注册并分享邀请链接,可获得视频播放与邀请奖励。

IT Guy
@T3chFalcon
Privacy Researcher. Check out my Articles 🥺. DM For Collabs & Partnerships. Founder @PhishCore - Human risk intelligence & Phishing simulation platform.
加入 November 2022
512 正在关注    45.5K 粉丝
Browser-in-the-browser. BitB. when you click sign in with Google on a website. A popup appears that looks exactly like a real Chrome window correct Google URL in the address bar, correct design everything. You type your credentials. They go to the attacker. But there's no real window. it's a simulation. built with HTML, CSS, and JavaScript inside the existing webpage. The URL bar is an image. The padlock is an image. The entire "browser window" is a div element rendered on top of the page you're already on. It was first demonstrated by a researcher mr.d0x(@mrd0x) in 2022. But it's now appearing in real attacks. Steam gaming accounts. Microsoft 365. Facebook. It's now packaged into phishing-as-a-service kits, making it available to anyone. It's hard to spot because the URL looks correct, and the window looks like it came from your OS. Your eyes have been trained to trust these things... the one thing that catches it: try to drag the popup window outside the browser. a real browser window moves freely. a BitB popup stops at the edge of the browser. it can't leave. Also: password managers don't autofill BitB windows. if your password manager doesn't offer to fill in your credentials, something is wrong.
显示更多
0
1
117
33
转发到社区