New phishing method called the Inception Bar on Chrome for Mobile

    New phishing method called the Inception Bar on Chrome for Mobile

    New phishing method called the Inception Bar on Chrome for Mobile


    Last Updated: 29 Apr 2019 at 09:20

    Welcome to HSBC, the world’s seventh-largest bank! Of course, the page you’re reading isn’t actually hosted on hsbc.com; it’s hosted on jameshfisher.com. But when you visit this page on Chrome for mobile and scroll a little way, the page is able to display itself as hsbc.com - and worse, the page is able to jail you in this fake browser! In this post I show how the attack works, then suggest some ways Chrome can fix this vulnerability, then finally show you how to get out if you’re still stuck here. But first, the proof:



    In Chrome for mobile, when the user scrolls down, the browser hides the URL bar, and hands the URL bar’s screen space to the web page. Because the user associates this screen space with “trustworthy browser UI”, a phishing site can then use it to pose as a different site, by displaying its own fake URL bar - the inception bar!

    This is bad, but it gets worse. Normally, when the user scrolls up, Chrome will re-display the true URL bar. But we can trick Chrome so that it never re-displays the true URL bar! Once Chrome hides the URL bar, we move the entire page content into a “scroll jail” - that is, a new element with overflow:scroll. Then the user thinks they’re scrolling up in the page, but in fact they’re only scrolling up in the scroll jail! Like a dream in Inception, the user believes they’re in their own browser, but they’re actually in a browser within their browser. Here’s a video of the hack in use:



    Read more: The inception bar: a new phishing method

    Brink's Avatar Posted By: Brink
    29 Apr 2019


  1. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #1

    Your article pops up a download on my PC... d33wubrki0I68.cloudfront.net.
      My Computer


  2. Posts : 68,893
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #2

    Faith said:
    Your article pops up a download on my PC... d33wubrki0I68.cloudfront.net.
    Odd.

    The image and video in the article are linked from cloudfront.net.

    Do you see this below with the image and video for the news article?

    New phishing method called the Inception Bar on Chrome for Mobile-article.jpg
      My Computers


  3. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #3

    The last image is blank. I'm guessing that's where the download comes up to me. It's 462kB from cloudfront.net. I'm using Edge.
      My Computer


  4. Posts : 68,893
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #4

    Faith said:
    The last image is blank. I'm guessing that's where the download comes up to me. It's 462kB from cloudfront.net. I'm using Edge.
    That would be the embedded video.

    I just checked in Edge, and it's showing and playing for me. Do you have any extensions installed that could be an issue with it?

    Does it show properly in another browser for you?
      My Computers


  5. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #5

    Nope. All default and stock. I thought it was a virus first. Everytime I get in here that video wants to download. I don't use any other browsers. Does anyone else sees this or is it just me?
      My Computer


  6. Posts : 3,105
    W10 Pro + W10 Preview
       #6

    Reading your article bring up the following....
    Attached Thumbnails Attached Thumbnails New phishing method called the Inception Bar on Chrome for Mobile-phish.jpg  
      My Computers


  7. Posts : 68,893
    64-bit Windows 11 Pro for Workstations
    Thread Starter
       #7

    I've removed the embedded video to stop that. I'm not sure why it would prompt to download the video though.

    Do you get the prompt at the news article source?
      My Computers


  8. Posts : 1,560
    Windows 10 Home 20H2 64-bit
       #8

    The video plays normal at the source, so it's only here where it prompts a download. Weird. I'm glad it was just the video and not a virus or something.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 10 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 10" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 15:13.
Find Us




Windows 10 Forums