New issue
Advanced search Search tips

Issue 815128 link

Starred by 2 users

Issue metadata

Status: WontFix
Owner:
Closed: May 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , iOS , Chrome , Mac , Fuchsia
Pri: 2
Type: Bug-Security



Sign in to add a comment

Security: Address bar suggests homograph lookalikes for IP addresses

Reported by mich...@mahemoff.com, Feb 23 2018

Issue description

VULNERABILITY DETAILS
Google search auto-completes "192.168" to "fake IP number" domains such as 192.168.l.l and 192.168.l.254 (those being lowercase "L" instead of the expected "1"). (See screenshot 192.168.autocomplete.png)

This could be exploited to perform a phishing attempt. The owner of a domain such as 192.168.l.l could inspect the requester's IP and other metadata and predict they are resident within a certain company's intranet, and then present the company's login page to steal their credentials.

Even without guessing anything about the client, they could present a generic company login page or mimic a router's login page. By accepting the suggestion of 192.168.l.l and typing "login", we can see routers such as dlink being suggested to continue the phrase (See screenshot 192.168.login.autocomplete.png). Fortunately this will lead to a Google search where the top term is _not_ that domain, but in some cases, it could be.

A probable fix is to disallow autocompletion for valid IP numbers, or at least commonly used prefixes such as "192.168" and "0.0". Arguably Google search should also make this change.

VERSION
Chrome Version: 62.0.3202.75 stable
Operating System: Ubuntu 17.10

REPRODUCTION CASE
Screenshot is attached, obtained by typing "192.168." into Chrome address bar

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
N/A
 
192.168.autocomplete.png
7.3 KB View Download
192.168.login.autocomplete.png
13.0 KB View Download
Components: UI>Browser>Omnibox
Labels: Security_Impact-Stable OS-Android OS-Chrome OS-Fuchsia OS-iOS OS-Linux OS-Mac OS-Windows
Status: Untriaged (was: Unconfirmed)
Summary: Security: Address bar suggests homograph lookalikes for IP addresses (was: Security: Address bar autocompletes IP numbers (vulnerable to phishing attempts))
Interesting, thanks for the report. This is an interesting issue, but it's worth noting that "192.168.l.l" is not a value that can be registered in the public DNS. As a consequence, navigating to such a suggestion results in a Google Search rather than navigation to the would-be attacker's website.
Good point. It might be okay unless endings like .ll and .lo become available, which aren't presently.

Google search is still a risk though if the same domain ends on top, which hopefully Google search would prevent.

Comment 3 by wfh@chromium.org, Feb 23 2018

Labels: Security_Severity-Low
Owner: pkasting@chromium.org
Status: Assigned (was: Untriaged)
this seems like severity Low but perhaps we can land a defence-in-depth feature as suggested by the reporter (perhaps do not autocomplete from search ip addresses). Assigning to pkasting@ to triage for omnibox.
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 24 2018

Labels: Pri-2
Owner: ----
Status: Untriaged (was: Assigned)
I'm not on omnibox anymore, their regular triage procedure should deal with this.
(That said, I think this should be WontFix.  I don't think we should take any client-side action against this.)
Owner: k...@chromium.org
Status: Assigned (was: Untriaged)
krb@ - perhaps you could suggest an owner for this, or just close as wontfix. Thanks.

Comment 8 by k...@chromium.org, May 3 2018

Status: WontFix (was: Assigned)
From what I recall about the discussion around this, we will close it WontFix. For some explanation, there is little we can do beyond what we are doing. For example, a far worse attack would be to grab the domain goog1e.com (if that can even be done.) The protection against it is that the security chip will not show "Google Inc".
Project Member

Comment 9 by sheriffbot@chromium.org, Aug 10

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment