aboutsummaryrefslogtreecommitdiffstats
path: root/app/scripts/lib/is-phish.js
diff options
context:
space:
mode:
authorDan Finlay <dan@danfinlay.com>2017-07-27 07:46:59 +0800
committerDan Finlay <dan@danfinlay.com>2017-07-27 07:46:59 +0800
commit6675241fa9a69d286df2b18a2ad35baa69da116b (patch)
tree25f6fc5361b3d7fc21badeb363ed46fefb92baf4 /app/scripts/lib/is-phish.js
parent8b1726cc550d4a5b142a2a525ce6b94713dc04e0 (diff)
parente3b5bb2052d59afbf9c2761af883de719261062e (diff)
downloadtangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar.gz
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar.bz2
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar.lz
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar.xz
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.tar.zst
tangerine-wallet-browser-6675241fa9a69d286df2b18a2ad35baa69da116b.zip
Merge branch 'master' into i1805-LiveBlacklistUpdating
Diffstat (limited to 'app/scripts/lib/is-phish.js')
-rw-r--r--app/scripts/lib/is-phish.js38
1 files changed, 38 insertions, 0 deletions
diff --git a/app/scripts/lib/is-phish.js b/app/scripts/lib/is-phish.js
new file mode 100644
index 000000000..68c09e4ac
--- /dev/null
+++ b/app/scripts/lib/is-phish.js
@@ -0,0 +1,38 @@
+const levenshtein = require('fast-levenshtein')
+const blacklistedMetaMaskDomains = ['metamask.com']
+let blacklistedDomains = require('etheraddresslookup/blacklists/domains.json').concat(blacklistedMetaMaskDomains)
+const whitelistedMetaMaskDomains = ['metamask.io', 'www.metamask.io']
+const whitelistedDomains = require('etheraddresslookup/whitelists/domains.json').concat(whitelistedMetaMaskDomains)
+const LEVENSHTEIN_TOLERANCE = 4
+const LEVENSHTEIN_CHECKS = ['myetherwallet', 'myetheroll', 'ledgerwallet', 'metamask']
+
+
+// credit to @sogoiii and @409H for their help!
+// Return a boolean on whether or not a phish is detected.
+function isPhish({ hostname, updatedBlacklist = null }) {
+ var strCurrentTab = hostname
+
+ // check if the domain is part of the whitelist.
+ if (whitelistedDomains && whitelistedDomains.includes(strCurrentTab)) { return false }
+
+ // Allow updating of blacklist:
+ if (updatedBlacklist) {
+ blacklistedDomains = blacklistedDomains.concat(updatedBlacklist)
+ }
+
+ // check if the domain is part of the blacklist.
+ const isBlacklisted = blacklistedDomains && blacklistedDomains.includes(strCurrentTab)
+
+ // check for similar values.
+ let levenshteinMatched = false
+ var levenshteinForm = strCurrentTab.replace(/\./g, '')
+ LEVENSHTEIN_CHECKS.forEach((element) => {
+ if (levenshtein.get(element, levenshteinForm) <= LEVENSHTEIN_TOLERANCE) {
+ levenshteinMatched = true
+ }
+ })
+
+ return isBlacklisted || levenshteinMatched
+}
+
+module.exports = isPhish