stargeek
PHP news website logo.
home    PHP scripts    articles    seo tools    links    search    contact    shop    realtors


Phishing and Bouncing







Phishing and Bouncing

Phishing and Bouncing 09/12/2004 12:36 PM

Looks like the trick of using redirection CGIs at popular website (described in Phishing with Google) is getting popular among phishers. I just got a couple that uses AOL's redir-complex CGI at:

http://r.aol.com/cgi/redir-complex?url=whereever

Note that phishers can use not just the redirecting CGIs, but also those CGIs that use return URL as parameters.  In fact, these types of CGIs are popular among financial institutions and single-sign on services.  For example, both Passport and 3D-Secure uses them.




This is a GrokNews Entry: (what is grok?)





Similar Items

Phishing and Bouncing

Grok Headline matches for Phishing and Bouncing

Anti-Phishing Toolbar Available. How to
Avoid Bank and Ebay Phishing Scams


Anti-Phishing Toolbar Available. How to
Avoid Bank and Ebay Phishing Scams
12/30/2004 07:54 PM
Tech-Recipes Dec 30 2004 11:09PM GMT

Bouncing Termsheets


Bouncing Termsheets 02/10/2004 02:56 AM
I’ve been hearing these stories, several times in the last month, from both here in Vancouver and down in the States, of entrepreneurs having drop-kicked a VC termsheet and walked away, on the basis of terms and/or valuation. If you don’t know what this jargon means, a crash lesson on how the VC process works. For those who do know, a few remarks on VC trends...

Following The Bouncing 419 Scam


Following The Bouncing 419 Scam 07/09/2004 01:13 PM
Because no one can believe just how often people are fooled by obvious 419 scams, the folks over at TheRegister have put together a story looking at the details of how one works, including the entire series of emailed correspondences. They also checked out the fake bank that the sucker sent his money too, and even spoke to someone claiming to work at the bank, who quickly got upset and hung up on them as he discovered where the phone call was headed. However, as they point out, it was the guy's own greed that got him into the situation: "He allowed his desire for riches to suck him into a scheme that - even if true - he must have known to be illegal. He has no recourse to law and the 419ers are laughing all the way to their bogus London bank."

Bouncing Baby Ryan


Bouncing Baby Ryan 03/20/2003 05:31 PM
Congratulations to Mike and Stacey on the birth of their son, Ryan! Don't expect to hear too much cooing coming from the Pirillo household anytime soon, though. Other than the... *ahem* nevermind. Why not? (1) We hardly have enough time for ourselves, let alone another human being; (2) Ain't no way I'm raisin' a kid in the city; (3) I'd have to buy yet another Webcam; (4) Diapers. 'Nuff said. (5) We've got Sprocket - and he's enough for now....

SSH Bouncing - How to get through
firewalls easily.


SSH Bouncing - How to get through
firewalls easily.
09/02/2004 10:20 AM

Bouncing Ball Games


Bouncing Ball Games 05/07/2004 05:42 PM
Resource Management System

SSH Bouncing - How to get through
firewalls easily


SSH Bouncing - How to get through
firewalls easily
09/01/2004 07:37 AM

PC Shipments Bouncing Back


PC Shipments Bouncing Back 12/13/2003 07:07 AM
SiliconValley.Internet.com Dec 13 2003 6:26AM ET

Brand new bouncing baby bl0g


Brand new bouncing baby bl0g 07/28/2004 11:14 AM
Larry Magid, CBS radio journalist and looong time tech writer, has started a blog. It's just two posts old. And the opposite end of the rhetorical spectrum, the folks at MeThree are doing the gonzo thang blogging the Convention. Jerry Michalski recommends the Democratics adopt "light, memory and discourse" as a way of countering the Republican "Me hammer, you nail" thrum. And Micah Sifry and Nancy Watzman have an op-ed in the LA Times (reg. required) about why Big Corps are throwing parties for the Demos....

DRAM bouncing back, report says


DRAM bouncing back, report says 12/17/2003 01:17 PM
CNET Dec 17 2003 12:48PM ET

Database sales bouncing back


Database sales bouncing back 05/26/2004 06:02 PM

Study: Database sales bouncing back


Study: Database sales bouncing back 05/26/2004 06:23 PM
CNET May 26 2004 10:11PM GMT

iVoice files patent on bouncing grannies


iVoice files patent on bouncing grannies 03/23/2005 12:46 PM
From speech recognition to airbags...

Scientists Uncover Protein Key to
Bouncing Back after Pregancy


Scientists Uncover Protein Key to
Bouncing Back after Pregancy
01/26/2004 01:12 AM

Hacking Linux Exposed: SSH Bouncing--How
to Get Through Firewalls Easily


Hacking Linux Exposed: SSH Bouncing--How
to Get Through Firewalls Easily
09/01/2004 07:39 AM

City Funds Flow to Check-Bouncing
Developer (Los Angeles Times)


City Funds Flow to Check-Bouncing
Developer (Los Angeles Times)
06/14/2004 05:01 AM
Los Angeles Times - Los Angeles parks Commissioner Christopher Hammond is no ordinary deadbeat.

Gone Phishing


Gone Phishing 01/25/2004 09:50 PM

Phishing for the end


Phishing for the end 08/17/2004 04:56 PM
"This site was created with one goal; to create the most comprehensive online archive of information and digital photos of the Coventry Vermont Phish show, August 14th and 15th 2004." Seems odd to think folks went to the trouble of dedicating an entire website to just a single concert, until you learn it was the very last one for Phish.

eBay Goes Phishing


eBay Goes Phishing 01/03/2005 12:35 PM
The popular online auction site rolls out a new approach in tackling account hackers: cut bait.

The future of phishing


The future of phishing 04/29/2004 10:42 AM
vnunet.com Apr 29 2004 2:09PM GMT

War Against Phishing Continues


War Against Phishing Continues 03/14/2005 04:32 PM
Phishers and other online scammers are well ahead of law enforcement officials and security experts right now in terms of techniques and tactics.

Phishing behind Google


Phishing behind Google 08/28/2004 01:03 AM

I just received a phishing email purporting to be from PayPal.  No surprise there since I get many of them everyday, but I looked closer at this one because it looked very professionally done.  I looked at the raw message and found this odd link:

This particular phisher is bouncing off Google to hide itself from domain name-based phishing detectors and scanners.  Clever.  Clicking on the link will open a browser to Google's URL search CGI which will automatically redirect the browser to the phishing site at IP address 209.152.181.10.  This trick will bypass phishing detectors that examines only the domain name part of a URL to see if it looks suspicious.

So the lesson here for security developers is to look at all the parameters and to keep track of oh-so-helpful redirectors like Google.  Also, website developers should keep in mind that helpful service is helpful to all, including the bad guys, and they might become an unwitting partner in crime.  For lawyers, it's a new source of income concern.


Phishing for Opera (GM#007-OP)


Phishing for Opera (GM#007-OP) 06/03/2004 12:03 PM
GreyMagic Software (Jun 03 2004)

IE bug provides phishing tool


IE bug provides phishing tool 12/10/2003 05:50 AM
ZDNet UK Dec 10 2003 5:09AM ET

Political Phishing


Political Phishing 08/03/2004 12:32 PM
It's election season, and that means that, just like with all the other news-sensitive scams, phishers are getting political. The latest is a phishing email that simply copied a donation request from the John Kerry campaign, but changed the link to a fake site. Of course, the folks behind the scam made one very stupid mistake: remotely using an image hosted on the Kerry website -- which was quickly changed by the campaign to explain that the site was a scam (though, it's likely this confused some people -- hopefully enough to stop them from donating). Still, it's likely that the next version won't make the same mistake. With the success phishing emails have had lately, and the fervor with which people seem to be donating to campaigns, an awful lot of cash supposedly going to campaigns is going to be making criminals wealthy.

Phishing on the rise in U.S


Phishing on the rise in U.S 06/15/2004 02:57 PM
ZDNet Jun 15 2004 5:56PM GMT

Do-it-yourself phishing kits appear on
web


Do-it-yourself phishing kits appear on
web
08/21/2004 04:39 PM
Personal Computer World Aug 21 2004 8:48PM GMT

DIY phishing kits hit the Net


DIY phishing kits hit the Net 08/19/2004 05:48 AM
My little fraudster

Phishing to cost SA millions'


Phishing to cost SA millions' 05/18/2004 10:36 PM
Sunday Times South Africa May 19 2004 2:49AM GMT

Best news in the war on spam: phishing


Best news in the war on spam: phishing 05/24/2004 03:10 AM
Boston Globe May 24 2004 6:25AM GMT

Pharming Out-Scams Phishing


Pharming Out-Scams Phishing 03/14/2005 05:21 PM
A fast-spreading online swindle redirects web users to phony sites where criminals can capture passwords and other data. Unlike phishing, which targets one user at a time, pharming nabs multiple victims at once. By Michelle Delio.

Phishing morphs into pharming


Phishing morphs into pharming 02/01/2005 09:24 PM

Phishing Attacks on the Rise


Phishing Attacks on the Rise 05/19/2004 06:10 PM
The volume of such attacks is growing rapidly, according to anti-fraud firm Cyota, which detected some 450 distinct phishing expeditions in March alone.

Crooks Are Phishing For Your Life


Crooks Are Phishing For Your Life 05/19/2004 04:15 PM
CBS News May 19 2004 8:20PM GMT

Email Spam and Phishing


Email Spam and Phishing 05/12/2004 05:18 PM
WebDevInfo May 12 2004 8:18PM GMT

Lawmakers: Phishing season is over


Lawmakers: Phishing season is over 07/15/2004 10:11 AM
ZDNet Jul 15 2004 2:15PM GMT

Phishing Costs Nearly $1 Billion


Phishing Costs Nearly $1 Billion 06/24/2005 09:28 PM
Information Week Jun 25 2005 1:16AM GMT

Phishing Expeditions Are Multiplying


Phishing Expeditions Are Multiplying 05/14/2004 07:41 PM

Re: New whitepaper "The Phishing Guide"


Re: New whitepaper "The Phishing Guide" 09/23/2004 03:11 PM
Aleksandar Milivojevic (Sep 23 2004)
Grok Description matches for Phishing and Bouncing
GrokA matches for Phishing and Bouncing

Phishing and Bouncing

The following phrases have been identified by the grok system as matching this entry:

















Also check out:


Grok

Ipod Porn on the
Rise

Brief Abstract of
Wikipedia's
Mesothelioma Cancer
page

Get first aid
instructions in your
cell phone

IE is crap
JSPWiki gains
podcasting support

Bush's Terror Error
Secret Photoshop
Quick Tips revealed!

Ceci n’est pas une
goatse.cx

Virtual
schizophrenia

Copenhagen Bloggers'
Dinner

Take Full Advantage
Of The Internet-Post
Your Ads Here

ahmedabad -ps2
-modded-where -looks
like nowhere?
games-any damn
idea???

Gray market in
Kolkata is in
Khidirpore and
Chandni Chowk...
Happy Shopping

Waiting for HUTCH
One... ;-)

No Microsoft
reports: police

New network layer
could reduce
Internet jams and
improve security

The Sims 2 / TS2:
Console and Cheat
Commands

Ecobot II: A
Fly-eating Robot

Hewitt Tries to Stop
Federer's Major Run
(AP)

Zhang Readies
Another Martial-Arts
Saga (AP)

Fire in Ohio
Apartment Building
Kills 8 (AP)

Three Said Killed in
Afghanistan Protests
(AP)

Migrants swamp
Italian island

Athletics: Holmes
second in Berlin

Football:
Hearts-Rangers draw

The case of the
fonts

Intel's Problems
Have Positive Side

The Return of
Robots.net

Tobacco Barns
Becoming Endangered
in Maryland

Notre Dame Bounces
Back to Stun
Michigan (AP)

Protesters Attack
Soldiers in
Afghanistan (AP)

ID3Library.Net
libircclient
SynCE
Vote Now: Apple
iTunes In Running
For 'Internet
Innovation Of The
Year'

ASCII cows and other
art

Eurobike 2004
Living with
Webservices

Proud Father -
WWW::BugMeNot

Land of Potatoes
Aims to Be High-Tech
Hotbed (Reuters)

Really Easy Video
Encoding Library 1.0

GalaxyHack 0.71
MacNessus 0.1
Java Desktop
Rolemaster Character
Generator .92.1

Free version of
Sybase released for
Linux

Iran Says It Won't
Halt Nuclear
Technology Drive

Israel's Sharon
Accuses Far-Right of
Inciting War

N.Korea Blast Area
Near Underground
Missile Base

U.S.: N.Korea Blast
Not Likely to Be
Nuclear

Freedom at Last for
Pakistanis Who Aided
Taliban

U.S. Says N.Korea
Blast Unlikely to
Have Been Nuclear

U.S. Says N.Korea
Blast Probably Not
Nuclear

Windows Tip: Change
Title Bar Colors

Singer Keys cancels
Jakarta show

WPP wins '£750m' US
takeover bid

what is grok?