Phishing with an in-browser remote desktop
mrd0x.com
mrd0x.com
Using VNC here is super clever. This means that the "automation" part of the phishing attack is actually a browser just like the user is using, so you can't fingerprint it. In fact, the victim is really typing in their password into a real Google login page, but the attacker is logging everything through VNC. It's going to be very hard for Google (or anyone else) to detect this.
The solution to this (like all phishing attacks), is still WebAuthn. However, many of us in security were hoping we could get by with bandaids like fingerprinting until WebAuthn was more widespread.
If we have the political capital to somehow get everyone on-board with changing their flow I really don't see why it should be webauthn. It's ultimately just a key stored somewhere controlled by the client presenting it, but with more red tape, pseudo-drm, and ewaste.
^ If you're in a high-security setting then go for it, but for the masses nah.
Would modern up-to-date browsers just see it as cross site and block it?
Wouldn't it still require sneaking in the VNC code to the site you want that user coming through via a pre-existing exploit chain or social engineering scheme?
By itself this seems negated by standard browser security. If youre using it at the end of some exploit chain it seems like there would be several other more effective and useful things to do from that chain like an invisible proxy mitm.
The outer browser is running on the user's machine, loading a page from the attacker's origin. That page makes no cross-site requests, but just establishes a websocket connection to the attacker's server (the data connection for the remote desktop protocol) and renders the remote desktop to the outer browser on a canvas.
The inner browser is running on the attacker's server, just configured to show no URL bar or other chrome. It has loaded the genuine login page of the target site completely normally.
The problem here, as with all phishing, is that humans are easily fooled. But machines aren't fooled about this at all. Just have the machines make this critical decision and the problem evaporates, use WebAuthn to do 2FA. This makes life easier for humans because it is no longer their responsibility to try to figure out if they're being phished, WebAuthn solves that, back to my game of Wordle.