This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

Phishing ...and Social Engineering

56 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

Phishers Use Wildcard DNS to Build Convincing Bait URLs
- http://news.netcraft.com/archives/2005/03/…_bait_urls.html
March 7, 2005
"Phishing operations have begun using DNS wildcards and URL encoding to create email links that display the URLs of legitimate banking sites, but send victims to spoof sites designed to steal their login details. A wildcard DNS record (*.example.com) will resolve all requests that are not matched by any other record. Wildcards are typically used to manage errant or mistyped e-mail addresses, but have been routinely abused by spammers. In recent weeks wildcard DNS settings have been used in a wave of phishing attacks on Barclays Bank, in which the "bait" email included URLs starting with barclays.co.uk, followed by a lengthy sequence of letters and symbols. Several examples:

-http://barclays.co.uk|snc9d8ynusktl2wpqxzn1anes89gi8z.dvdlinKs.at/pgcgc3p/
-http://barclays.co.uk|YJ3EMOHOqljQ8J5oW2ZKyTaRMQOahSWaxTrFTEQK9l9VVQj6jDtyq10d24r2h0bijh2
-http://barclays.co.uk|34fdcb4rvdnp9phxbahhvbs6l56a2uyx%2edivxmovies%2ea%74/41pvaw3/

The phishers use a wildcard DNS setting at a third-party redirection service (kickme.to) to construct the URLS. The wildcard allows the display of URLs beginning with "barclays.co.uk," which is followed by a portion of the URL which is encoded to obscure the actual destination domain. The redirector at kickme.to/has.it forwards to a Barclays spoof site hosted…in Moscow. The spoof loads a page from the actual Barclays site, and then launches a data collection form in a pop-up window from the Russian server…"

:rant2: :thumbdown:
FYI…

- http://www.informationweek.com/showArticle…cleID=160702186
April 13, 2005
"…There were 2,625 active phishing sites in February, growing at an average monthly rate of 26% since July, according to a recent report from the Anti-Phishing Working Group, a coalition of financial institutions, online retailers, Internet service providers, and law enforcement formed to prevent identity theft and fraud caused by phishing, pharming, and E-mail spoofing. In February, there were 13,141 new, unique phishing E-mail messages reported to the organization…"


:blink: :oops: :ph34r:
FYI…

Fraudsters deploy Botnets as DNS Servers to Sustain Phishing Attacks
- http://news.netcraft.com/archives/2005/05/…ng_attacks.html
May 4, 2005
"Botnets controlled by fraudsters are running their own DNS nameservers on compromised computers, complicating the task of shutting down malicious sites. The technique can keep phishing sites accessible longer by making the nameservers a widely distributed moving target amongst thousands of compromised machines within a bot network.
In recent days both the Internet Storm Center and DailyDave mailing list have received reports of botnets using rapidly-shifting DNS servers. The sophisticated new strategy makes it harder to target phishing sites at the nameserver level, which can be the most effective route to taking a malicious site offline. If fraudsters are able to compete effectively by deploying botnets as nameservers, additional emphasis will be placed upon the responsiveness of domain registrars…
Bot networks aggregate computers that have been compromised allowing them to be remotely directed by the attackers. Botnets are being used for a variety of scams, including spamming, phishing, sniffing network traffic for unencrypted passwords, and click fraud targeting Google's AdSense program. A March report found that at least 1 million compromised machines are being used in botnets."

:ph34r:
FYI…

Fraudsters seek to make phishing sites undetectable by content filters
- http://news.netcraft.com/archives/2005/05/…nt_filters.html
May 12, 2005
" More fraudsters are adopting new approaches in an effort to make phishing sites undetectable by common security measures such as firewalls and content filtering web proxies. By replacing some of the textual content on the phishing page with similar-looking images, fraudsters are making it much more difficult for automated systems to detect the presence of keywords such as "PayPal" and "credit card"…some of the page is made up from images, which are easily read by a human, but will be ignored by content filters which only process the text on the page…Because the content filters may not detect this page as being a PayPal phishing scam, it could slip through undetected, allowing the fraudster to harvest the credentials of thousands of PayPal customers…"

:ph34r:
FYI…

New phishing attack uses real ID hooks
- http://news.com.com/2102-7349_3-5706305.ht…g=st.util.print
May 15, 2005
"Security researchers are reporting a new brand of phishing attack that attempts to use stolen consumer data to rip off individual account holders at specific banks…phishing e-mails arrive at bank customers' in-boxes featuring accurate account information, including the customer's name, e-mail address and full account number. The messages are crafted to appear as if they have been sent by the banks in order to verify other account information, such as an ATM personal-identification number or a credit card CVD code, a series of digits printed on the back of most cards as an extra form of identification…
Cyota has already taken down several sites related to the personalized phishing schemes, but indicated that many more such sites have appeared since. The company is advising consumers to avoid sharing any financial information online without first verifying that a request for such data was sent for legitimate purposes…"

:ph34r:
FYI…

Phishing emails capable of automatic scripts!
- http://www.news.vu/en/living/education/050…ated-lure.shtml
May 19, 2005
"…Over the last two weeks, MessageLabs has monitored a small number of these dangerous new emails, which are capable of sidestepping the need for user intervention in phishing attacks. Users who only open maliciously constructed emails to be exposed to risk. These emails contain scripts that rewrite the host files of targeted machines. This means that next time a user attempts to access their online banking account they will be automatically redirected to a fraudulent website instead, enabling their log-in details to be stolen. So far, MessageLabs has only intercepted copies of emails targeting three Brazilian banks, but if the technique catches on it could have potentially serious consequences.
A defence is available. Providing surfers have Windows Scripting Host disabled they are not at risk from this particular type of phishing attack…"

Disabling Windows Script Host
- http://www.slipstick.com/outlook/wsh.htm#disable
(Updated Apr 26 2005)
"If you want to retain the ability to run scripts when necessary, but avoid running them automatically, a good strategy is to change the default action for scripts so that they open in Notepad when you double-click them, rather than executing as scripts…step-by-step instructions…"

How to disable or remove the Windows Scripting Host
- http://www.symantec.com/avcenter/venc/data…pt.hosting.html
(January 16, 2005)

:ph34r:
FYI…

Hostile Consumer Profiling - You Are Exposed
- http://home.businesswire.com/portal/site/m…iewID=news_view
May 23, 2005
"…"Hostile Profiling" is easily accomplished using two new types of attacks, registration attacks and password reminder attacks. These attacks exploit sites that employ e-mail addresses as user identifiers during the registration process or password reminding, allowing attackers to know whether a certain address belongs to a customer of such sites.
By automatically attacking hundreds of Web sites, spammers and phishers can generate a detailed consumer profile from any e-mail address, including the owner's place of residence, hobbies, political views, purchasing preferences and health information, and then use this information for targeted spamming and phishing attacks. Blue Security has found that a large majority of Web sites, including eight of the top 10 Web sites in the United States, are vulnerable to registration attacks and password reminder attacks. Some Web sites are already taking measures to protect themselves against such assaults by requiring billing information with each registration or asking the user to solve a graphical challenge…"
- http://www.bluesecurity.com/
"Armed with your email address alone, spammers and phishers know almost anything about you, including your place of residence, hobbies, political views, purchasing preferences or even the state of your health. Hostile Profiling is easily accomplished using two new types of attacks - Registration Attacks and Password Reminder Attacks… Research findings in full, together with instructions how to protect yourself from such attacks can be found in the hostile profiling whitepaper (PDF)…"
- http://download.bluesecurity.com/research/…leProfiling.pdf
(See: "Counter-measures" and "Protect Yourself")

EDIT/ADD:
- http://www.techweb.com/wire/security/163700240
May 23, 2005
"…Few sites use the simple techniques that can stymie such attacks. eBay seems to be one of them. When TechWeb tried the password reminder technique at eBay, and used the bogus address "[removed]," eBay responded with "eBay just sent your User ID to [removed]. Check your email to get your User ID." It didn't verify that the address was in use on the site or not…"

:ph34r:
FYI…

Another Web extortion scheme
- http://www.crn.com/showArticle.jhtml?articleID=163700484
May. 24, 2005
"Computer users already anxious about viruses and identity theft have new reason to worry: Hackers have found a way to lock up the electronic documents on your computer and then demand $200 over the Internet to get them back. Security researchers at San Diego-based Websense uncovered the unusual extortion plot when a corporate customer they would not identify fell victim to the infection, which encrypted files that included documents, photographs and spreadsheets. A ransom note left behind included an e-mail address, and the attacker using the address later demanded $200 for the digital keys to unlock the files. "This is equivalent to someone coming into your home, putting your valuables in a safe and not telling you the combination," said Oliver Friedrichs, a security manager for Symantec.
The FBI said the scheme, which appears isolated, was unlike other Internet extortion crimes. Leading security and antivirus firms this week were updating protective software for companies and consumers to guard against this type of attack, which experts dubbed "ransom-ware."
"This seems fully malicious," said Joe Stewart, a researcher at Chicago-based Lurhq Corp. who studied the attack software. Stewart managed to unlock the infected computer files without paying the extortion, but he worries that improved versions might be more difficult to overcome. Internet attacks commonly become more effective as they evolve over time as hackers learn to avoid the mistakes of earlier infections. "You would have to pay the guy, or law enforcement would have to get his key to unencrypt the files," Stewart said.
The latest danger adds to the risks facing beleaguered Internet users, who must increasingly deal with categories of threats that include spyware, viruses, worms, phishing e-mail fraud and denial of service attacks…"
- http://www.websensesecuritylabs.com/alerts…php?AlertID=194

:ph34r:
FYI…'not an "exploit", but it -will- help prevent them:

(Netcraft) Anti-Phishing Toolbar Now Available For Firefox
- http://www.techweb.com/wire/security/163700999
May 25, 2005
"U.K.-based Web security firm Netcraft on Wednesday released a Firefox version of the anti-phishing toolbar that's been available for Microsoft's Internet Explorer since December 2004. The toolbar, which installs as a Firefox extension, or plug-in, automatically blocks suspected phishing sites identified by other users and verified by Netcraft. The company's database of Web site information is also used to display several attributes of any visited site, including its country location, longevity, and popularity. That information can be used to gauge possible risky sites, since most phishing sites are short-lived, and often hosted in countries like China and Russia. Netcraft claims that the toolbar has blocked more than 7,000 phishing sites since it debuted. The free Firefox toolbar can be downloaded from Netscraft's site"
- http://toolbar.netcraft.com/install

;)
FYI…

New Phishing Attacks Eliminate Need for Target Web Site
- http://news.netcraft.com/archives/2005/06/…t_web_site.html
June 24, 2005
"New phishing attacks with data collection forms embedded directly in the electronic mails received by victims are inducing victims to send their financial details directly to the phishers via mail rather than through a specially constructed web site mimicking that of the financial institution.
The HTML emails masquerade as a security check on a PayPal account, with the subject "Validate Your Informations by Email" (sic). The message asks recipients to fill in an HTML form, which includes fields for the user's credit card details, date of birth, Social Security number and mother's maiden name. "Completing all of the checklist items will automatically restore your account access," the email advises. Clicking on "Submit to Secure Server" mails the form's contents to a free email account at Yahoo, using a CGI script hosted by a Brazilian hosting reseller at The Planet… The scam takes advantage of known insecurity in Formmail, a widely-used form-to-mail Perl script initially written in 1995. In early 2001, spammers began using Formmail to anonymously deliver massive volumes of spam, taking advantage of the Formmail's failure to restrict access to the script. Most hosting providers have replaced the original Formmail with customized versions or secure replacement scripts like the NMS Project…"

:ph34r:
FYI…

- http://www-1.ibm.com/press/PressServletFor…wContacts$
June 30, 2005
"…Key findings from IBM's May Global Business Security Index include:

* Phishing explodes: Phishing incidents reached a peak point in January 2005 and then dropped again. In May, phishing attacks exceeded anything previously recorded, increasing by 226 percent.
* Viruses grew: In May 1 in 32.2 (3.12 percent of all email) emails contained some form of virus or trojan attack, a significant increase over the past month of 33 percent. To combat malwares such as Sober and Mytob, and other variants of these viruses, IBM advises organizations to keep antivirus signatures up-to-date, and to keep current with Windows patches.
* Spam levels off: In May, 68.7 percent of inbound email traffic contained some form of spam. This figure has remained relatively unchanged over the past three months; During the same period, the proportion of unwanted email originating from known botnets and open proxy sources has dropped by a further 1.7 percent for the second month running.
* Application hacking exploits: Ninety percent of target systems are exploited because of Web application hacking. Financial applications and online shopping accounts are popular targets. Top Web application vulnerabilities include: invalidated input; cross-site scripting flaws; injection flaws; broken authentication and session management; and improper error handling.
* Malware scam: a malware hijacking threat was discovered operating from the host name iframeDOLLARS.biz. This website attempted to recruit partner websites to host a variety of malicious code to exploit Internet Explorer browsers. A successful exploit would result in numerous trojans, backdoors and spyware installed on the client. IBM has been identifying the hosting ISPs, strongly recommending the malicious Web sites be removed.
* Educational institutions systems pharmed: In late May, after a long period of calm, IBM security analysts observed active exploitation of a Microsoft Library ASN.1 vulnerability. Correlating the signatures with other security events, IBM was able to determine that several attacking sources belonged to educational institutions, revealing that the attacking sources were compromised hosts, belonging to an Rbot network. IBM quickly notified customers and possibly infected institutions to address any outstanding issues.


"IT systems have become so crucial to today's business operations, work productivity, and customer service, that even a small disruption can have serious impact on business operations, and loss of data integrity or confidentiality can lose a customer base that took years to build"…"

:ph34r:
FYI…

Phishers Up Ante With 5x Spike In Trojans
- http://www.techweb.com/wire/security/165702797
July 15, 2005
"…Websense, a San Diego-based security company, has detected a "four- to five-fold increase in the number of Trojans during the last week of June and especially the first two weeks of July," said Dan Hubbard, Websense's senior director of security. "In July alone, we've seen more than a thousand different sites that are hosting this malicious code, and more than 100 unique Trojans," Hubbard added. The Trojan horses are either planting keyloggers on compromised systems, or retrieving downloaders that in turn install a keylogger, said Hubbard. All have the same goal: snatch usernames and passwords to specific online banking sites so that the criminals can empty accounts. "The keyloggers are going after a specific list of banks, and don't invoke themselves until or unless the user accesses the bank's Web site," said Hubbard. That list of banks, he noted, is hard-coded into the keylogger. Once in possession of the account access username and password, the keylogger then transmits the information back to the attacker(s), sometimes in an encrypted form using SSL (Secure Socket Layer). "Because it's using HTTPS, the traffic is undetectable," said Hubbard, another way that phishers are camouflaging their criminal acts. While the technique isn't new, it is seeing wider user by phishers.
The Trojan horses (and thus the keyloggers) are installed after a user naively surfs to a malicious site linked in an e-mail or instant message, said Hubbard – a now-standard tactic by hackers and phishers of all kinds. Those sites, which number in the hundreds, are hosted on free-of-charge U.S.- and U.K.-based Web hosting services, typically disguised as personal home pages, blogs, and home-made Web directories. The e-mails and IMs that entice users to these sites run the range from those claiming to be a message from an ISP or a company's IT department to others allegedly from friends sending electronic greeting cards, said Hubbard.
"They're using good old-fashioned social engineering," he said…"
- http://www.websensesecuritylabs.com/alerts…php?AlertID=238

:ph34r: