Live data from Hacker News

Stopping phishing campaigns with Bash

blog.haschek.at

121–130 of 169 posts

Re: Stopping phishing campaigns with Bash

#121
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

If your insecure site has been hijacked by phishing campaigns, you deserve to have it brought to its knees. Security is your responsibility.

If your insecure house has been broken into, you deserve to have all of your stuff stolen. Security is your responsibility.

Re: Stopping phishing campaigns with Bash

#122
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

Have you ever tried reporting a phishing site through those legitimate channels? I have, and my experiences have been that: * The domain registrars are apologetic and well-meaning, but tend to explain that they aren't empowered to take this stuff down without being ordered to by Law Enforcement or similar. There typically isn't a mechanism available for getting LE to respond before the phish campaign is over. * The h…

I've had a similar experience. I ran into a scam that was masquerading as a popular Canadian clothing store (Roots) where everything was 50% off. I reported the domain to Namecheap and they said they're not responsible for the content since its hosted elsewhere. I pointed out that the domain itself was also trying to pass as legitimate and they told me unless I was the trademark owner they couldn't do anything. I also e-mailed the hosting provider but never heard back.

Fortunately I got ahold of Roots via Twitter and the scam seems to have been shut down.

Re: Stopping phishing campaigns with Bash

#123
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

If your insecure site has been hijacked by phishing campaigns, you deserve to have it brought to its knees. Security is your responsibility.

Mind posting a link to your website?

Re: Stopping phishing campaigns with Bash

#124
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

If your insecure site has been hijacked by phishing campaigns, you deserve to have it brought to its knees. Security is your responsibility.

This is prevalent logic in the security community, but it sounds strange applied to other domains.

"Porch pirates are justified because you should have secured your amazon delivery."

"She deserved harassment because she was dressed provocatively"

"Your country didn't have a wall so it deserved to be invaded."

Re: Stopping phishing campaigns with Bash

#125

Earlier quoted context omitted.

If your insecure site has been hijacked by phishing campaigns, you deserve to have it brought to its knees. Security is your responsibility.

This is prevalent logic in the security community, but it sounds strange applied to other domains. "Porch pirates are justified because you should have secured your amazon delivery." "She deserved harassment because she was dressed provocatively" "Your country didn't have a wall so it deserved to be invaded."

None of those acts enable the criminal to commit crimes against other people.

Re: Stopping phishing campaigns with Bash

#126

Earlier quoted context omitted.

If your insecure site has been hijacked by phishing campaigns, you deserve to have it brought to its knees. Security is your responsibility.

If your insecure house has been broken into, you deserve to have all of your stuff stolen. Security is your responsibility.

Which doesn’t apply to what I said. If you leave your handgun unsecured and it’s stolen and used in a crime against OTHER PEOPLE, you don’t believe you bear some responsibility?

Re: Stopping phishing campaigns with Bash

#127
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

I used to report these things but ran into some issues: 1) There is no way I can see to contact anyone at Ali Cloud to report abuse and no expectation they will do anything and I've seen an increasing number of scams hosted on offshore providers with no apparent abuse reporting system. 2) Some registrars and hosting providers want you to sign up with an account first to be able to create a support ticket to report abuse which is very time consuming. 3) I would probably be spending hours per week reporting abuse and it never seems to end. It feels like trying to empty the ocean with a thimble. So now I just ignore phishing scams.

Re: Stopping phishing campaigns with Bash

#128
The same IP that hosted this guys phishing page also hosted phishing pages targeting Italian banks WeBank, Banca Intesa Sanpaolo and Banca Sella over the past 14 days, all with wildcard certs issued by the same CA. So not really surprising, just run of the mill phishkit activity most likely. If you have fun spamming their inbox knock then yourself out, but it's not gonna make a dent in the thousands of phishkits deployed every day. Source: https://urlscan.io/ip/89.46.110.15

Re: Stopping phishing campaigns with Bash

#129
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

I used to report these things but ran into some issues: 1) There is no way I can see to contact anyone at Ali Cloud to report abuse and no expectation they will do anything and I've seen an increasing number of scams hosted on offshore providers with no apparent abuse reporting system. 2) Some registrars and hosting providers want you to sign up with an account first to be able to create a support ticket to report ab…

You should be able to find the registar abuse contact information in the whois, in the fields "Registrar Abuse Contact Email" and "Registrar Abuse Telephone Number". Registrars are required to provide these for the accreditation to ICANN [0]. Both email and valid phone number are required.

[0] https://www.icann.org/resources/pages/faqs-2013-11-26-en

Re: Stopping phishing campaigns with Bash

#130
post #112

That's really... not an appropriate response, and not only for the legal reasons others mentioned. Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised). Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup…

> A more appropriate response is to report the abuse who manages the infrastructure (most likely a legitimate provider) and the domain registar; both usually have appropriate channels and response procedures just for that.

Unless of course it's behind Cloudflare - then you cannot find out whose infrastructure the criminals are operating from and Cloudflare itself does not give a fuck. Best case scenario: they will forward your complaint to their customer - an unknown party to you who might be the criminals themselves, putting you in danger.

Thank you, Cloudflare.

Post reply on HN