Live data from Hacker News

An Innovative Phishing Style

tehaurum.wordpress.com

51–60 of 83 posts

Re: An Innovative Phishing Style

#52
post #29

Earlier quoted context omitted.

Unthemed Windows & Mac OS will be convincing to a lot, Linux will be pretty hard. Then again those who tinker with their computers are unlikely to fall into this trap.

This specific phishing website mimics an ingame website for Counter-Strike Global Offensive, a shooter game with the vast majority of players using Windows. Linux isn't supported at all and while the game technically runs on a Mac most people don't (or play it with Bootcamp). I would not be surprised if 99% of the audience for this website is using Windows, the vast majority with default themes (and the ones without…

CS:GO runs natively on Linux, most Valve games do actually

Re: An Innovative Phishing Style

#53
post #50
post #30

Earlier quoted context omitted.

It's a common sales technique. People are willing to give their CC details for a free plan since they are not charging anyway. But by the time your site grows, this takes away the friction of switching to a paid plan. Mailgun does the same.

Maybe it's a cultural thing? I've never come across a situation where anyone would give their CC number for a free service. That gives a really shady impression. Or expose myself to that risk.

Free service that requires a credit card? That is almost always a red flag for me and just screams “scam”. Who falls for that?

Re: An Innovative Phishing Style

#54

Earlier quoted context omitted.

Well, first, phishing is not calling someone, but at our bank we train our employees monthly about phishing by testing them, and if they fail they must take a class. Serial failures could result up to termination. So, how much you wanna bet?

> So, how much you wanna bet? You're not resigned enough to be on an infosec team, and if you're not on an infosec team you probably don't know the true percentage of how many employees are failing over and over (it's a ton, it's always a ton). I'd go big :)

Personally I'd be pretty sure that, at least at the bank I currently work at, this would rarely ever work.

I mean, other than the attempts to foster a relationship between bank staff and the tech people through things like days of letting tech people hang out and try and be helpful at branches in order to "see what real difference they could make" - and that laegely ending up being a fairly regular educational exercise for everyone involved theres two problems I see:

1. All the phone calls into branches are monitored (you may have noticed so many "we will record this call and it may be monitored" messages - they arent kidding) and if certain key words, or even key tones of voice are picked up someone from a relevant team silently dials onto the call to listen in. 2. The general process for anyone not in it interacting with any IT system is to click a button on their screen which generates a 6 digit pin and if you cant match that pin with the person talking to you and dont confirm success then alerts go out immediately.

And given the hit rate on the "generate pin" api, tellers are definitely using it properly.

So i'd be inclined to go pretty small if I where to bet at all.

Not sure why the assumption that you can social engineer your way onto any half way competent institution still persists,but nowadays, as far as I know, you have to pick the really low hanging fruit for someone to let you in so easily.

Re: An Innovative Phishing Style

#55
OAuth and similar technologies are a blessing and a curse. Users are too willing to use one site’s login credentials to log into another site, and this willingnessis a phisher’s dream come true. This whole class of problems would go away or at least be minimized if there were fewer of these “log in with Facebook” and “log in with your google account” opportunities to exploit.

In this case it looks like the 3rd party service required deep integration with Steam so it was probably unavoidable, but many sites use OAuth as a crutch because they don’t want to bother butlding their own sign-in system.

I’ve stopped using services if they don’t provide an option to create a site-specific username and password. Facebook login the only way to sign up for your site? How about no.

Re: An Innovative Phishing Style

#56

Wanna bet that if I call anybody working in a bank, telling them I am from the IT department and I want them to check the new login page (done the way described in this article), they will enter there their login & password?

Well, first, phishing is not calling someone, but at our bank we train our employees monthly about phishing by testing them, and if they fail they must take a class. Serial failures could result up to termination. So, how much you wanna bet?

At my previous bank, you could get your account password reset with SSN and birthday. Also, your account number (and your website login) was your social security number. And for the longest time, your password for your account online was your ATM pin. This is at a credit union in the US. I switched banks as soon as I had a significant amount of money in my account.

tbh, i'm surprised they don't have bank accounts emptied out regularly, but they're sort of small(limited to grocery store employees), so maybe its just nobody has seen it.

Re: An Innovative Phishing Style

#57
post #54

Earlier quoted context omitted.

> So, how much you wanna bet? You're not resigned enough to be on an infosec team, and if you're not on an infosec team you probably don't know the true percentage of how many employees are failing over and over (it's a ton, it's always a ton). I'd go big :)

Personally I'd be pretty sure that, at least at the bank I currently work at, this would rarely ever work. I mean, other than the attempts to foster a relationship between bank staff and the tech people through things like days of letting tech people hang out and try and be helpful at branches in order to "see what real difference they could make" - and that laegely ending up being a fairly regular educational exerci…

> half way competent institution

At which attackers shift their targets from a bank to a mobile phone provider... :(

Re: An Innovative Phishing Style

#59
post #58

a phising attemp that emulates a OS window in html is lame and should have been spoted a mile away. real popups open as tabs to begin with.

Depends on the browser, but in Firefox and Chrome you can certainly pop a window using a click event. Assuming a JS library was clever enough to simulate the OS-chrome believably it could be easy enough to trick people.

Re: An Innovative Phishing Style

#60
post #50
post #30

Earlier quoted context omitted.

It's a common sales technique. People are willing to give their CC details for a free plan since they are not charging anyway. But by the time your site grows, this takes away the friction of switching to a paid plan. Mailgun does the same.

Maybe it's a cultural thing? I've never come across a situation where anyone would give their CC number for a free service. That gives a really shady impression. Or expose myself to that risk.

What risk? That you have to wait a few days for your bank to send you a new card if it is compromised? There is no accidental charge risk as you then just call the bank and have them remove it. If your bank makes that difficult then switch to a reputable one.
Post reply on HN