The ultimate phishing tactic?

  • Thread starter Thread starter Banned member 185991
  • Start date Start date
B

Banned member 185991

Guest
I saw this earlier:
2beaf1f76258af7f15dc59c8ca86ce6f.png

source: http://thehackernews.com/2017/04/unicode-Punycode-phishing-attack.html

How awesome is that?

I <3 Blackhat
 
Very good. Very good indeed. Strange that Safari is just like "Nah".
 
I read this shit today and thought of posting it here but refrained thinking that people would really exploit this. Well.. :p btw fix is on the way
 
This is big.

I've been noticing more and more spam from these xx--encoded domains. This is probably part of the reason. If I decoded the domains they'd probably read like some famous western brand....

Thanks for the share.
 
this exists since ages. I really thought it's pretty common for attacks, the phishing 101

nothing prevents you if you're opening unsolicited emails with brain.exe shut down
 
this exists since ages. I really thought it's pretty common for attacks, the phishing 101

nothing prevents you if you're opening unsolicited emails with brain.exe shut down

So you knew "since ages" that if only foreign characters are used in a domain, major browsers would bypass converting them to punychars?

Sure you did Einstein.

If this is "Phishing 101" - then what do you teach in "Phishing 201"?
 
Don't worry guys, Chrome browser already patched it in his next update version.

If you use Mozilla, you can change some advanced settings and then you're safe.
 
Sure you did Einstein.

If this is "Phishing 101" - then what do you teach in "Phishing 201"?

He is right, this has been around for a long time... Almost 90% of the malware around is using this method for hijacking user sessions or credentials..

If you think this method is the most advanced one out there than boy you got some reading to do...
 
He is right, this has been around for a long time... Almost 90% of the malware around is using this method for hijacking user sessions or credentials..

If you think this method is the most advanced one out there than boy you got some reading to do...

"Almost 90% malware" ?!?

What are you smoking? That is COMPLETELY untrue.

Also, I never said anything about this being the "most advanced one out there". I simply dismiss calling it "phishing 101".
 
Learn something new every day i guess.
The trick can be old, and i used something similar for spoofing usernames, but i would have never thought about using it this way.

Although if these domains arrive via email, the sender's email address would need to be spoofed too for maximum effect, otherwise it wouldn't work, at least not on me. :)
Until there's no browser fix, it's a quite good prevention method, what's mentioned in the last few paragraphs of the article.
 
@Brian Alexander Read first, have an opinion later, chew a gum instead of talking during the in between period.

The attack vector is 15 years old, it even says it so explicitly on the exploit explanation page. What is new is this specific implementation's bypass over the browsers defensive measures.
 
Back
Top