Home »

Security Vulnerability with Google Chrome

2. September 2008 by thebeebs 6 Comments

Have you installed the new Google chrome? Make sure you’re careful with your application shortcuts because I just thought of a very easy way to Phish basic users.

  1. Wrap the Chrome browser installation in your own InstallShield.
  2. Create a Phising Mirror of Gmail or what ever site you want to Phish.
  3. Add Desktop Shortcuts to the InstallShield which link to.
    "C:\Documents and Settings\User\Local Settings\Application Data\Google\Chrome\Application\chrome.exe"  --app=http://login.live..yourfakehotmailwebsite.com
  4. Build your InstallShield.
  5. Stick a graphic on your website that says “Get Google Chrome Now” and link to your InstallShield build.

When the user install Google chrome from your link they'll get the browser but they will also find some helpful desktop links to their Hotmail/Gmail/Ebay account.

As the Apps mode in Chrome loads in full screen with NO URL BAR (What were they thinking?). The user will happily click on the desktop links thinking it's just a handy shortcut that their friends at Google installed, not knowing it's really a link to our phishing mirror of Gmail.

Currently rated 5.0 by 2 people

  • Currently 5/5 Stars.
  • 1
  • 2
  • 3
  • 4
  • 5

Comments

Add comment


(Will show your Gravatar icon)  

  Country flag

biuquote
  • Comment
  • Preview
Loading