Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Danger - Phishing ahead » Don't trust the Lock icon either!
Search Topic:
Uniqs:
2
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
AuthorAll Replies


justin
Australian
join:1999-05-28
Brooklyn, NY
reply to The Way Out
Re: Don't trust the Lock icon either!

Did you knock this site up? i was going to try an https redirect to see if it could be done, it seemed like it could but I didn't have a domain handy.

The Way Out

join:2003-01-20
Yes, I set it up. As long as the "real" webhost has a valid SSL certificate (and is issued by a root that is trusted by the browser), no warning is popped up at all. Scary, huh.


justin
Australian
join:1999-05-28
Brooklyn, NY
I figured it would work, as its just a display bug, really. Damn. I updated the news bit to link to your post demonstrating the fake encrypted site that gives no alerts about the certificate not matching what is displayed in the address bar.


Googled
Yay, I have FIOS

join:2001-08-13
Orchard Park, NY
·VoicePulse
·Verizon FIOS
·WildBlue

 reply to justin
I was thinking some more about this bug and I came up with an even scarier usage.

Using the Apache "Redirect" directive you can phish an entire site! Just put this into your httpd.conf!


Redirect /test "http://www.domainyouwant.com^A@www.domainyouhave.com"


Now anyone who visits www.domainyouhave.com/test will be redirected to the phished site! Doing this makes IE automatically modify EVERY link on the page to a phished version!

--
DirecWay DW3000 DRS, SatMex 5 1170 gateway 164, P3-533/256 MB, AOL+ 7.0 4114.10712 on 98SE w/ICS,shared to 2 x 2K Pro, 1 x Redhat Linux 7.3, 1 x Netgear 802.11b


justin
Australian
join:1999-05-28
Brooklyn, NY

Host:
IPv6
Business Connectiv..
Home/Office setup ..
Console/Handheld g..
Console Tech
thats cute. I figured there would be creative use of redirectors.

I mean - you could post one of those "Special offer" links, the ones that nobody expects to look correct because they are long and have affiliate pay-on-click codes in them? - and then redirect to a phished version of SBC DSL signup page and keep them within it. Then collect credit card numbers for days before the victims noticed.
Forums » Danger - Phishing ahead


Wednesday, 15-Oct 21:11:29 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [136] All Hail the New RIAA Copyright Czar
· [82] More on Comcast's New 22Mbps Speed Tier
· [72] New 'Economic Stimulus' Plan Includes Universal Broadband
· [71] Comcast: Hey, At Least We're Not Hiking Broadband/VoIP Prices
· [41] Cindy McCain Gets Her Own Verizon Cell Tower
· [38] 72% Of P2P Pirates Would Stop With ISP Warning
· [37] Unions Want Improper Cable Grounding Inspected, Too
· [31] AT&T To Sell U-Verse At Walmart, Circuit City
· [31] Google: We're Fresh Out Of Androids
· [30] Crackberry Addicts Fear Microsoft Takeover
Most people now reading
· Extreme HD and Essentials [Verizon FIOS TV]
· [WotLK] Broken (OP) Holy Paladin Build (Current Beta) [World of Warcraft]
· IMG 1.6 Build 06.89 Released [Verizon FIOS TV]
· [ Classes] Holy Priest Level 70 WoW 3 Talent Build [World of Warcraft]
· Southern California New HD Watch [Verizon FIOS TV]
· Well Cons are In -- Begin the Damnation. [TekSavvy]
· Basement - Concrete Walls - What to do? [Home Repair & Improvement]
· [WotLK] What you guys think of the patch? [World of Warcraft]
· Official Patch Notes - 3.0.2 [World of Warcraft]
· Sarah Palin Ordered to Preserve Yahoo! Emails [Security]