New issue
Advanced search Search tips

Issue 900997 link

Starred by 2 users

Issue metadata

Status: Assigned
Owner:
Cc:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 2
Type: Bug



Sign in to add a comment

abuse technique: redirect to re-prompt for notifications

Project Member Reported by ellyjo...@chromium.org, Nov 1

Issue description

Observed on <http://eveplanets.com/eve/planet/set?planets_set=Barren%2CGas%2CIce%2COceanic%2CStorm%2CTemperate%2CLava%2CPlasma>:

1) The site pops up a fake recaptcha-like dialog, with the characteristic "I'm not a robot" checkbox
2) Clicking this "checkbox" spawns a popup, which displays a static image with the text "Type allow to prove you're not a robot", and which requests notification permission. This popup is on some origin (like http://a000.sketchy.site).
3) Clicking the X on the permission prompt causes the site to redirect you to http://a001.sketchy.site, which behaves identically and displays a new prompt
4) Clicking that X causes a redirect to http://a002.sketchy.site... and so on.

I reloaded the site and it does not behave the same way on a reload, so perhaps this came from a compromised ad network or similar.



 
Cc: csharrison@chromium.org
Labels: abuse
Labels: -abuse Hotlist-Abusive

Sign in to add a comment