The fake address bar is now used by phishing attackers, in order to trick users on Chrome for Android

The First Art Newspaper on the Net    Established in 1996 Wednesday, April 24, 2024


The fake address bar is now used by phishing attackers, in order to trick users on Chrome for Android



When you use Chrome for Android, it hides the URL bar in order to give the user much more screen space to browse the internet. After a web page has been loaded, Google Chrome on Android conceals information about the URL and expands the real estate space on the mobile phone screen, in order to show the actual content on the website. This feature, even though may be handy for users, can be exploited by phishing attackers in order to exploit users when they are browsing the internet. You can use PhishProtection.com and ProofPoint.com to protect yourself from phishing.

It has been already demonstrated by James Fisher in his blog post that, the content can easily be made very convincing as if it is hosted on the real and genuine website, along with the HTTPS sign and other features. The phishing attackers would be then waiting for the user to click a link in a message and then scrolling down, upon which the URL is hidden from the face of the user. This feature is non-existent on the Chrome for iOS, as Apple devices still show the original URL bar even during scrolling down. But in this case, the URL bar could be replaced by a fake URL bar which is already built into the web page of the phishing attacker’s website.

James Fisher also said that attackers can also mimic the design of the Google Chrome web browser as well. In this type of attack, there will be a padding element where the user will not be able to see the URL bar anymore, even if he or she scrolls up or down, which Chrome normally shows the URL bar. This is termed as ‘scroll jail’. Even though the user might think that he or she is scrolling up, in fact, he or she is scrolling up in ‘scroll jail’. The name of this attack has been named after the sci-fi movie named, Inception, starring Leonardo DiCaprio.

The ‘scroll jail’ will be like a dream in Inception. The user will think that they are browsing in Google Chrome, but actually, they’re within another browser within their own Google Chrome browser. Even though Google might not flag it as a security vulnerability, it not be the first time a Google feature that has been exploited by the scammers. It was last year as well, that Fisher founded that dots in between writing a Gmail address will still go to the owner of the original email address. This allowed Gmail accounts to be created by scammers in order to con Netflix account owners by adding payment card details to the scammer’s account. Phishing attacks like these can be avoided by using services from Cofense.

The reason behind this is that Gmail does not recognise the dots, even though other online services do recognise and allow the creation of accounts based on the dotted email accounts. The same was reported by ZDNet as well, as scammers used this trick to apply for fraudulent unemployment benefits and also file fake tax returns as well. Fisher does suggest Google Chrome could leave a small space at the top of the screen to show that the URL bar has collapsed.










Today's News

April 30, 2019

Rare Edouard Cortes painting appears at Rehs Galleries after 114 years

Lock of Leonardo's hair to go on show for first time

British Museum acquires Damien Hirst works

Sotheby's to offer the wardrobe of fabled film star Claudia Cardinale

'Boyz n the Hood' director John Singleton dead at 51

Woodstock 50 fest under threat as investor pulls out

Art world leader David Norman named Chairman of the Americas at Phillips

Crawling to extinction: Singapore turtle haven fights for life

National Portrait Gallery announces shortlist for BP Portrait Award 2019

A major exhibition by renowned Colombian artist Doris Salcedo opens at Irish Museum of Modern Art

Revamped Russian animation goes for global audiences

Buena Vista Social Club's Portuondo blows final round of kisses

Dallas Museum of Art appoints Assistant Curator of European Art

Gerry Judah's new work The Scroll unveiled on site in Sharjah to mark UNESCO World Book Capital launch

Ketterer Kunst announces highlights included in the 19th Century Art Auction

Petzel Gallery now represents New York-based artist Derek Fordjour

Photo London reveals ambitious development plans with announcement of new Director

Phillips announces highlights from May Photographs Auction

Exhibition at bo.lee gallery brings together a new body of work by Tomas Harker

Elmgreen & Dragset explore the idea of 'home' in new exhibition at SMK National Gallery of Denmark

GR Gallery opens a solo exhibition by Catalan artist Joan Cornella'

Lévy Gorvy opens an exhibition devoted to Warhol's feminine subjects

Jenny Gibbs and Helen Toomer to spearhead the IFPDA and Fine Art Print Fair's vibrant new chapter

Exhibition presents French drawings from the New Orleans Museum of Art

5 Typical Errors to Avoid When Starting to Use Manual Mode of Your Camera

How to Use Best Cordless Tire Inflators?

The fake address bar is now used by phishing attackers, in order to trick users on Chrome for Android




Museums, Exhibits, Artists, Milestones, Digital Art, Architecture, Photography,
Photographers, Special Photos, Special Reports, Featured Stories, Auctions, Art Fairs,
Anecdotes, Art Quiz, Education, Mythology, 3D Images, Last Week, .

 



Founder:
Ignacio Villarreal
(1941 - 2019)
Editor & Publisher: Jose Villarreal
Art Director: Juan José Sepúlveda Ramírez

Royalville Communications, Inc
produces:

ignaciovillarreal.org juncodelavega.com facundocabral-elfinal.org
Founder's Site. Hommage
to a Mexican poet.
Hommage
       

The First Art Newspaper on the Net. The Best Versions Of Ave Maria Song Junco de la Vega Site Ignacio Villarreal Site
Tell a Friend
Dear User, please complete the form below in order to recommend the Artdaily newsletter to someone you know.
Please complete all fields marked *.
Sending Mail
Sending Successful