP requests and sending those requests to the other site Neither of these scenarios reflects a bug in Chrome. Unfortunately, the certificate used by https://www.theice.info is invalid and thus you don't have a good way of connecting to the site securely to rule out a network-based attacker.
,
Nov 29 2017
I can reproduce this behavior from Texas, so this isn't a local network issue. This site appears to be compromised. If your request sends "ru" (Russian language) in your browser's Accept-Language, the site redirects to the unrelated site. If your Accept-Language does not include "ru", it sends you to the legitimate www site.
,
Nov 29 2017
Yes, 302 redirect to traffico and then to another site. The issue is isolated to Chrome: Edge on the same computer does not exhibit the behavior and if I remove the user profile the www.theice.info works fine until I visit 3dnews.ru.
,
Nov 29 2017
Yes, the issue seems to be related to compromised www.theice.info site and presence of the Russian language. I can reproduce it from a REST client and removing the Russian language from the language list in Chrome fixes the redirect. Visiting 3dnews.ru and answering "Never translate Russian" prompt adds the Russian language to the language list in Chrome and exposes the problem with the compromised site. Thank you for quick responses! |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by elawrence@chromium.org
, Nov 29 2017