Closed Bug 1596189 Opened 5 years ago Closed 5 years ago

Website opens popups in fullscreen and tricks user into installing add-on

Categories

(Toolkit :: Add-ons Manager, defect, P3)

70 Branch
defect

Tracking

()

RESOLVED DUPLICATE of bug 1432856

People

(Reporter: uskolor, Unassigned)

References

(Blocks 2 open bugs)

Details

Attachments

(2 files)

Attached image website.jpg (deleted) —

User Agent: Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:70.0) Gecko/20100101 Firefox/70.0

Steps to reproduce:

Hello I would like ask why my Firefox is vulnerable for that website .I have install plugin .
http://mns07.xyz/ww/

Actual results:

Website do not allow my go I have install plugin .If click the website made full screen

http://mns07.xyz/ww/

Expected results:

I should normally left website but I can't

404 Not Found for that url.

Flags: needinfo?(iiiiiikolor)

Because you respond was later .Probably owner remove this website .I wanted show you how Firefox is valuable .

Now is too later .

Flags: needinfo?(iiiiiikolor)

Hello I would like ask why my Firefox is vulnerable for that website .I have install plugin .

I think it is a deceptive picture to guide you download and install a malicious software. No more worry.

I find yo website where is the same

http://ewch5.xyz/ww/

Attached file http _ewch5.xyz_ww_.html (deleted) —

source of this website !!

I can't move or back from this website .

(In reply to iiiiikolor@gmail.com from comment #4)

I find yo website where is the same

http://ewch5.xyz/ww/

Press Esc key work for me.

This need to move to a better component, I guess.

Component: Untriaged → Security
Blocks: eviltraps

This bypassed our patch for Bug 1412561 by opening a popup and requesting the addon installation there.

The phishing site will most likely not stay online for very long. I've created a copy of the site but stripped out all the malicious code. You can try it out here: https://eviltrap.site/trap/fullscreen-addon-popup/
To exit simply close the popup and press the Esc key.

Yes I understand you .I can go out of this website .But this is real example how Firefox is able beat,hit but some website .YOU want to be the best Browser .Then listen me .Make Firefox stronger and any of this website will effected of our Browser.

Status: UNCONFIRMED → NEW
Ever confirmed: true
Summary: Firefox is vulnerable for that website → Website opens popups in fullscreen and tricks user into installing add-on

The priority flag is not set for this bug.
:wleung, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(wleung)

Moving to Add-ons Manager, since this is mostly about the add-on installation in fullscreen.

Component: Security → Add-ons Manager
Flags: needinfo?(wleung)
Product: Firefox → Toolkit

The priority flag is not set for this bug.
:jimm, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(jmathies)
Flags: needinfo?(jmathies)
Whiteboard: webext?

The priority flag is not set for this bug.
:jimm, could you have a look please?

For more information, please visit auto_nag documentation.

Flags: needinfo?(jmathies)
Flags: needinfo?(jmathies)
Priority: -- → P3
Whiteboard: webext?

This should be fixed now that we leave fullscreen when a website opens a popup.

Should be resolved in Nightly.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → WORKSFORME

So, this is a dupe of bug 1432856? This would be fixed by https://hg.mozilla.org/mozilla-central/rev/10fde12558b7cf7fb1f2849d8b2bdbf3b5b196c9. I suggest just opening open the other bug.

The comment 9 case WFM in Fx72 which does not have the patch for bug 1432856. Was there a separate change where doorhangers kill fullscreen, too?

(In reply to Daniel Veditz [:dveditz] from comment #18)

The comment 9 case WFM in Fx72 which does not have the patch for bug 1432856. Was there a separate change where doorhangers kill fullscreen, too?

I've just tested this again with Firefox 72 on Ubuntu 19.10. The website stays in fullscreen for me with the popup + doorhanger on top.

Addon install permission doorhangers do not kill fullscreen, they are blocked/denied in fullscreen. There is Bug 1412561 for permission prompts, but I don't think that includes the addon prompts.

Status: RESOLVED → REOPENED
Resolution: WORKSFORME → ---
Status: REOPENED → RESOLVED
Closed: 5 years ago5 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: