Bienvenido! - Willkommen! - Welcome!

Bitácora Técnica de Tux&Cía., Santa Cruz de la Sierra, BO
Bitácora Central: Tux&Cía.
Bitácora de Información Avanzada: Tux&Cía.-Información
May the source be with you!
Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Wednesday, September 7, 2011

Cyberangriff aus Iran

Totale, unbemerkte Überwachung
Um das zu erreichen, hätte es allerdings noch eines zweiten Tricks bedurft - und das spricht stark dafür, dass es sich bei dem Angriff tatsächlich um die Aktion einer staatlichen Organisation handelt.
Um diesen Teil zu verstehen, ist ein bisschen Internet-Grundwissen nötig:
  • Wenn ein Browser eine bestimmte Website öffnen soll, braucht er dazu eine zusätzliche Information: Die Übersetzung des Domainnamens (etwa www.spiegel.de) in eine IP-Adresse (im Fall von Spiegel.de: 195.71.11.67).
  • Diese Übersetzung erledigt das sogenannte Domain Name System (DNS). Der Browser fragt bei einem von vielen rund um die Welt verteilten DNS-Servern nach, welche IP-Nummer zu dem Domainnamen gehört, die er gerade aufrufen soll.
  • Wer die Kontrolle über den jeweiligen DNS-Server hat, könnte den Browser im Prinzip in die Irre führen - und ihn zu einer eigentlich falschen IP-Nummer seiner Wahl weiterleiten.
Mächtig und gefährlich würde beides in Kombination: Ein so in die Irre geführter Browser, dem dann auch noch ein gefälschter Web-Ausweis gezeigt wird, hielte eine gefälschte Web-Seite zwangsläufig für echt. Für den Nutzer wäre es praktisch unmöglich, zu erkennen, dass er gerade ausgetrickst wird. Zugriff auf DNS-Server hat nicht jeder - aber beispielsweise die iranischen Behörden. Sie könnten also alle Nutzer von Diensten wie Googlemail, Yahoo-Mail oder Skype auf eigene Websites umleiten und dort eine Kopie des echten Angebots bereitstellen.
Wer sich in seinen Mailaccount einloggte, würde nichts Ungewöhnliches bemerken, dabei liefe die ganze Kommunikation heimlich über den Server des jeweiligen Angreifers. Totale, unbemerkte Überwachung wäre die Folge. Allerdings wohl nur in der jeweiligen Region - deutsche Nutzer etwa beziehen ihre DNS-Informationen nicht von iranischen DNS-Servern.
Tatsächlich benutzt wurde Abdulhayoglu zufolge bislang nur eines der gefälschten Zertifikate - das für Yahoo. Comodo selbst habe festgestellt, dass die Angreifer es offenbar ausprobiert hätten, wiederum über eine iranische IP-Adresse.
Attacke auf das Sicherheitssystem des Webs
http://de.wikipedia.org/wiki/Man-in-the-middle-Angriff
http://de.wikipedia.org/wiki/Spoofing

Friday, March 19, 2010

Phishing in Cyberspace: Issues and Solutions

Source
Abstract:

This paper analyses and addresses the growing threat of phishing in cyberspace. Digital transactions and communications have, over the past decade, been increasingly transpiring at an accelerated rate. This non-linear progression has generated a myriad of risks associated with the utilization of information and communication technologies in cyberspace communications, amongst the most important of which is the online phishing crime.
This paper aims to provide an overview of the risks related to this crime and seeks to offer some solutions based on the necessity of pursuing an international policy encompassing strategic, regulatory and technical approaches.
Keywords: Phishing - Cybercrime – Cyberspace - Identity theft
1. Introduction
Phishing [1] is the act of sending an email to a user falsely claiming to be an established legitimate business in an attempt to scam the user into surrendering private information that will be used for identity theft. [2] The email directs the user to visit a Web site where he or she is asked to update personal information, [3] such as passwords and credit card, social security, and bank account numbers, that the legitimate organization already has issued. [4] The Web site, however, is bogus and set up only to steal the user’s information. [5] Phishing combines the power of the internet with universal human nature to defraud millions of people out of billions of dollars. [6] Nearly every internet user has received a phishing email by now.
On such account, phishing is a serious crime that merits due consideration and adequate prevention and combating. Phishing may be committed in whole or in part by the use of information and communication technologies (ICTs), which dispenses with face – to – face physical contact and allows for distance counters. [7] Historically, fraud involved face-to-face communication since physical contact was primarily the norm. [8] Even when remote communication — i.e., snail mail—could be used to set up a fraudulent transaction, it was often still necessary for the parties to meet and consummate the crime with a physical transfer of the tangible property obtained by deceit. [9] Nevertheless, the proliferation of ICTs has exerted a profound impact upon the nature and form of the crime, and has altered the mechanisms of crime commission. [10] Nowadays, perpetrators can use fraudulent emails and fake websites to scam thousands of victims located around the globe, and may expend less effort in doing so than their predecessors. [11] This new form of automated or electronic crime distinguishes online virtual fraud from real-world fraud in at least two important respects: [12] (a) it is far more difficult for law enforcement officers to identify and apprehend online fraudsters; and (b) these offenders can commit crimes on a far broader scale than their real-world counterparts.
Studies indicate that the number of phishing incidents is increasing at an alarming rate. [13] A recent report by the Anti – Phishing Working Group (APWG) found that phishing attacks have increased. [14] In May 2006, alone, more than 20, 109 emails and 11, 976 phishing web sites, representing 137 hijacked brands were reported and tracked by the APWG. [15] In the United States, it was estimated that between May 2004 and May 2005, 1,2 million internet users were victims of phishing, totaling approx. $ 929 million USD. [16] In the United Kingdom, losses from phishing almost doubled to £ 23.2 m in 2005, from £ 12.2 m in 2004. [17]
Finally, online phishing does carry the seeds of a potential conflict between national legal systems due to the intrinsic transnational and cross-border implications of such crimes, and the relative variation and divergence of national and regional policies dealing with such crimes. Whilst national and international efforts are underway to establish harmonized and consistent national strategies and policies to combat cybercrime, global condemnation as well as adequate universal policies may not be achieved in the near future at least until all states recognize the importance of ICTs and the need for existence of an adequate regulatory framework. [18]

Wednesday, September 30, 2009

Denunciar phishing & test

Source
No es extraño recibir correos fraudulentos donde intentan engañarnos para robarnos información o infectar nuestros equipos, muchas veces esta clase de mails terminan en nuestra carpeta de spam pero en ocasiones burlan los filtros y llegan a la bandeja de entrada.
Ya he comentado algunos casos de phishing en este blog (ej: Gmail, Hotmail, Twitter, Banco Santander), y hace algunos días recomendé un test que enseña a detectar los correos fraudulentos más comunes.
Ahora bien, ¿qué debemos hacer luego de confirmar que efectivamente hemos recibido un correo falso o estamos ante una página fraudulenta?... lo que debemos hacer es eliminarlo o salir del sitio, pero antes también podemos denunciarlo para que sea analizado y bloqueado.
...
Test para intentos de phishing:
La empresa SonicWALL ha elaborado un test para entrenar y enseñar a los usuarios a identificar correos legítimos y falsos.

test phishing
Se mostrarán 10 capturas de correos y nosotros deberemos decidir si se trata de un caso de phishing (engaño) o estamos ante un correo legítimo. Finalizado el test se mostrarán los resultados y será posible visualizar una explicación de por qué el correo era real o falso.
Vía: Security By Default.
Phishing en Gmail.
Phishing de Hotmail.
Clon falso de Gtalk.

Saturday, November 15, 2008

Phishing

Source
Phishing, also known as "brand spoofing", is an elaborate
form of data theft, targeting possible clients of ISP companies, banks,
online banking services, government agencies etc.

When submitting your email address on the Internet, filling in
online forms, accessing newsgroups or websites, your data can be stolen
by Internet crawling spiders and then used without your permission to
commit fraud or other crimes.


The Phishing Concept
Phishers develop counterfeit webpages, which imitate the corporate
image of well-known, trusted service providers. Then, using collected
or random generated email addresses, they "throw the bait".

A
message with a credible subject is sent by email or instant messenger,
asking for confidential data, inviting you to access a website ( 'Click Here'
link; URL link; Image link; Text link) or even to fill in a form in the
email itself. It looks like a plausible request and it even comes with
a dire consequence, to get your immediate reaction.


Examples of email subject:
"Update Your PayPal Account"
"Your eBay User Account has been suspended!"


The required information is usually:
$ Credit card number;
$ ATM PIN and TAN number;
$ Bank account information;
$ Social Security Number;
$ Passwords;
$ Email accounts;
$ Other personal information.


Once entered, the user's information is no longer confidential and
it is immediately used by the fraudsters in their own interest. It is
usually very difficult to get the money back, as the phishing sites are
generally online for a few days or even just hours.


Phishing Techniques
The main method is using a trustworthy-looking email, which tries to
lead you to a fake web page. Some phishing emails contain an
application or order form directly in the message body. You should know
that officials will never send you an email containing a form or asking
for personal information.

On the fake website you might notice that the URL is not the correct one. Still, there are ways to fake the URL:


  • Social engineering:
    The URL is very similar to the real one and you might just notice this on the first view. For example the real URL http://www.volksbank.com can be faked with http://www.voIksbank.com . If you think they are the same – not true! The lower case ‘l’ letter is replaced with the upper case ‘i’ letter.
  • Browser vulnerabilities:

    The fake website may contain a script to exploit your browsers. In this
    case, the real URL is displayed, but the content of the web page is the
    one from the fake server. One example is to display a fake picture on
    top of the browsers real address bar. You can not ‘click’ in the bar’s
    input field to mark the URL. Other exploits allow a fake input field
    displayed on top, so it will be even possible to click into the field
    and mark the URL.
  • Pop up’s:
    The link in
    the email points to the real website, but another browser window is
    displayed in front. Practically you can browse the real website without
    risk, but don’t get tricked by the second window. Those pop up's
    usually do not have an address bar to help identify a fake website.
  • No address bar:
    Some fake sites do not display the address bar at all and unless you specifically look for it, you might not notice this.

There are other techniques, apart from playing with the address
bar, which can be used in addition or stand-alone, to get access to
confidential information.


  • Other browser vulnerabilities:
    Some other
    vulnerability in your browser can be used to download and execute any
    malicious software. Such malicious software may be a Trojan that
    records all keystrokes and monitors all Internet traffic, especially
    when you are going to enter and submit data in an online form.
  • Pharming:
    Also known as “domain spoofing”,
    it is used to redirect the users to a fake website. Although you type
    the correct URL in your browser, you are redirected to a fake website.
    The correct URL remains in your browser, without change. In order to
    accomplish the redirection process, the name resolution has to be
    modified. This can be done either by changing the TCP/IP protocol
    settings or by an entry in the hosts file.
  • Man in the middle:

    Probably the most sophisticated method, as nothing has to be changed on
    the local computer. The phisher is located in between and redirects
    your connection to a fake server.

Phishing Camouflage
The phishing website might use other tricks such as:
  • Forged tooltip,
  • Right-click inaccessible.

Phishers avoid being detected by antispam/ antiphishing programs using:


  • Random letters or famous quotes in the subject or in the body of the email;
  • Invisible text in HTML emails;
  • HTML or Java content instead of plain text;
  • Pictures only (no other text in the email body).

Consequences
As the phishers can use so many techniques and can even combine
them, it is rather difficult to tell if an email request comes from
officials or not.

What are the consequences of disclosing confidential information?


$ The phishers can run up charges on your account.
$ They can open new accounts, sign utility or loan contracts in your name.
$ They can use a false ID and commit crimes using your personal information.

Do not bite the bait!


  • Do not fill in email forms concerning confidential
    information. Any trustful service provider uses secure websites and
    digital certificates.
  • Do not click on links provided by
    email, especially if you were not expecting that email. Contact the
    sender to verify if it was his/her intention to send this email (use
    the contact number the company gave you, not the one in the email).
  • Do
    not reply. Delete the message and check with the real company (use the
    contact number the company gave you, not the one in the email).
  • Do not click to follow the link provided in such a message. Type the address in the browser yourself.

Safety Rules
Repairing the damage caused by phishing may be frustrating and
time-consuming. Apart from the loss of productivity and use of network
resources, data theft requires considerable efforts on your part: you
will have to rescue your identity, property and rights and to clear
your name.

It is much easier to follow some basic safety rules:


  • Update your operating system with the latest patches as soon as they appear.
  • Alternate Internet Explorer with other browsers.
  • Use antivirus and firewall solutions and keep them permanently up-to-date.
  • Always type the URL yourself instead of following a link.
  • Make sure you are using a secure website (HTTPS) and check the digital certificates.
  • Regularly check your accounts and statements and immediately report any abuse.
  • Report suspicious emails to security companies and authorities from your area.

You can send suspicious messages to Avira’s report addresses:
spam@avira.com
virua@avira.com

Saturday, November 8, 2008

Netcraft Toolbar

With the Netcraft Toolbar you can protect your savings from Phishing attacks.

  • See the hosting location of every site you visit.
  • Help defend the Internet community from fraudsters.
Getting started with the toolbar

Getting Started

To learn more about using the Netcraft Toolbar visit the Tutorial.
If you have any further questions about the toolbar please see the FAQ