The inception bar: a new phishing method
31–40 of 238 posts
Re: The inception bar: a new phishing method
#32The scroll jail didnt work for my firefox for android latest stable.
Re: The inception bar: a new phishing method
#33Re: The inception bar: a new phishing method
#34Using Firefox for android: if I open the page and scroll down, the address bar becomes invisible and the hsbc bar shows up. If I keep scrolling down, I just see hsbc. The moment I scroll up, the original address bar is shown, and even if I keep scrolling down, the bar does not disappear. Edit: it's happening kind of randomly. 1 time it happens, 3 times it doesn't...
Re: The inception bar: a new phishing method
#35I'm surprised that nobody included "clicking on the url bar in order to modify it" as a mitigation.
In principle, it's not a mitigation - I was just too lazy to forge an interactive URL bar! You could make one which acts just like the Chrome URL bar, but e.g. acts as a MITM.
But you could go to your own host and have your server sit in the middle. The user wouldn't be logged in, since cookies wouldn't be sent. But maybe they would login through your proxy.
Re: The inception bar: a new phishing method
#36Re: The inception bar: a new phishing method
#37An inception bar could include a fake refresh button, no?
Re: The inception bar: a new phishing method
#38Re: The inception bar: a new phishing method
#39Re: The inception bar: a new phishing method
#40Earlier quoted context omitted.
Just to be clear, you're referring to real Firefox address bar (pointing to TFA), not the fake Chrome address bar (pointing to hsbc.com). So yes, in this case Firefox has (accidentally?) somewhat thwarted this attack vector.
It certainly looks accidental. It hides on scroll on other pages but this one causes it to half hide and then it pops back up again.