The ultimate phishing tactic?

  • Thread starter Thread starter Banned member 185991
  • Start date Start date
"Almost 90% malware" ?!?

What are you smoking? That is COMPLETELY untrue.

Also, I never said anything about this being the "most advanced one out there". I simply dismiss calling it "phishing 101".

I dont usually respond to childish non fact supported troll posts but..

With how many phishing methods are you familiar with ? Have you analyzed any malware sample so far ? Do you know how to even decrypt and analyze a bin ?

This and various other methods are used in today`s common malware. How do you even think the researches found out about this ?

If you cant use your brain than at least you can use your eyes and read.. ( but i guess you still need a brain to process this info )

Hackers can use a KNOWN vulnerability in the Chrome, FF and Opera web browsers.
Homograph attack has been known since 2001.

This last report is just a workaround for the browsers and even when chrome and other browsers get this patched, "persistent people" will always find another way to locally hi-jack or manipulate browser sessions.

But luckily for you buddy ignorance is a blessing.

Cheers
 
this is the best 'fishkin' method ever
 
So you knew "since ages" that if only foreign characters are used in a domain, major browsers would bypass converting them to punychars?

Sure you did Einstein.

If this is "Phishing 101" - then what do you teach in "Phishing 201"?

Yeah cause I regulary have to read security bulletins and stuff like that. Part of my work consists of knowing attack vectors and educating coworks how to avoid that get shit like that in our daily mails.
No need to be butthurt or upset if someone knows more or long before you. Shit like that worked mid 90s for ICQ usernames iirc.

If understand that "new" vulnerbility correct it's just an extend of something that worked and works at least for 10+ years. To be fair the trigger of the flaw has changed a bit, but also some browsers had settings to not show punny code or plugins that turned punycode to unicode.

Also that stuff is mentioned in the RFC as "may be converted to punycode" and not must. So the flaw may have it'S starting point there. Also those RFCs are from the early 2000s.

Anyway, maybe you wanna educate yourself a little more on how URLs, IRIs & Punycodes work please read the according pages on the RFC and W3org as a basic.
I linked em below for you:

rfc3987
rfc3492
http://www.faqs.org/rfcs/rfc3490.html
http://www.faqs.org/rfcs/rfc3491.html
http://www.faqs.org/rfcs/rfc3454.html
https://www.w3.org/International/articles/idn-and-iri/

Also I would almost bet, if you generate an url or to be exact a domain name long enough you will trigger some hardlimit that will make the browser discard the conversion to punycode. even if the RFCs for http don't specify or force a hardlimit for urls doesn't mean that browsers won't enforce such.

This attack vector becomes even more fun I guess when you take into credit that some antivirus tools out there bring their own ssl certificate that is link between your session and the original server.
But I don't want to over stress your brain, as this maybe covered in Pishing 301...
 
this exists since ages. I really thought it's pretty common for attacks, the phishing 101

nothing prevents you if you're opening unsolicited emails with brain.exe shut down


I am really astonished by replies too.
 
Its the same old story. Dont click random links to important sites.

type apple.com and your good.
click some link on a forum to apple.com and log in... then you get everything you deserve.
 
Kinda alarming, I'd fall for these phishing sites as I seriously have not idea this could be possible. All those potential data/money that could be stolen/taken.
 
I'm intentionally using Chrome right now on my 2004 XP machine & it's displaying the www.xn--80ak6aa92e.com domain.

So this doesn't look like a very new or sophisticated attack.
 
Back
Top