Earlier quoted context omitted.
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.
Older school even -- instead of logging out of (real hardware) terminal sessions, exec a program which prints `login: ` and disables keyboard interrupts. Read peoples creds and store somewhere, then issue a 'wrong password' msg and exit, resulting in the real login message. People will just assume they made a typo and continue as if nothing happened. I've argued before for a genuine out-of-band independent display on…
The inception bar: a new phishing method
101–110 of 238 posts
Re: The inception bar: a new phishing method
#102Earlier quoted context omitted.
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.
ha I did a similar thing too. Except it was fake error messagebox and on Windows 3.1 (or might have even been 3.0?) It worked quite effectively on 3.x because you could just minimize progman.exe
Re: The inception bar: a new phishing method
#103"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…
I have an unquantified theory that the number of users that can distinguish between a Windows 7/8/10 dialog box that is presented directly by the operating system, versus as an image inside a browser coming from external http/https server, is diminishing greatly every year.
I couldn’t convince them that it was just a picture, and that I could fake it if I wanted to.
Re: The inception bar: a new phishing method
#104Using Firefox for android: if I open the page and scroll down, the address bar becomes invisible and the hsbc bar shows up. If I keep scrolling down, I just see hsbc. The moment I scroll up, the original address bar is shown, and even if I keep scrolling down, the bar does not disappear. Edit: it's happening kind of randomly. 1 time it happens, 3 times it doesn't...
Using Firefox Beta for Android v67.0b9, I see the hbsc address bar as a second address bar below the real one. It remains in place as I scroll, although a couple of times it disappeared. Also this version wouldn't fool me because it says I have 26 tabs open. I'm used to the infinity symbol there!
Re: The inception bar: a new phishing method
#105Interesting. iOS Safari seems to force the address bar to stay visible on this page.
Also the scrolling feels "weird". Kinda like when you're on an amp page (although I think they fixed that now).
Re: The inception bar: a new phishing method
#106Earlier quoted context omitted.
Older school even -- instead of logging out of (real hardware) terminal sessions, exec a program which prints `login: ` and disables keyboard interrupts. Read peoples creds and store somewhere, then issue a 'wrong password' msg and exit, resulting in the real login message. People will just assume they made a typo and continue as if nothing happened. I've argued before for a genuine out-of-band independent display on…
That's why Windows can be set to require Ctrl+Alt+Del before login as it can't be intercepted by a fake login screen.
Incidentally, this is why Face ID is strictly worse than Touch ID in my opinion.
Re: The inception bar: a new phishing method
#107Re: The inception bar: a new phishing method
#108I'm not doubting the concerns raised but the fake failed in many ways for me on my phone with the latest chrome. It didn't appear. Then when it did it appeared below the existing bar. But I guess you just need it to work often enough.
It's like the fake "Allow Notification" dialogs on some sites. They look off to pretty much anyone paying attention, but their target market probably isn't people paying attention
Re: The inception bar: a new phishing method
#109"Ceci n'est pas un UI." This specific example may be new, but the concept of fooling users with websites containing images of the system's own UI is not new --- for example, all the fake antivirus alert boxes. That had a relatively easy mitigation --- using non-default appearance on your system (e.g. an XP-style "you have a virus!" dialog box image would just look silly if you weren't using XP with the default theme)…
In high school we would screenshot the windows 98 desktop, make it the wallpaper, hide everything, and watch people fluster about.