註冊並分享邀請連結,可獲得影片播放與邀請獎勵。

IT Guy
@T3chFalcon
Privacy Researcher. Check out my Articles 🥺. DM For Collabs & Partnerships. Founder @PhishCore - Human risk intelligence & Phishing simulation platform.
加入 November 2022
512 正在關注    45.5K 粉絲
Browser-in-the-browser. BitB. when you click sign in with Google on a website. A popup appears that looks exactly like a real Chrome window correct Google URL in the address bar, correct design everything. You type your credentials. They go to the attacker. But there's no real window. it's a simulation. built with HTML, CSS, and JavaScript inside the existing webpage. The URL bar is an image. The padlock is an image. The entire "browser window" is a div element rendered on top of the page you're already on. It was first demonstrated by a researcher mr.d0x(@mrd0x) in 2022. But it's now appearing in real attacks. Steam gaming accounts. Microsoft 365. Facebook. It's now packaged into phishing-as-a-service kits, making it available to anyone. It's hard to spot because the URL looks correct, and the window looks like it came from your OS. Your eyes have been trained to trust these things... the one thing that catches it: try to drag the popup window outside the browser. a real browser window moves freely. a BitB popup stops at the edge of the browser. it can't leave. Also: password managers don't autofill BitB windows. if your password manager doesn't offer to fill in your credentials, something is wrong.
顯示更多
0
1
117
33
轉發到社區