I'm an engineer (mostly web) and I am very tech savvy, and extremely wary on the internet of scams. However, if this site had to come me via a trusted channel, I would have fallen for it maybe 80% of the time. I hardly ever login to steam as it's always running and while I have 2FA my password would have been stolen in this attack for sure. I don't think teenagers and non-techy users would stand a chance against this…
An Innovative Phishing Style
41–50 of 83 posts
Re: An Innovative Phishing Style
#42I will vouch for the author of this article. Smart kid! On a slightly off-topic, I think it's safe to say that trading and farming items in popular games, is responsible for cheaters, unfair practices, and in turn developers churning out more of these. I hope we can return to games, where I pay for a title for its entertainment value, bar of all loopholes and caveats.
It's a stretch to say it results in cheaters, people have been writing cheats since quakeworld.
Re: An Innovative Phishing Style
#43This is hard to defend against, but changing the default colour scheme (also used for every window title bar) helps somewhat.
A good solution is to force popup windows to open as a tab in the current window, so that the address bar is absolutely always in the same place. This distorts the popup window because it can't change size but that's a small price to pay. I find it annoying that any website should open a new window anyway. I'm not sure if this is possible in Chrome, or if so how to do it, but in Firefox the setting is browser.link.op…
It's incredibly well done, and I was almost fooled by it when I went to the web site. If I hadn't been using Qubes OS where my dispvm's are using red borders, I probably wouldn't have noticed at all.
Re: An Innovative Phishing Style
#44Browsers should implement some mechanisms to combat this type of phishing. I've gone ahead and reported this as a phishing site on Google safe browsing and other services.
> Browsers should implement some mechanisms to combat this type of phishing. combatting this doesn't require browsers - you can have a passwordless login mechanism (like email links!). Or, if browsers do indeed want to combat issues such as these, we'd need support for client-side certs (so you can login using a key-pair!), rather than username/password. Or, rely in a tool like lastpass to consistently enter the cred…
Re: An Innovative Phishing Style
#45Earlier quoted context omitted.
A good solution is to force popup windows to open as a tab in the current window, so that the address bar is absolutely always in the same place. This distorts the popup window because it can't change size but that's a small price to pay. I find it annoying that any website should open a new window anyway. I'm not sure if this is possible in Chrome, or if so how to do it, but in Firefox the setting is browser.link.op…
If you go to the page, you'll notice that they are not displaying a popup. Instead, they have recreated the entire UI experience, and if you're on Windows the only way to tell that something fishy is going on is if you try to move the window and you'll notice you can't move it outside the bounds of the parent Window. It's incredibly well done, and I was almost fooled by it when I went to the web site. If I hadn't bee…
But that's exactly my point! If you have set your browser to make all popups appear as a tab taking up the whole of your existing window (and adding an entry to your tab list), and then a fake one looks like a separate window, then it will stick out as fake immediately. For me, a browser-like window within the boundary of my actual browser is so foreign that I wouldn't even consider the possibility that it's real.
Re: An Innovative Phishing Style
#46I'm an engineer (mostly web) and I am very tech savvy, and extremely wary on the internet of scams. However, if this site had to come me via a trusted channel, I would have fallen for it maybe 80% of the time. I hardly ever login to steam as it's always running and while I have 2FA my password would have been stolen in this attack for sure. I don't think teenagers and non-techy users would stand a chance against this…
Re: An Innovative Phishing Style
#47Wanna bet that if I call anybody working in a bank, telling them I am from the IT department and I want them to check the new login page (done the way described in this article), they will enter there their login & password?
Re: An Innovative Phishing Style
#48Earlier quoted context omitted.
Unthemed Windows & Mac OS will be convincing to a lot, Linux will be pretty hard. Then again those who tinker with their computers are unlikely to fall into this trap.
This specific phishing website mimics an ingame website for Counter-Strike Global Offensive, a shooter game with the vast majority of players using Windows. Linux isn't supported at all and while the game technically runs on a Mac most people don't (or play it with Bootcamp). I would not be surprised if 99% of the audience for this website is using Windows, the vast majority with default themes (and the ones without…
What? Valve games tend to have pretty good Linux support.
Re: An Innovative Phishing Style
#49Wanna bet that if I call anybody working in a bank, telling them I am from the IT department and I want them to check the new login page (done the way described in this article), they will enter there their login & password?
Well, first, phishing is not calling someone, but at our bank we train our employees monthly about phishing by testing them, and if they fail they must take a class. Serial failures could result up to termination. So, how much you wanna bet?
You're not resigned enough to be on an infosec team, and if you're not on an infosec team you probably don't know the true percentage of how many employees are failing over and over (it's a ton, it's always a ton).
I'd go big :)
Re: An Innovative Phishing Style
#50Earlier quoted context omitted.
Why would it require a credit card to sign up for the free plan? To "prevent" scams and abuse?
It's a common sales technique. People are willing to give their CC details for a free plan since they are not charging anyway. But by the time your site grows, this takes away the friction of switching to a paid plan. Mailgun does the same.
I've never come across a situation where anyone would give their CC number for a free service. That gives a really shady impression.
Or expose myself to that risk.