republican-creole
Search:  

 
 
   News
newer
story category Gone Phishing
Scammers discover new tactic
(old news - 09:55AM Friday Mar 26 2004)
tags: security
As if pop-ups that pretend to be "system warnings" urging you to buy some product aren't bad enough, phishers apparently are getting in on the game. A fairly new trick, discussed in our scam busters and security forums, involves the removal of the address bar and replacing it with a faked image to give the impression you're at a legitimate site. Millers Miles, a UK based auction resource and scam guide, wrote a piece on the tactic earlier this month, including tips on how to avoid being taken for a ride. The Anti-Phishing Working Group reports phishing scams are up some 300% since January.

Related:
  1. 37% Of Malware Originates In U.S.
  2. Using PS3's To Forge Site Certificates
  3. PA Man Charged With Selling Hacked Cable Modems
  4. Wednesday Evening Links
  5. New Botnet Targets Routers, Dumb People
  6. FoxNews.com Serving Up Infected Ads?
  7. Uh, Mom? The Air Force Just Attacked Our PC
  8. T-Mobile Systems Hacked?
Forums » Gone Phishing
view: topics flat text 
Post a:

AnonProxy
Proxy of Anon
Premium
join:2001-05-12
ß

1 edit

FIRST!

Free howard stern, Pud Rules!

The sad part is, old people that bought their PC at WalMart fall for this stuff all the time.

rosco
Premium
join:2003-11-10
USA

1 edit

Re: FIRST!

This is very bad...but I am amazed that a trick this simple and fairly easy to do, hasn't been done before.

quanta
Premium
join:2002-05-07
Toronto, ON

Wow

Wow...that's clever, and a bit sad at the same time. Imagine if these scammers got REAL jobs.

Incidentally, the Mozilla and Firefox browsers have JavaScript controls that allow you to prevent webpages from hiding your status bar or location bar, nor move and resize windows.
--
Happy customer of TOROON08CGO | Silentblue.net
Canadian DSL Troubleshooting and Why Can't I Get It? FAQs

DHRacer
Fire Survivor

join:2000-10-10
Lake Arrowhead, CA
·Charter Pipeline
·Verizon west (ex G..


1 edit

Re: Wow

According the the Miller article, this all starts with a spoofed email...clicking on the spoofed email link causes IE to open, then close, then re-open with the spoofed address/status bar(s).

So, at the moment, it seems you could not accidetnally stumble on this kind of scam while simply websurfing, unless you fall for a spoofed email first.

So, it again comes down to teaching people that email is not always truthful, and to be skeptical of emails that have an urgent warning that you bought something or need to update your account, whatever...

It's a shame this kind of thing does not get TV news attention. Just a 2 minute blurb by a newscaster would reach enough people to help educate the masses. How many people would know enough to do the research online (besides us)?

Edit: The second spoof report says that this happened just surfing the web, now that's scary! And it reduces the faith I would have that any web site is what it claims to be without having to Source-check every page I go to. For that, I would stop using the web unless I hand type in every url I want (I already practically quit email). Seriously, Microsoft needs to start over from scratch with IE, or just buy up Mozilla and rebadge it (can anyone say Mosaic?).

lordfly

join:2000-10-12
Homestead, FL

Themes?

I guess this method would be obvious if you have themed your browser or customized the position of your address bar.

Still a clever way of getting the internet rookies.

shaner
Premium
join:2000-10-04
Calgary, AB

Re: Themes?

said by lordfly See Profile:
I guess this method would be obvious if you have themed your browser or customized the position of your address bar.

You mean HotBar is now a security feature? With all the same spyware.
sti3

join:2002-05-13
Chicago, IL

Re: Themes?

Does anyone have a URL of an example of this? I want to see how it looks in my browser.

quanta
Premium
join:2002-05-07
Toronto, ON

Actually, even if you changed your desktop colours (aka "3D Objects"), this would be a dead giveaway. Or if you used Microsoft's IE Toolbar Wallpaper Powertoy to put a wallpaper on your IE's toolbars.

Of course, 99% of all computer users never bother to change their defaults...
--
Happy customer of TOROON08CGO | Silentblue.net
Canadian DSL Troubleshooting and Why Can't I Get It? FAQs

Seven1

join:2002-07-24
Lexington, KY
·Insight Communicat..

IE is a piece of crap

I maintain the computer of a person that's not very technically inclined. After finding he had Bagle on his computer, even though he supposedly didn't download anything, I formatted his computer and installed Mozilla Firefox (I already use it) on it. I have a feeling that the ammount spyware, worms, and the like will be cut in half - at least.

Microsoft doesn't deserve to have the leading browser, the way they maintain it.

caesarv

join:1999-08-02
Santa Rosa, CA


1 edit

Re: IE is a piece of crap

While I won't argue with you, and while I do use Mozilla, it does appear that IE is much safer with the intro of XP Service Pack 2. The beta version does allow one to block all sorts of things. Of course it is just a matter of time before that gets defeated too.

lettcco

join:2003-12-04
Valencia, CA

another way to tell

since it's a static picture, if you click on the URL it shouldn't highlight or the prompt should not appear, right?

CCTVTech
Premium
join:2003-04-23
Phoenix, AZ
clubs:
·Integra Telecom
·Cox HSI
·Qwest.net
·GoDaddy Hosting

Re: another way to tell

said by lettcco See Profile:
since it's a static picture, if you click on the URL it shouldn't highlight or the prompt should not appear, right?

unless they used a javascript or something else that would act like the address bar.

Chris Guth
www.SeniorsLivingHealthy.com
Home of Tru Blue Pain Relief Cream
rlively

join:2000-09-24
Villa Rica, GA

»www.antiphishing.org/news/03-31-···Bar.html

It does so by automatically detecting the consumer's browser, and applying a custom JavaScript that replaces the look and feel of the Web address bar with an appropriately designed working fake.

You can even type in the web address directly into the fake Address bar. This is a live piece of JavaScript code, not a static fake Address bar image.
Forums » Gone Phishing


Sunday, 05-Jul 00:10:30 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9.5 years online! © 1999-2009 dslreports.com.