USENIX Security2021Top-tier venue
PhishPrint: Evading Phishing Detection Crawlers by Prior Profiling
Bhupendra Acharya, Phani Vadrevu
Abstract
Security companies often use web crawlers to detect phishing and other social engineering attack websites. We built a novel, scalable, low-cost framework named PhishPrint to enable the evaluation of such web security crawlers against multiple cloaking attacks. PhishPrint is unique in that it completely avoids the use of any simulated phishing sites and blocklisting measurements. Instead, it uses web pages with benign content to profile security crawlers. We used PhishPrint to evaluate 23 security crawlers including highly ubiquitous services such as Google Safe Browsing and Microsoft Outlook e-mail scanners. Our 70-day evaluation found several previously unknown cloaking weaknesses across the crawler ecosystem. In particular, we show that all the crawlers' browsers are either not supporting advanced fingerprinting related web APIs (such as Canvas API) or are severely lacking in fingerprint diversity thus exposing them to new fingerprinting-based cloaking attacks. We confirmed the practical impact of our findings by deploying 20 evasive phishing web pages that exploit the found weaknesses. 18 of the pages managed to survive indefinitely despite aggressive self-reporting of the pages to all crawlers. We confirmed the specificity of these attack vectors with 1150 volunteers as well as 467K web users. We also proposed countermeasures that all crawlers should take up in terms of both their crawling and reporting infrastructure. We have relayed the found weaknesses to all entities through an elaborate vulnerability disclosure process that resulted in some remedial actions as well as multiple vulnerability rewards.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 54339ea2-7d7e-433d-b882-1ec14768a2f2Cited by top-tier papers7
- Conning the Crypto Conman: End-to-End Analysis of Cryptocurrency-based Technical Support ScamsBhupendra Acharya, Muhammad Saad, Antonio Emanuele Cinà, Lea Schönherr et al.S&P 2024 · 26 citations
- PhishDecloaker: Detecting CAPTCHA-cloaked Phishing Websites via Hybrid Vision-based Interactive ModelsXiwen Teoh, Yun Lin, Ruofan Liu, Zhiyong Huang et al.USENIX Security 2024 · 13 citations
- Pirates of Charity: Exploring Donation-based Abuses in Social Media PlatformsBhupendra Acharya, Dario Lazzaro, Antonio Emanuele Cinà, Thorsten HolzWWW 2025 · 8 citations
- Rods with Laser Beams: Understanding Browser Fingerprinting on Phishing PagesIskander Sánchez-Rola, Leyla Bilge, Davide Balzarotti, Armin Buescher et al.USENIX Security 2023
- Doubly Dangerous: Evading Phishing Reporting Systems by Leveraging Email Tracking TechniquesAnish Chand, Nick Nikiforakis, Phani VadrevuUSENIX Security 2025
Builds on11
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 279 citations
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 199 citations
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 143 citations
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn et al.S&P 2019 · 129 citations
- FP-STALKER: Tracking Browser Fingerprint EvolutionsAntoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain RouvoyS&P 2018 · 117 citations
Related papers
- CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingPenghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun et al.S&P 2021 · 1 citation
- PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing BlacklistsAdam Oest, Yeganeh Safaei, Penghui Zhang, Brad Wardman et al.USENIX Security 2020
- 7 Days Later: Analyzing Phishing-Site Lifespan After DetectedKiho Lee, Kyungchan Lim, Hyoungshick Kim, Yonghwi Kwon et al.WWW 2025 · 5 citations
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
- Everyone is Different: Client-side Diversification for Defending Against Extension FingerprintingErik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis et al.USENIX Security 2019 · 43 citations
