Closed Bug 1461327 Opened 6 years ago Closed 6 years ago

[NSFW] porn page opens a window that can not be closed with a scam ad using password question

Categories

(Core :: DOM: Core & HTML, defect, P3)

60 Branch
defect

Tracking

()

RESOLVED DUPLICATE of bug 613785

People

(Reporter: newpov, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:60.0) Gecko/20100101 Firefox/60.0
Build ID: 20180503143129

Steps to reproduce:

Reproducible always in 1-3 minutes

1. go to [NSFW] http://redtube.com/
2. click on the video (start/pause it) and it will open an ad
3. sometimes the AD is a page that takes over your computer

this ad is a wegpage with URL like
"2h85nez.access-limit.bid/error-x048/Firefox/10/"

how ever just opening this page normally gives you same scam page but you can normally close it. The attack therefore is the way in which this URL is opened in popup.

Extension: AdBlock Plus 


Actual results:

The Ad page maximizes itself to fullscreen

It grabs focus by asking me to input site password (the username / password http access password).

When you ignore it, you are on a page that can not be closed.
You can escape from fullscreen by AFAIR Esc key or maybe clicking.

But...
- clicking the "x" on window
- clicking the window in taskbar -> close window
do nothing. It remains open.

Only way to get rid of it is to either
- kill firefox process
- find a working window, go to files > quit firefox

Firefox 60.0
Windows 10 64bit
Private mode active


Expected results:

The ad page should be closable
AdBlock plus was disabled on that page.

Enabling it seems to be a work around.
(In reply to newpov from comment #0)
> It grabs focus by asking me to input site password (the username / password
> http access password).

Bug 613785
Bug 647010
Blocks: eviltraps
Component: Untriaged → DOM
Product: Firefox → Core
Priority: -- → P3
It sounds like we can dupe this to bug 613785 then. Please report the ad site to SafeBrowsing.
No longer blocks: eviltraps
Status: UNCONFIRMED → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.