Thứ Hai, Tháng Một 30, 2023
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z
No Result
View All Result
NATuts
No Result
View All Result
Home Tech

Hackers can use ‘Application Mode’ in Chromium browser’ to perform stealthy phishing attacks

7 Tháng Mười, 2022
in Tech
0
Hackers can use ‘Application Mode’ in Chromium browser’ to perform stealthy phishing attacks
585
SHARES
3.2k
VIEWS
Share on FacebookShare on Twitter

Các bài viết liên quan:

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022

Advanced Phishing Attacks

In a new phishing technique, it has been demonstrated that the Application Mode feature in Chromium-based web browsers can be abused to create “realistic deceptive desktop applications” .

Application Mode is designed to provide an original-like experience in such a way that the website is launched in a separate browser window, while also showing the site’s favorite icon and hiding the address bar.

According to security researcher mr.d0x – who also invented the in-browser (BitB) attack method earlier this year – a bad guy can take advantage of this behavior to use a number of tricks HTML/CSS and display a fake address bar on top of the window and fool users into giving up their credentials on fake login forms.

“Although this technique is more geared towards internal phishing, you can technically still use it in an external phishing scenario,” said mr.d0x. “You can distribute these rogue apps independently as files.”

This is achieved by setting up a phishing page with a fake address bar at the top and configuring the –app parameter to point to the phishing site hosting the page.

Advanced Phishing Attacks

On top of that, a phishing site controlled by an attacker can use JavaScript to perform more actions, such as closing a window as soon as a user enters credentials or resizing and positioning it to achieve the desired effect.

It should be noted that this mechanism works on other operating systems, such as macOS and Linux, making it a potential cross-platform threat. However, the success of the attack is predicted by the fact that the attacker already has access to the target’s machine.

That said, Google is removing support for Chrome apps in favor of Progressive Web Apps (PWA) and web standards technologies, and the feature is expected to be discontinued entirely in Chrome. 109 or later on Windows, macOS, and Linux.

In a statement shared with The Hacker News, the internet giant said that “the –app feature was deprecated before this study was published, and we are taking into account its potential for abuse when we I consider its future.”

“Users should be aware that running any file provided by an attacker is dangerous. Google Safe Browsing helps protect against unsafe files and websites. While Safe Browsing is enabled by default in Chrome, users may want to enable Advanced Protection to check the safety of your downloads to better warn you when a file could be dangerous. dangerous. “

This finding comes as new Trustwave SpiderLabs findings show that HTML piracy attacks are a common phenomenon, with .HTML (11.39%) and .HTM files (2.7%). The second most spammed attachment type after .JPG (25.29%).

Related Posts

Previous Post

Bai Tien Nha Trang – The beauty of paradise on Ngoc island

Next Post

30+ The most beautiful male worm hairstyle

Megusta

Megusta

Related Posts

5 Best Software to Stream Games

5 Best Software to Stream Games

2 Tháng Một, 2023
Top 10 CRM Software For Construction 

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
Instruction how to use OBS streaming software

Features, settings and how to use OBS streaming software through 9 simple steps

25 Tháng Mười Hai, 2022
What is Trans woman?  What is Transgender Women?

What is Trans woman? What is Transgender Women?

23 Tháng Mười Hai, 2022
Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

Christmas gift: Genuine Windows 10 Pro for only $6.63 and Office 2021 for $14.22

22 Tháng Mười Hai, 2022
How to get 50 free coins of SkyJoy App to redeem

How to get 50 free coins of SkyJoy App to redeem

21 Tháng Mười Hai, 2022
Load More
Next Post
30+ The most beautiful male worm hairstyle

30+ The most beautiful male worm hairstyle

Trả lời Hủy

Email của bạn sẽ không được hiển thị công khai. Các trường bắt buộc được đánh dấu *

Bài viết mới

How to get travel insurance
Đời sống

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly
Phần mềm

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023
5 Best Software to Stream Games
Software

5 Best Software to Stream Games

2 Tháng Một, 2023
IBM Bridge To Cloud For Power
Software

IBM Bridge To Cloud For Power- Everything You Should Know

2 Tháng Một, 2023
Top 10 CRM Software For Construction 
Tech

Top 10 CRM Software For Construction Enterprises All The Time

31 Tháng Mười Hai, 2022
What Is IBM Software
Software

What Is IBM Software? 4 Business Segments at IBM You Should Know

26 Tháng Mười Hai, 2022
W3Schools

Ads

Contact: [email protected]

DMCA.com Protection Status

Categories

  • Android
  • Cạm bẫy tâm lí
  • Chưa được phân loại
  • Đồ họa
  • Đời sống
  • Gen Z
  • Health
  • iOS
  • Kĩ năng mềm
  • News
  • Nhà mạng
  • Phần mềm
  • Phần mềm đồ họa
  • Review sách
  • Software
  • Tech
  • Thiết kế ảnh
  • Thiết kế video
  • Thủ thuật
  • Travel
  • Văn hóa Nam Bộ
  • Văn học
  • Window

Browse by Tag

ai là triệu phú android Apple browser Bullet Journal bản thân chai pin Chỉnh ảnh data domain download fshare game game show giả lập màu hosting IKEA ios khuyến mãi kinh doanh kiến thức kiểm tra pin messenger miễn phí mua sắm Máy ảnh mạng network nghệ thuật ngôn ngữ nhà Trần pin laptop quảng cáo tiếng anh trạng thái Trần Thủ Độ tên miền tắt hoạt động từ vựng video viettel window 10 word zalo Đơn giản

Recent News

How to get travel insurance

Guide on how to get travel insurance with 4 options

24 Tháng Một, 2023
Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

Software Asset Management for Websites: How to Keep Your Sites Running Smoothly

8 Tháng Một, 2023

Trang tin nóng hổi - vừa thổi vừa xem

No Result
View All Result
  • Home
  • Health
  • News
  • Software
  • Tech
  • Travel
  • Gen Z

Trang tin nóng hổi - vừa thổi vừa xem