Slashdot Mirror


Download Bomb Trick Returns in Chrome -- Also Affects Firefox, Opera, Vivaldi and Brave (bleepingcomputer.com)

Catalin Cimpanu, writing for BleepingComputer: The release of Google Chrome 67 has reopened a "download bomb" bug that was exploited by tech support scammers last winter, and which had been fixed with the release of Chrome 65 in March 2018. Furthermore, the issue also appears to affect other browsers as well, such as Firefox, Vilvadi, Opera, and Brave, according to tests carried out by Bleeping Computer. The "download bomb" trick is a technique that involves initiating hundreds or thousands of downloads to freeze a browser on a specific page. Across the years, there have been multiple variations of download bombs, and they have often been used by tech support scammers to trap users on shady sites that tried to lure victims into calling a tech support number to have their browser unlocked. Over the winter, security researchers from Malwarebytes noticed a tech support scam campaign that employed a new "download bomb" technique to trap users on its shady sites.

34 of 78 comments (clear)

  1. bleepingcomputer -again-? by Anonymous Coward · · Score: 1

    I mean, if I wanted a bleepingcomputer RSS subscription I'd get one..

  2. I just don't need downloads to auto-initiate by ScentCone · · Score: 3, Insightful

    I've never seen the value of a page being able to spawn a download dialog without an affirmative click on a download link to the resource being fetched. Not that dumb people will be saved from themselves if there's something to click on ("Oh! It says to click on this - I guess I better click on it!"), but the "if your download doesn't start automatically, click here" language always seemed unnecessary. Perhaps I'm missing something on why a cruise-control file download should ever be supported?

    --
    Don't disappoint your bird dog. Go to the range.
    1. Re:I just don't need downloads to auto-initiate by smooth+wombat · · Score: 2

      Perhaps I'm missing something on why a cruise-control file download should ever be supported?

      Don't you know? It saves time! Having to move your mouse cursor a few inches here or there to click OK to begin a download is too time consuming. Think of all the time you waste every day having to manually click an acceptance button when you want to download a file.

      This is the future, old man. Auto download, whether you like it or not. You'll take this file if it has to be shoved down your throat.

      --
      We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    2. Re:I just don't need downloads to auto-initiate by Anonymous Coward · · Score: 5, Insightful

      Perhaps I'm missing something on why a cruise-control file download should ever be supported?

      It's quite simple, and quite stupid.

      Everyone wants to streamline the user experience so much so as to avoid confusing users with things like downloading and installing.

      So, as a result, everyone takes out the sensible controls which would otherwise prevent this shit, and things just happen automatically.

      Microsoft has been leading the charge of this stupidity for a long time now -- from hiding extensions, to deciding that Outlook would be helpful and run any scripts it finds, to the auto-run shit on CDs that Sony used to install rootkits.

      Increasingly, browsers are getting stupid and just say "hey, there's a script and some arbitrary code I know nothing about, let me just run that for you", so they create these issues themselves. No, sorry, I don't see the benefit in letting the dozens of embedded sites run code on my machine, because it's mostly just ads, analytics, trackers, and malware.

      The problem is if you don't have the knowledge to block this shit, it happens without your knowing it, and often to very bad outcomes. And, since the internet has become (even more of ) a steaming swamp of bad actors, then things like browsers just rush ahead and keep doing the same stupid shit.

      It's time to have browsers and other internet aware things be saying "why the fuck would I let you run scripts since I don't know who you are". But every time someone tries that, the ad companies screech and howl that their business model is in jeopardy. I don't fucking care about your business model, and since you're an ad company you can kiss my ass and fuck off.

      If you want to know why this stuff happens, it's because browsers try to dumb down the experience to the point that you have no idea you've just allowed 15 external sites to run scripts and whatever else they want.

    3. Re:I just don't need downloads to auto-initiate by thegarbz · · Score: 1

      Don't you know? It saves time!

      Really? Because the only pages that seem to auto-download anything do so with "Your download will begin shortly" followed by an advert.

    4. Re:I just don't need downloads to auto-initiate by The+MAZZTer · · Score: 1

      Well, the problem is some sites are configured such that an affirmative click would not be possible. This is mostly related to site which implement hotlink blocking.

      For example, let's say I don't want people hotlinking my downloads so I require the user to load a landing page first so they see they are on my site, and I am providing them with the file. When the page loads, I generate a unique download url for them that will only work once, so hotlinking is not possible. Then the page will redirect them to the link so they get their download.

      In your scenario, the browser would be redirected to the file, but then drop the connection once it sees its a file (you don't want to start downloading, after all) and asks the user if they really want to save it, providing the .EXE or .ZIP or whatever file name. Once you hit save the browser repeats its request, but now the server sees you are reusing a link and the hotlink block kicks in, and the browser downloads an error page to an .EXE or .ZIP name. Not very useful.

      Lots of free file hosting sites use this model so it's important browsers support it for users who use those sites.

      The current method Chrome uses, the file quietly downloads to your Downloads folder in the background while the user makes their choice. If they deny the download, the download is aborted and the file deleted. If it is accepted the download simply keeps going, having gotten a head start.

      Chrome will block multiple file downloads from a single user interaction outright. So it sounds like this is just a bug with that functionality failing to handle this extreme case. There is no need to break websites over it.

    5. Re:I just don't need downloads to auto-initiate by Eravnrekaree · · Score: 2

      They don't really *need* scripts to throw up an ad. A flat JPG would do perfectly fine. I'd be perfectly find with JPG ads and have defended these, but the scripts, the video garbage, i've lost my tolerance for it. The websites are ramming down all of these 100% CPU scripts and bandwidth hogging video down peoples throats and then they act surprised and so hurt when people install an ad blocker. It really pisses me off.

    6. Re:I just don't need downloads to auto-initiate by another_twilight · · Score: 1

      You might want to look at uMatrix (link for Chrome version). It does some of what you want (site specific handling of calls to different resources with a default that blocks external resources), but I don't think it allows you to substitute your own code.

      Probably my 'if you had to use just one ...' extension.

    7. Re:I just don't need downloads to auto-initiate by pots · · Score: 1

      Microsoft has been leading the charge of this stupidity for a long time now

      Now, let's be fair: Microsoft is pretty late to the party on this. Removing or hiding options from users is very much an Apple thing.

  3. Attack of the clones by DarkRookie · · Score: 1

    Not surprising that it works in those other browsers since they are all pretty much Chrome clones.

    --
    The millennial that doesn't like most of the stuff designed for millennials.
    1. Re:Attack of the clones by Oswald+McWeany · · Score: 1

      Not surprising that it works in those other browsers since they are all pretty much Chrome clones.

      Regardless, I'm sure all 10 people who use Brave are worried about this development.

      --
      "That's the way to do it" - Punch
    2. Re:Attack of the clones by war4peace · · Score: 1

      They're all cowards.

      --
      ...gis sdrawkcab (usually not responding to ACs; don't bother posting as AC)
    3. Re:Attack of the clones by CaptainDork · · Score: 2

      As each browser tries to grab market share, we experience the game of chromes.

      When asked which browsers do this, we reply, "Chrome is some."

      --
      It little behooves the best of us to comment on the rest of us.
    4. Re:Attack of the clones by TheFakeTimCook · · Score: 1

      Not surprising that it works in those other browsers since they are all pretty much Chrome clones.

      But you will note that Safari isn't on the list; so WebKit must not be affected.

    5. Re:Attack of the clones by Cro+Magnon · · Score: 1

      Not surprising that it works in those other browsers since they are all pretty much Chrome clones.

      Regardless, I'm sure all 10 people who use Brave are worried about this development.

      Yeah, both of them, assuming you're using binary.

      --
      Slow down, cowboy! It has been 4 hours since you last posted. You must wait another few hours.
  4. Yup, I've seen this. by lasermike026 · · Score: 1

    The web and browsers have gone mad. I like turning off javascript just to have a simple web experience.

    1. Re:Yup, I've seen this. by mujadaddy · · Score: 1

      I keep all cookies off (* scope uMatrix), and all 3rd-party everything-else off as well. It's better. If you keep all 1st-party JS off, most sites are utterly blank. At least when you allow the domain to do what it's trying to, you get a good value measure of whether the content is worth seeing, before you need to decide to check from where they want their 3rd-party scripts.

      Usually, though, I find there's nothing under the js-clusterfuck. Noise > Signal.

      --
      Populus vult decipi, ergo decipiatur...
      "Force shits upon Reason's back." - Poor Richard's Almanac
  5. Freeze the browser? by PPH · · Score: 1

    What is xkill?

    --
    Have gnu, will travel.
    1. Re:Freeze the browser? by PPH · · Score: 1

      I'd guess that most Windows users know what the equivalent utility is on their platform.

      --
      Have gnu, will travel.
    2. Re:Freeze the browser? by DontBeAMoran · · Score: 1

      There is no way in hell that 'most Windows users' are aware of things like processes. Not by a long shot.

      Fixed that for you.

      "Most Windows users" still think the "blue e icon" means "the Internet". And yes, they think the Web is the Internet.

      --
      #DeleteFacebook
    3. Re:Freeze the browser? by PPH · · Score: 1

      There is no way in hell that 'most Windows users'

      Then they aren't actually running Windows. They are staring at a bunch of hung apps. If you can't find the process manager in your sleep, you haven't actually logged in to a Windows machine.

      --
      Have gnu, will travel.
  6. But not Edge? by Kenja · · Score: 2

    Or do people just not care enough to exploit it on Microsofts browser?

    --

    "Have you ever thought about just turning off the TV, sitting down with your kids, and hitting them?"
    1. Re:But not Edge? by bobdehnhardt · · Score: 4, Funny

      Things that cause Edge to run poorly would be redundant.

    2. Re:But not Edge? by thegarbz · · Score: 2

      Why write an exploit for a system with no users?

    3. Re:But not Edge? by CaptainDork · · Score: 2

      Your's is the best post.

      As I was reading all the bullshit here, including my stuff, Edge never entered my mind.

      Wonder why that is?

      I'm a retired IT guy and family members occasionally ask, "In Chrome, how do I ..." or, "Is there a Firefox extension that ..."

      But never Edge.

      --
      It little behooves the best of us to comment on the rest of us.
    4. Re:But not Edge? by Locke2005 · · Score: 1

      Edge is currently the world's most popular browser to use for downloading Google Chrome! So basically, for every new Windows installation, it gets used once!

      --
      I've abandoned my search for truth; now I'm just looking for some useful delusions.
    5. Re:But not Edge? by gravewax · · Score: 1

      then explain Firefox being on the list?

    6. Re:But not Edge? by thegarbz · · Score: 1

      Nostalgia.

  7. Not ... by cascadingstylesheet · · Score: 1

    ... Palemoon?

  8. "Download bomb", indeed? by Rick+Schumann · · Score: 1

    Website uses Download Bomb; it's super-effective!

    Me: "WTF? What's your problem, Firefox?" Opens Task Manager, Ends Task on Firefox, re-launch Firefox; same thing happens on the same page. "Hmm, must be a fucked-up webpage, guess I won't go there." End Taks on Firefox again, re-launch again. Close the tab before it loads, go on to something else.

    ..where's the problem? People actually fall for this nonsense? Pathetic.

  9. Shady by duke_cheetah2003 · · Score: 1

    I love how the summary makes liberal usage of my favorite word to describe unscrupulous entities.

    SHADY AS FUCK!

  10. Sometimes it works by Locke2005 · · Score: 1

    I had to explain to my ex, "No, you don't call the phone number and give them your credit card number, you hit Ctrl-Alt-Delete, bring up Task Manager, and kill the browser process(es), idiot!" Of course, that assume the victim is running Windows (fairly safe assumption).

    --
    I've abandoned my search for truth; now I'm just looking for some useful delusions.
  11. Browsers suck by DMJC · · Score: 1

    I have a new computer running Linux and it'll quite often lock up when running Chrome. It only happens in Chrome. Such a crap browser, but I still prefer the web experience slightly more than Firefox so I live with the pain. Thank god for SSDs running at 1800mb/s.

  12. Comment removed by account_deleted · · Score: 1

    Comment removed based on user account deletion