New issue
Advanced search Search tips

Issue 791018 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Dec 2017
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

Scareware with fullscreen and tiny popup, hang chrome, disturb mouse

Reported by bau...@gmail.com, Dec 1 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.70 Safari/537.36

Steps to reproduce the problem:
Google add big regression since it autorise fullscreen without permission. and never add a real popup blocker.

browse this: http://www.support.microsoft770571yfrmsrbchs9670.com.s3-website.eu-central-1.amazonaws.com/index.html

What is the expected behavior?
request to add site to exception list for FULLSCREEN,
and block all popup.
not analyse how it can disturb mouse (high cpu,graphics..)

What went wrong?
site enter fullscreen, read MP3 to call one phone number.
If not clic immediatly to ESC and close (example, search to copy URL to report this badpage @amazonaws ..)
Press ESC can't access to menu to close tab. one tiny popup stay in bottom righ (see it with more website now; it can open new fullscreen page after more second)
very difficult to clic in tab to close, not respond, and popup appear to close. Hard to go in the popup, mouse hang...

How many use call number? because can't close it, or not see must press ESC to exitfullscreen ?
to believe that Google encourages this practice by allowing the passage in full screen

Did this work before? Yes 

Chrome version: 63.0.3239.70  Channel: beta
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version: 

Why not just enable again the list exception for fullscreen, perhaps prefilled (google.com,youtube,...).
and same to block popup (all popup)or open all popup in new tab.
 
Status: Untriaged (was: Unconfirmed)
Summary: Scareware with fullscreen and tiny popup, hang chrome, disturb mouse (was: badware with fullscreen and tiny popup,hang chrome, disturb mouse)
There doesn't seem to be anything novel here, it's the typical set of malicious stuff including fake prompts, a fake cursor, etc. The tab closes reliably when hitting Leave on the onbeforeunload dialog shown after clicking the "X".

Comment 2 by bau...@gmail.com, Dec 1 2017

search to copy URL first after exit fullscreen, popup open, can't access to it, mouse block.
https://youtu.be/Dl7mqrLAoQU
https://youtu.be/6Z23Qax8yG0

Status: WontFix (was: Untriaged)
Thanks for the report. It looks like the site is already down and based on elawrence's investigation in #1 it doesn't seem like there is any action to take.
Project Member

Comment 4 by sheriffbot@chromium.org, Mar 10 2018

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment