PhishPrint: Evading Phishing Detection Crawlers by Prior Profiling
Bhupendra Acharya, Phani Vadrevu
摘要
Security companies often use web crawlers to detect phishing and other social engineering attack websites. We built a novel, scalable, low-cost framework named PhishPrint to enable the evaluation of such web security crawlers against multiple cloaking attacks. PhishPrint is unique in that it completely avoids the use of any simulated phishing sites and blocklisting measurements. Instead, it uses web pages with benign content to profile security crawlers. We used PhishPrint to evaluate 23 security crawlers including highly ubiquitous services such as Google Safe Browsing and Microsoft Outlook e-mail scanners. Our 70-day evaluation found several previously unknown cloaking weaknesses across the crawler ecosystem. In particular, we show that all the crawlers' browsers are either not supporting advanced fingerprinting related web APIs (such as Canvas API) or are severely lacking in fingerprint diversity thus exposing them to new fingerprinting-based cloaking attacks. We confirmed the practical impact of our findings by deploying 20 evasive phishing web pages that exploit the found weaknesses. 18 of the pages managed to survive indefinitely despite aggressive self-reporting of the pages to all crawlers. We confirmed the specificity of these attack vectors with 1150 volunteers as well as 467K web users. We also proposed countermeasures that all crawlers should take up in terms of both their crawling and reporting infrastructure. We have relayed the found weaknesses to all entities through an elaborate vulnerability disclosure process that resulted in some remedial actions as well as multiple vulnerability rewards.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Conning the Crypto Conman: End-to-End Analysis of Cryptocurrency-based Technical Support ScamsBhupendra Acharya, Muhammad Saad, Antonio Emanuele Cinà, Lea Schönherr 等S&P 2024 · 被引用 26 次
- PhishDecloaker: Detecting CAPTCHA-cloaked Phishing Websites via Hybrid Vision-based Interactive ModelsXiwen Teoh, Yun Lin, Ruofan Liu, Zhiyong Huang 等USENIX Security 2024 · 被引用 13 次
- Pirates of Charity: Exploring Donation-based Abuses in Social Media PlatformsBhupendra Acharya, Dario Lazzaro, Antonio Emanuele Cinà, Thorsten HolzWWW 2025 · 被引用 8 次
- Rods with Laser Beams: Understanding Browser Fingerprinting on Phishing PagesIskander Sánchez-Rola, Leyla Bilge, Davide Balzarotti, Armin Buescher 等USENIX Security 2023
- Doubly Dangerous: Evading Phishing Reporting Systems by Leveraging Email Tracking TechniquesAnish Chand, Nick Nikiforakis, Phani VadrevuUSENIX Security 2025
它引用的顶会 Paper11
- Beauty and the Beast: Diverting Modern Web Browsers to Build Unique Browser FingerprintsPierre Laperdrix, Walter Rudametkin, Benoit BaudryS&P 2016 · 被引用 279 次
- (Cross-)Browser Fingerprinting via OS and Hardware Level FeaturesYinzhi Cao, Song Li, Erik WijmansNDSS 2017 · 被引用 199 次
- Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting BehaviorsUmar Iqbal, Steven Englehardt, Zubair ShafiqS&P 2021 · 被引用 143 次
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn 等S&P 2019 · 被引用 129 次
- FP-STALKER: Tracking Browser Fingerprint EvolutionsAntoine Vastel, Pierre Laperdrix, Walter Rudametkin, Romain RouvoyS&P 2018 · 被引用 117 次
相关 Paper
- CrawlPhish: Large-scale Analysis of Client-side Cloaking Techniques in PhishingPenghui Zhang, Adam Oest, Haehyun Cho, Zhibo Sun 等S&P 2021 · 被引用 1 次
- PhishTime: Continuous Longitudinal Measurement of the Effectiveness of Anti-phishing BlacklistsAdam Oest, Yeganeh Safaei, Penghui Zhang, Brad Wardman 等USENIX Security 2020
- 7 Days Later: Analyzing Phishing-Site Lifespan After DetectedKiho Lee, Kyungchan Lim, Hyoungshick Kim, Yonghwi Kwon 等WWW 2025 · 被引用 5 次
- Phish in Sheep's Clothing: Exploring the Authentication Pitfalls of Browser FingerprintingXu Lin, Panagiotis Ilia, Saumya Solanki, Jason PolakisUSENIX Security 2022
- Everyone is Different: Client-side Diversification for Defending Against Extension FingerprintingErik Trickel, Oleksii Starov, Alexandros Kapravelos, Nick Nikiforakis 等USENIX Security 2019 · 被引用 43 次
