How script kiddies can hijack your browser to steal your password
arstechnica.com
arstechnica.com
I might have fallen for this before. Can't say for sure. Change all the things!
I agree that it does seem a touch unlikely to work in the real world. However, I think a scammer with a touch of ingenuity, creativity, and programming knowledge could probably construct a realistic enough scenario to fool many people.
Because the exploit pages are lists of leaked passwords, or cc#s. So to check if their password has been leaked they would naturally search for their password.
This is just a very slick implementation of the old "enter your credit card number to see if it's been stolen" technique, except the end-users don't realize that they've given anything away.
Here's an analogy: you get a phone call from someone telling you that your bank account has been hijacked and you need to visit your local branch right away to fix it. So you drive to your bank, enter, and you go talk to a bank employee. As he sits at a computer he asks you for your bank account number, home address, and social security number. After typing them in and hitting a few buttons he tells you that your account has actually not been hijacked and you're safe, so you head home and go watch tv. Meanwhile, what actually happened is that you didn't realize that it was a bank holiday and con-men had broken into the bank and dressed up as bank employees to trick you into giving out your personal information.
There is a special place in hell for people who override PgUp/PgDown or the arrow keys in their webpages.
Except for game developers, maps developers, in-browser document editors, presentation viewers, etc. The web isn't just hypertext any more, and part of making the browser a powerful platform is having features that could be misused.
Do any major browsers have a setting to disable overriding default keyboard shortcuts
I don't know about that. When I'm using a web-based word processor or spreadsheet I want CMD+s to save the document I'm working on instead of bringing up the "Save Web Page As" dialog....If you're having this problem, I hear Common Sense 2013 is a great browser security package.
The trick is to convince someone to try finding something sensitive on the page. This might be done by showing a long list of 'leaked' passwords or social-security-numbers.
Even without explicit prompting, some people might Ctrl-F search for their own, with a false confidence that a local search isn't shared with the page.
Except, what if you posted a page of compromised passwords or other data? Then someone might go to that page and search for their own secret information, to see if it had been leaked. They wouldn't even think twice about this because normally the information in a search box is secure, and known only to the browser. But if a site creates an html based search box that is hooked into ctrl-F then the user might divulge their secret information without even knowing.
The problem here is that browsers allow overiding ctrl-f and almost no users realize this is possible. It's not just a human problem, it's also a browser design problem. Browser makers have trained their users to trust that pressing ctrl-f will pull up a find dialog, it's as much their fault as it is user's fault.