Last week it was reported that Outlook app for Android, which is used by more…
The problem is that content of the address line can be faked.
“It was observed that the DuckDuckGo privacy browser ominibar can be spoofed by a crafted javascript page spoofing setInterval` function and reloading the URL in every 10 to 50 ms.”, — reported Dhiraj Mishra.
While real website duckduckgo.com automatically loads every 50 milliseconds, researcher managed to have reflection of the entirely different content in browser.
PoC-exploit can be seen below.
Internet-security specialists have good reasons to call such attacks to be the worst type of fishing, as if user cannot trust its own browsers’ address line, the things are bad.
Issue is still not fixed, though researcher reported about it via HackerOne platform in October 2018. After a long discussion, DuckDuckGo developers preferred to mark report on vulnerability as “informative”, paid a revenue to a researcher, but said that do not view bug as a serious vulnerability.
Source: https://securityaffairs.co
CmbLabs Virus - Details CmbLabs stands for a ransomware-type infection. CmbLabs was elaborated particularly to…
Yttnmx.co.in is a domain that tries to force you into subscribing to its browser notifications…
Starcat - General Info Starcat mean a ransomware-type infection. Starcat was elaborated particularly to encrypt…
PetyaX - Ransomware PetyaX stands for a ransomware-type infection. PetyaX was elaborated specifically to encrypt…
Fripolonishnity.co.in is a domain that tries to force you into subscribing to its browser notifications…
Hotbpekare.today is a site that tries to force you into clik to its browser notifications…