Showing posts with label Automated Phishing. Show all posts
Showing posts with label Automated Phishing. Show all posts

Wednesday, 14 October 2015

Trustwave Provides SSL Certificate For PayPal Phishing Sites


Trustwave Certificate Authority is using an organization validated SSL certificate issued for a variety of PayPal phishing domains. SSL certificates are used to identify the website and to encrypt traffic between visitors and website.

There are basically three different categories of SSL certificates. When domain-validated (DV) certificate, only the control checks on a particular domain. In the case of an organization-validated (OV) certificate is the right of the applicant to use a specific domain name checked as well as a validation of the company. Thirdly, there is the Extended Validation (EV) certificate, the identity of the owner is thoroughly checked. Many certificates of misleading domain names are assigned DV certificates. Often this involves an automated process.

In the case of the OV and EV certificates, the verification will be conducted by people. It is also noteworthy that Trustwave an OV SSL certificate for paypal-office.com, myaccount-paypal.com and paypal-sign.com has been issued and used on a PayPal phishing site. The certificate was issued to a person in India, reports Internet company Netcraft. The phishing site has since been taken down, but the certificates are not revoked, according to Netcraft.

Friday, 21 August 2015

Phishing Springboard Hidden In PDF Documents


PDF documents are often used to infect computers with malware, cyber criminals but the format now use to lure victims to phishing sites. Researchers at Kaspersky Lab discovered a PDF document that is distributed via an e-mail scam.

According to the email, the recipient of the message received $ 53,000 in his account. However, the recipient must confirm the transaction, which can be done via the enclosed PDF document. The PDF document contains only an illustration that states that the document is protected and offers the user a button to view the contents. The button, however, points to a phishing site which looks like a PDF document with transaction data.

To view the data, the user must then enter their email address and password. These data are sent to the criminals. According to analyst Dmitry Bestuzhev, this is an interesting technique that some phishing filters can mislead.

Monday, 5 January 2015

Wifiphisher Performs Automated Phishing Attack Against Wi-Fi Networks



A Greek researcher has developed a tool that is trying to steal the passwords of Wi-Fi networks. "It's a social engineering attack that does not use brute forcing in contrast to other methods. It's an easy way to get WPA passwords," said George Chatzisofroniou on his tool " Wifiphisher ".


The attack consisting Wifiphisher performs several steps. In the first step, the connection between the user and the Wi-Fi network. Wifiphisher remains hereby block all Wi-Fi devices in the vicinity of the access point. Wifiphisher then copy the settings of the access point attacked and put a fake access point that makes the victim connection.


During the final step, the victim gets to see a convincing according Chatzisofroniou configuration page of the router. This page is displayed once the victim opens a web site on the Internet. On the false configuration page for a so-called firmware upgrade WPA passphrase requested. To use Wifiphisher needed Kali Linux and two WiFi cards, which can do one injection.

On Hacker News and Reddit , there is also criticism of the tool because it would not be possible to set up a fake access point without a password. "The tool is actually a second unencrypted network. On Windows displays a warning that the network configuration has changed. On Android you must manually with the unencrypted network connection. This method thus does not perform automatic man-in-the- middle out, "said one of the critics.