Closed
Bug 302974
Opened 19 years ago
Closed 19 years ago
"I'm feeling lucky" search can be abused to trick users into fake sites
Categories
(Firefox :: Address Bar, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 263213
People
(Reporter: hjtoi-bugzilla, Unassigned)
Details
This was discussed on full-disclosure with summary Weird URL.
The Firefox feature that when you enter a non-URL on the URL bar it will do a
Google I'm Feeling Lucky search without notifying the user seems to have taken
some security conscious people by surprise.
This becomes a potential problem if someone is instructed to copy and paste a
URL that fools the user into thinking they are going to one site while Google in
fact routes them to a different location. Not a very likely scenario or big
threat, but worth thinking about.
For example, this URL (http://phrack;//gmail.com) will take you to
http://www.phrack.org/. Now imagine this with
http://duhgobbledygook;//bankofamerica.com where you are the number one hit for
"duhgobbledygook", and had created a page that looked just like BoA's page.
I think at a minimum there should be some information visible to the user when
the "I'm Feeling Lucky" search was activated. That is bug 275957.
But since something more might be done, filing this as a separate bug.
Reporter | ||
Comment 1•19 years ago
|
||
Removing the security-sensitive status since this was discussed on the public
full-disclosure list.
Group: security
Comment 2•19 years ago
|
||
Neither of your examples are at all convincing. The first one *looks* like
phrack, the second does not look like bankofamerica. In both cases when the user
gets where they are going the URL bar will clearly show the real site (unless
bug 264610 kicks in, but that's independent).
The problem isn't spoofing users, it's mystifying them as in bug 275957
Comment 3•19 years ago
|
||
examples match this bug.
*** This bug has been marked as a duplicate of 263213 ***
Status: NEW → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
You need to log in
before you can comment on or make changes to this bug.
Description
•