of Google's leading security experts, Ben Hawkes, warns cybercriminals using two 0-day iOS vulnerabilities in…
“We discovered a great hole in security of most popular mobile browsers. To our surprise, between 2017 and till the end of 2018 Google Chrome, Firefox and Safari did not show any notifications about websites from the black list, even with the enabled security settings that ensure protection from such resources” – reported researchers.
Issue involved not only browsers that are supported by Google Safe Browsing technology. It raised after transition on new mobile API where was optimized data consumption. As it turned out, API did not work as expected.
“At the same time, black list function was activated, so users expected that Internet-browser will notify them about fraudulent websites” – argued specialists.
Incorrect Google Safe Browsing work was discovered in the frameworks of PhishFarm research project that started in 2017.
During the research, specialists created 2380 fake authorization pages in PayPal service. Researchers realized in them mechanisms for bypassing browsers’ black lists and checked what time it took to transit them to black list (if they were transited at all).
Authors of the research notified Google about the issue and at the end of last year, it was fixed.
Read also: Google openly stored G Suite passwords for 14 years
Aside from Google Safe Browsing, specialists tested such technologies as Microsoft SmartScreen and mechanisms of adding websites to the blacklist as US-CERT, Anti-Phishing Working Group, PayPal, PhishTank, Netcraft, WebSense, McAfee and ESET.
Source: https://www.adamoest.com
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…
Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…
Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…
Themoneyminutes.com is a domain that tries to force you into subscribing to its browser notifications…
News-xcidizi.com is a domain that tries to trick you into clik to its browser notifications…
Everytraffic-flow.com is a domain that tries to trick you into subscribing to its browser notifications…
View Comments