Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

71–80 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#71

Earlier quoted context omitted.

The TLD registries are supposed to each have defined rules for IDN which can prohibit abuses and to police the use of your service. If you operate the registry for say, Switzerland, it makes sense to allow what Swiss and maybe German people would want, then forbid everything else. But if you operate .COM or .INFO or .FREE-MONEY or whatever, your goal isn't to help anybody it's to obtain the most money possible withou…

Ah, that is interesting, thank you.

Also apparently wrong.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#72

Earlier quoted context omitted.

I just tried it and… it redirects me to the actual page https://keepass.info/ That is weird. I don’t have mobile debugging set up, or I’d try and figure out what’s going on there.

Right now, using curl, [ķ]eepass.info redirects to xn--eepass-vbb.info and consequently that redirects to official domain keepass.info.

So it might be triggering on certain UAs

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#73

The root cause is alphabets/fonts with lookalike characters being permitted in security-critical contexts. Tracing further, it's the mindset that this is a valuable feature, and not a reckless risk, that is to blame. Browser designers should have been feverishly working to further disambiguate Il1O0, not add more risk by allowing a multitude of whole new alphabets!

It sucks but doing that would be unfair to the majority of the world not using the Latin alphabet.

Maybe restricting those characters to the relevant top level domains? At least you'd notice you're on ķeepass[.]lv

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#74
post #47

Earlier quoted context omitted.

The first "punycode attacks" were using letters that were completely indistinguishable from the "real" ones (e.g. by using Cyrillic letters). I guess the assumption is that the user would be able to identify any letters with diacritics (even if they're indistinguishable from specks of dust on your screen) and avoid them - after all, you wouldn't go to "göogle.com" either?

weird because the keepass example, on chrome + android, looks exactly like a regular k in the address bar.

>looks exactly like a regular k in the address bar.

Because there's a quick 302 redirect from "ķeepass.info" to "keepass.info" :

Chrome F12 Dev Tools network trace: https://imgur.com/a/vrxjsUV

Whether that redirect was there at the time of the Arstechnica article, I don't know.

EDIT ADD: around 12:57 UTC, the 302 redirect was changed to a Youtube video: https://imgur.com/a/TtLxafP

(Somebody is apparently having fun trolling the internet.)

ICANN lookup trivia says "ķeepass.info" domain was created 3 days ago:

  Domain Information
  Name: xn--eepass-vbb.info
  Internationalized Domain Name: ķeepass.info
  Registry Domain ID: a375f89abb384328a10460509f9f99f8-DONUTS
  Domain Status:
  clientTransferProhibited
  addPeriod
  Nameservers:
  leia.ns.cloudflare.com
  sevki.ns.cloudflare.com

  Dates
  Registry Expiration: 2024-10-16 10:21:45 UTC
  Updated: 2023-10-19 11:40:19 UTC
  Created: 2023-10-16 10:21:45 UTC

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#77
post #10

1) Use an ad blocker, always. 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? 3) IDN shouldn't be enabled by default.

> 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? Because advertisers usually want to send links to a tracker site of their own first so that they can verify if their numbers match up with what Google reports. No one trusts anyone in the advertising space, and for good reasons. Advertising has always been a space filled to the brim…

For one thing, Google search ads should not show users a domain different from the domain Google redirects directly to. If a website wants to track clicks, the URL they ask Google to send users to should not live on a different domain than the domain the user sees before clicking. Anything else invites impersonation like this, and makes Google complicit in undetectable phishing.

See previously, gilimp and https://fxtwitter.com/ericlaw/status/1712531148356661494.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#78

The root cause is alphabets/fonts with lookalike characters being permitted in security-critical contexts. Tracing further, it's the mindset that this is a valuable feature, and not a reckless risk, that is to blame. Browser designers should have been feverishly working to further disambiguate Il1O0, not add more risk by allowing a multitude of whole new alphabets!

When you're at a point where you're relying on a display name to make security-critical decisions, you've already lost.

Character substitutions like ķeepass or ƙeepass or keypass are at least possible to spot if you know the name of the product, but not the full URL.

But there are many ways to create lookalike domains that don't change the product name: https://keepass.org https://keepass.net https://keepass.info https://keepass.cx https://keepassxc.org https://keepass-info.net https://keepass-manager.com

Which of these is the correct one? (It's https://keepassxc.org of course, but just looking at the URL won't tell you that.)

The root cause is downloading software you see advertised on Google even though that does not in any way establish trustworthiness.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#79
post #53

Earlier quoted context omitted.

It's not xenophobic, it's just realistic. If you tried to run a fake, malware-laden website in a Western country you would eventually be shut down and prosecuted. These scams mostly fester in nations with weaker institutions, not just Eastern Europe but also China and India. Their authorities are simply not interested in preventing this kind of unlawful activity.

Can you somehow quantify it or is it your gut feeling? Any articles out there? I don't know if they catch small fish as in this example, it just isn't in the news. The bigger fish happens to be in the news, like shutting down international scam call center - 2 in LV, 1 in LT. Video from police cam if anyone wants to see smashing windows: https://www.vp.gov.lv/lv/jaunums/verieniga-starptautiska-ope... We are also bein…

At least for Russia itself there's plenty of articles about it. Here's one:

https://krebsonsecurity.com/2021/05/try-this-one-weird-trick...

> In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#80
Advertising intermediaries should be held partly liable for fraudulent adverts, or advertising should be aggressively de-anonymised, or maybe both. I'm not a fan of German-style "impressum" requirements for general publishing, but advertising is different in the way it aggressively inserts itself onto other sites in ways which (crucially) the user has no control over. Other than blocking all ads.

It ought to be possible to click on the corner of an ad and get the company number and business address of those responsible for it. "Overseas" adverts originating in different countries should be even more heavily checked, because if they're fraudulent then recourse is much harder even if they're not anonymous.

Post reply on HN