Google Search

Showing posts with label phish. Show all posts
Showing posts with label phish. Show all posts

Wednesday, July 24, 2013

Anatomy of a phish - how to spot a Man-in-the-Middle attack, and other security tips

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Even if you are used to phishing scams, it still pays to take the occasional look at a scam campaign, just to remind yourself not to let your guard down.

So here's a recent scam in which the crooks are targeting customers of Absa, one of the Big Four banks in South Africa.

The email used in the scam pretends to be a refund from the South African Revenue Service (SARS):

The South African tax year ended on 28 February, so the timing is right, and with the Revenue Service's eFiling system available this year even from mobile phones, more South Africans than ever will be expecting to deal with the tax office electronically.

Of course, even if you are an ABSA customer and expecting a tax refund, you should still be suspicious, not least because your bank won't send you login links via email.

Banks avoid sending you links to their secure banking sites precisely so they can tell you, "Never click on emailed login links, because they won't be from us."

There are other tell-tale scam signs here, too, if you are alert to orthographic (writing and spelling) clues, such as these:

The Revenue's online service is called eFiling, not EFilling.Dates in South Africa are written with the month in the middle, where it jolly well belongs, so 18 April 2013 is 18/04/2013, not 04/18/2013.

Note that you shouldn't rely on spotting phishing emails and websites only by looking out for errors of this sort, because there is nothing to stop the crooks being careful.

But if you spot something that obviously doesn't look right, assume the worst.

If you do click the link without thinking, you won't go to Absa's website, but instead to a hacked website in Korea.

The server itself isn't owned by the criminals - it's just being "borrowed" to provide free IT services for this phish.

The Korean site doesn't actually host the fake banking pages, but instead simply bounces you, using an HTTP redirect, to a hacked site in the Netherlands, where the fraudulent login process begins.

The visual appearance of the fake pages is professional, largely because the crimimals have ripped off Absa's own HTML and JavaScript code to reproduce the look and feel of the real thing, right down to the virtual keyboard asking for your PIN:

Then you are asked to enter your password:

Note that Absa's login system usually only asks you for a randomly-selected subset of the characters in your password, as a precaution to stop a crook from learning your entire password from a single login attempt.

This doesn't improve security enormously, but it does make things harder for a cybercriminal or a shoulder-surfer, and it is a designed-in part of Absa's login process.

So, take the trouble to familiarise yourself with what your bank advises you to look out for.

In this case, the phishers are greedily asking for your entire password in one shot, presumably so they know all the possible characters for next time; this should be a tell-tale sign that something is wrong.

The next screen asks you to put in the Random Verification Number (RVN) code that Absa sends to your mobile phone as a one-time password:

This should ring alarm bells even more loudly.

Absa specifically documents that the RVN is used only in special cases involving more than simply looking at your balance, which is what the original email was inviting you to do:

When creating a new beneficiary, changing transfer limits, or other kinds of sensitive transactions, a special one-time password, called a Random Verification Number (RVN), will be sent to your cellphone. You must type this into the indicated field for verification. Just before the payment is made, another one-time password will be sent to your cellphone, called a Transaction Verification Number (TVN) to confirm the transaction. These passwords can only be used once, and dramatically decrease the risk of being defrauded.

The only plausible reason you'd be asked for an RVN code when you thought you were just checking your balance is that you aren't talking to the bank's real site, but to an imposter site that is attempting a Man-in-the-Middle (MiTM) attack.

The idea is that you perform what you think is an innocent transaction with the bank, while the Man-in-the-Middle commences a simultaneous sensitive transaction with the real banking site - such as telling the bank that you just agreed to pay out money to him.

When the bank asks the Man-in-the-Middle a question he can't answer, he asks you. And what you tell him, he tells to the bank as if he knew it all along.

You think you're talking to the bank and asking it to do X, but you're really talking to the MiTM, who uses the security information innocently submitted by you to ask the bank to do Y.

This is why it is vital to keep checking, throughout any online banking session, that you are on the bank's real site.

If you're an Absa customer, for example, you need to know that Absa's internet banking site is called https://ib.absa.co.za/, and that it uses HTTPS, or secure HTTP.

Don't look in the web page itself for "proof" that the site is secure, because the crooks try to fill their fake pages with security reassurances.

In this phish, for example, the first page in the fraudulent login sequence advises you to watch out for phishing scams, and even correctly advises you never to login from links sent via email:

Always look in the address bar (which can't be directly modified by a web page, only by the browser itself) for the tell-tale HTTPS padlock.

In most modern browsers, you can also click on the padlock in the address bar to double-check who owns the secure website:

The identification information in an HTTPS transaction isn't infallible - it's a bit like the certification stamp on a certified copy - but if it is wrong or missing, then you can be certain you are being tricked.

Finally, you're asked for the Transaction Verification Number (TVN):

With your PIN, password and a TVN, the crooks could, at least in theory, pay out money, but only to someone who is already setup up as a beneficiary on your account (a person you pay money to).

So they might be able to pay your electricity bill, or send a gift to your mother.

But with a one-time RVN as well, the crooks could, at least in theory, add themselves as a beneficiary first, and then use the TVN to send themselves some of your money.

So always be on your guard.

In this phish, any one of these signs should have been enough to put you off, even if you were an Absa customer awaiting a taxation refund:

Orthographic (writing and spelling) errors in email.Clickable link to login page in email.Wrong link, going to a site in Korea.Link redirects to wrong location, going to a site in the Netherlands.Login site not correct for Absa.Login site not encrypted with HTTPS.Non-standard procedure for password entry.Inappropriate request for Random Verification Number (RVN).

If you detect the smell of phish at any point in the process, pull the plug.

The longer you stay "on the hook," the more security information the crooks will end up getting out of you.

Follow @duckblog


View the original article here

Friday, March 29, 2013

Facebook Class Action email - it looks like a phish but it's the real deal

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

The news that Facebook is turning facial recognition back on in photo tagging has a silver lining.

Many of our readers have been inspired to revisit their privacy settings and to make sure those settings really are what they intended.

Reviewing what the cyberlifestyle gurus call your security posture is something well worth doing once in a while.

Like regular trips to the dentist, or routine prostate examinations, it can save you a lot of unexpected grief in the future - but it doesn't leave you numb in body, mind or wallet.

This, in turn, has led a number of you to ask about a Facebook-related email that's doing the rounds lately.

It certainly has some of the hallmarks of a phish:

There's an arresting headline:

NOTICE OF PENDING CLASS ACTION AND NOTICE OF PROPOSED SETTLEMENT

There's the assurance that this email is lawful, objective, legitimate and, indeed, important:

A federal court authorized this Notice. This is not a solicitation from a lawyer.

There are millions of dollars up for grabs, if only you are willing to join in:

Facebook will pay $20 million into a fund that can be used, in part, to pay claims of Class Members who appeared in a Sponsored Story.

Got your attention? Good. Because there are some worrying things, too.

Like the sender's email address, which seems unusual for something with the imprimatur of a federal court:

From: legalnotice

Or the online call to action, asking you to click a link the in the email:

Please visit www.xxxxxxxxx..com (if clicking on the link does not work, copy and paste the website address into a web browser)

If you're worried about web links in unsolicited emails (and you should be!), you can fall back to the good old telephone.

But you have to a phone number given by the sender, which is usually a no-no.

That number is always going to terminate where the sender wants it to, so a bogus sender can answer to make you believe you've reached a company with any name they like:

You may also contact Class Counsel, Robert S. Axxx of the Axxx Law Firm, by calling 1-555-555-5555

Or you can send an email, though interestingly to an address quite different from the already-unusual one used by the sender.

Oh, and there's just a touch of bait-and-switch, if you read carefully:

Each participating Class Member who submits a valid and timely claim form may be eligible to receive up to $10.

That's it, I'm afraid.

That $20 million pot will give you a maximum return of $10.

If you dig further, you might find even more curious facts that aren't immediately obvious. You'll need to click the link and drill down into a number of documents, including a 46-page PDF entitled:

PLAINTIFFS MOTION AND MEMORANDUM OF LAW IN SUPPORT OF MOTION FOR ATTORNEYS' FEES AND COSTS AND CLASS REPRESENTATIVES' SERVICE AWARDS

The bottom line, roughly speaking, is that the lawyers are hoping to claim approximately $8 million in fees. So there'll be $12 million left to pay all the possible claimants.

? You'll get $10 if there are 1.2 million claimants or fewer. But if there more than 2.4 million claimants, your share would be below $5, and the court might decide that it's too hard and expensive to distribute that many payouts. In that case, a named charitable fund may end up scooping the whole pot. After the lawyers' fees.

Fact is, however, that this isn't a phish.

It's a genuine class action, with a genuine proposed settlement for Facebook's disputed Sponsored Story system.

So the lawyers are entitled - indeed, I suspect they're probably obliged - to try to contact you to advise you of your involvement (whether you expect it or wish it), because your own legal rights are affected by this matter.

There isn't a simple opt-in here.

You can opt in, and you might get $10, but you waive the right to sue Facebook independently if you do. You can opt out, get nothing now, but maintain the right to take your own legal action later.

Or you can do nothing. Then you automatically waive your right to sue Facebook later, as well as any claim on that $20 million mountain of moolah.

Since this is the default, "neither in nor out", you can see the legalistic purpose of the initial email.

And, to be fair to the lawyers, there probably isn't any other reasonable way they could contact you, since most Facebook users are little more than an email address, at least as far as Facebook can reliably tell.

In short, this email, and others like it against other internet companies, aren't phishes. They're lawful communications that couldn't be done in an efficient, timely and effective fashion any other way.

First problem is, I think they look sufficiently phishy to teach us bad standards once we realise they're legitimate. If this one's OK, why not similar emails that are utterly bogus?

Second problem is, I can't think up a way they could be made clearer from a security point of view without making them ineffective in getting the underlying message across of what your options are, and why.

How would you approach this sort of communication in order to make it set higher security standards without losing clarity and completeness?

Share your ideas in the comments below...

Follow @duckblog


View the original article here

Friday, March 15, 2013

Anatomy of a phish - how crooks hack legitimate websites to steal your details

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Old-school phishing is where cybercrooks lure you into logging in to your bank account on one of their websites.

When you enter your personally identifiable information (PII), as you would on the bank's real site, it gets uploaded to the crooks instead of to your bank.

The idea, of course, is that they then use the credentials they just stole to start draining your account.

So phishing is still worthwhile to the crooks, even though it doesn't seem to be quite as successful as it used to be. Many of us have learned to take great care when we're banking online, and to check for the "vital signs" of a scam before we trust a website with our usernames and passwords.

Nevertheless, the phishers are still giving it all they've got. By combining simplicity with accuracy, they're creating banking scams that are much more believable than the crude and misspelled emails and websites that were common a few years ago.

If you pick your moment, or just get lucky, there's still money to be made.

In Australia, for example, today (at least in Sydney) has been a very wet and gloomy public holiday.

Just the sort of morning to loaf on the couch with your laptop or your iPad and goof off online, where you might have received an email like this one:

Many banks now have a closed cloud-style email service built into their internet banking sites. The idea is that you'll get into the habit of logging in securely to read important messages, rather than believing what arrives in insecure emails.

The bank still sends you emails, but they don't contain any detail - they just give you an overview (e.g. "your statement is ready"), and advise you to read the full message on the secure site. A bit like the message here, in fact.

But what your bank won't do is to invite you to click a link to get to the secure site. They rightly leave you (indeed, they urge you) to find your own way to the banking portal, so you're not at the mercy of the URL embedded in the email.

So the link here is certainly phishy - it shouldn't be present at all - but it doesn't look like the sort of obvious phishing nonsense you often see.

You probably know what I mean: weird and unlikely domains such as really.your.bank.wefljdrsecxr.example.org that are an instant giveaway of bogosity.

In fact, this phish links to a government website in .cn (that the People's Republic of China, or PRC):

The government site seems to have had a security lapse, allowing the crooks to add a small and simple web page called nabau.html.

This page silently redirects your browser elsewhere by using this HTML:

The redirect takes you off to another hacked site, specified in the URL as an IP number rather than as a domain name.

This presents you with a bogus login page hosted on a web server (it looks like part of the Computer Science department) at a Colombian university:

Ironically, this bogus page helpfully advises you to keep up to date with anti-virus, firewall software and the latest patches, and urges you to report phishing scams to NAB.

When you click Login to submit the form, the POST request (HTTP's name for an upload) goes to yet another hacked web property. This one is a student vacation site in the USA, apparently with some insecure plugins in its blogging subdirectories.

You never get to see the site's main page, which is unexceptional:

Instead, the web upload that is linked to from from the Colombian university page gives the crooks their first page of login data.

Then you're shuffled back to the server in Colombia to face a request for another page of PII:

The POST request on this page uploads your formful of data to the same place as before: the US student vacation site.

This time, the vacation site bounces you back to Australia, rounding off the phishers' journey.

You end up unremarkably on National Australia Bank's own site, albeit that you're on the regular main page, not amongst the internet banking pages:

Let me be quick to say that you ought not to fall for this sort of phish:

NAB wouldn't have put a link in the email, so you ought not to have clicked it.None of the so-called banking sites referenced a nab.com.au URL.None of them used secure HTTP, also known as HTTPS.

(HTTPS is the protocol that puts a tiny padlock in the address bar at the top of your browser's screen.)

Nevertheless, this phish didn't take you to any sites that would have stood out, under normal circumstances, as part of the cybercriminal underworld.

It relied on three unremarkable and legitimate servers, owned by legitimate organisations and operated by unsuspecting sysadmins, in three different countries: PRC, Colombia and the USA.

That's why even self-proclaimed "safe surfers" - people who back themselves not to wander off into obviously-shady parts of the web - should consider themselves at risk.

Be careful out there. And that applies whether you're browsing or running an online business.

The crooks want to redirect your browser into harm's way, and they want to use your servers to help them do so.

Follow @duckblog

Running a web server at home?

Why not try out the free Sophos UTM Home Edition?

You get web and email filtering, web application firewall, IPS, VPN and more for up to 50 IP addresses. You can also protect up to 12 Windows PCs on your network with Sophos Anti-Virus!

(Note: registration required.)


View the original article here