A new type of phishing attack. Works on savvy users.
azarask.in
azarask.in
I just didn't expect the first result in google would be a phishing website and I actually tried logging in to facebook through the site. The phishing site actually took my info and logged me in to facebook, but facebook immediately warned me that I had logged in from a domain that wasn't facebook and that I needed to change my password.
They do:
I read it the same way to.
It seems to be an iPhone proxy: http://wiki.github.com/tcurdt/iProxy/
Didn't look much further into it but it doesn't look like a phishing site.
Anyone have any good experience or tips :)
Also another win for Single-Site Browsers like Fluid and Prism. I wouldn't expect to see Gmail in my main browser window.
And for those, like me, who had not heard of Single-Site Browsers, here are some links:
However, I'm at a point where I need to figure out a recovery plan, because, you see, my Dropbox password is in 1Password as well, and my email password too. So, I could imagine a scenario where something gets compromised and I have a hard time getting it back…
I've been using LastPass for the last week. It has Chrome extensions which on my personal Macs and work Windows machines. The Chrome extension UX is a bit too rough for me to recommend it to non-techies but I think the idea and execution is sound.
Recommended. I don't use it for Gmail or banking passwords of course.
I would have to try it, but this looks good. Thanks for the tip!
added bonus:my wife has access to my password file because of dropbox, so when i add a new password for some service she may need, it immediately and securely shows up on her mac.
I don't think I've seen the latter, though I would love to see some way of sharing just a part of my DB with my wife. (she has a pretty weak master password, so one shared DB would not work well for me)
oh, and the 1Password/DropBox combination is brilliant
Brilliant, I'm going to do that right now. Thank you!
My personal favorite feature: the keychain-package is just a folder / bundle, and it contains a website... which is capable of decrypting your passwords, given your master password. Which means you can recover your passwords without the application, on any machine with a web browser. Including through the Dropbox web interface, without needing to download it locally.
Go for it, they've made an excellent product.
* shrug * 'tis strange.
Between that and noscript (and enough savvy to spot even slightly-wrong websites), I haven't had any problems. I don't think this attack would work on me because I've long kept email segregated from normal web browsing due to other attacks, which rely on you clicking malicious links while logged into the site they want to get your information from. So I would, if anything, just think I'd clicked on the wrong shortcut and close out of it rather than logging in. Score one for paranoia? I've never been infected by spyware/viruses/etc.
I tried Chrome and still use it for certain things, but I refuse to use it as my primary browser until it has NoScript or equivalent.
You might be able perform the same attack using hanging HTTP requests to load a stylesheet and favicon at the bottom of the page. Defer completion of the requests for several minutes until it's likely the user has moved on to another tab. Stylesheet displays the hidden phishing UI, favicon is loaded. Bam, same effect.
Alternatively use a meta refresh tag to simply redirect to an entirely different page.
That was going to be my suggestion too. In fact that would be my preferred attack because you could change the URL to something that looked "kosher" as well.
[edit]
The "no javascript" control is under "Options / Under the Hood" click the "Content Settings" button. I see the ability to disable javascript and add exceptions. Javascript can be enabled by clicking on the icon at the right-hand side of the address bar. Cool!
Clever idea. Has the demo worked for anyone? (Edit: I see below that posters report that this worked for at least some versions of Chrome on Windows)
Its a never ending problem owing to the nature of computers being easily programmed... its lucky phishers are so extremely bad at what they do - it certainly within reason to abuse existing websites far beyond what we see regularly - if you can find and use the right type of exploit then you can actually just use google or whatever to provide the exact login page, with correct URL etc, then just steal the input. Although saying that... it can be done so well that I wouldn't actually know if it ever happened... maybe there are some smart ones out there and the swarms of poor attempts are just a distraction from a much more serious potential problem?
yes, i think you're just seeing what the bad ones do and the good ones never enter your consciousness. good bank robbers and jewel thieves have never been caught, and i'm sure good virus writers and phishers have probably never even been detected. think of a gmail login phishing attack that, after capturing your information, re-posted it to google's servers so it actually logged you in. by the time you stopped to think about what just happened, your browser is already at mail.google.com with a green everything's-ok address bar.
the phishing site that plants the stuff could even get away with being massively obvious - so long as people look at it they could be infected.
of course finding such exploits is non-trivial... but people are doing it with some regularity.
(EDIT: incidentally the only way I log in to Google Mail or anything I log into is by typing in the URL specifically, e.g."mail.google.com", so this is pretty much the only way to hit me up with this sort of attack - if I get "magically" logged out then I might get stung, but it seems doubtful... its just too suspiscious)
http://msdn.microsoft.com/en-us/library/ms997537.aspx http://msdn.microsoft.com/en-us/library/ms646293%28VS.85%29....
for example. although i'm not sure how good they are these days... i honestly can't remember exactly which technique i used but i managed to make a keylogger with excel/vba once with apis i randomly looked up on msdn - it was just to prove a point though, i haven't really done anything more elaborate than that.
the difficult bit is really getting code to run. that i have no idea about, but i've heard about exploits from time to time, usually when they are fixed :)
I think Yahoo does that, and so does my bank. Of course, one has to bother creating the seal, but it's an easy one-time step.
Actually, besides uploading a pic, they also allow text or a doodle. In case anyone is curious, it's here, in Portuguese: http://www.banif.pt/xsite/Particulares/Banifast/ServicoBanif...;
Their 'password' security is pretty good, too. They have two levels of 8-digit PINs (one to 'read' the account, then another to 'write', i.e. move money out). They only ask for input of 4 out of those 8 digits (randomly, e.g. 3rd, 5th, 6th, 8th), using a on-screen pad (defeats key-logging).
I'm not exactly sure what I want as far as design vs. usability but it feels bad right now to have one password for the amount of data that it's protecting, especially when I have to enter it occasionally for more "fluffy" services.
I wouldn't really mind getting my Reader account broken into. But AdWords, with mounts of sensitive data and the ability to inflict huge charges on me? Google Checkout, with names and addresses of half of my customers a finger-flick away? Gmail, which could probably be bootstrapped into a password reset at my brokerage, bank, or GoDaddy? shudder
Google, if you want more of my money, I'll happily pay for a dongle. If you don't know how to make one, have somebody break out the petty cash drawer and buy Blizzard, I hear they have one for critically sensitive information like WoW characters.
Other google services like adsense require password confirmation even when logged into gmail, but I'd be less apt to 'forget I was trying' to log in to that, and it would be less likely that random people would be users, so it would attract more suspicion.
Still, This is something I'll watch out for.
Do you have the same practices with facebook and your bank account as you do with gmail?
Still, it's a pretty clever phishing attack, and I bet it would fool a lot of people. What I didn't get from the article was whether this was something Aza Raskin has seen, or a is it something that he thought up. If the later, then I'm not too sure about the scruples of publishing this trick while promoting the password manager in FF.
Slightly related: I think new tabs should inherit history, so that I can clearly see how I got somewhere. If I don't remember having a tab with my bank login in it, and I see that I got there from reddit, I know things are very wrong. As it is, Most things I find on reddit open in tabs with no history, so they'd look exactly like I opened the directly.
The nice thing about a password manager with form fill is that it would prevent this "attack" because the domain name does not match the spoofed site. I wouldn't even have the ability to have it fill my Gmail password in for me.
Phishing is so ridiculously easy that I doubt the phishers will need to display any technical sophistication at this level for a long time to come.
As long as users will happily click on whatever lands in their inbox this is total overkill.
Is there any password manager for Chrome like the proposed one coming out for Firefox?
You'll have to get a very similar address to fool me, and good luck making the page look exactly the same as the original. The rounded buttons and differently aliased text on the attack page were enough for my red flags be raised.
The only reason you noticed the different buttons and different text is cause the author decided to save himself some time and just replaced the page with a screenshot of how gmail is rendered on their computer.
That's because he used a screenshot...
He did mention it was only tested on Firefox though, I wonder if it would be hard to make it work on the other browsers?
My bet though is they won't become so wise and will instead just rely on displaying my private image and phrase on the login screen.
https://chrome.google.com/extensions/detail/ecpgkdflcnofdbbk...
However it is an extremely clever new attack vector, and I don't know how browser manufacturers can stop this attack.
For example, I don't normally have gmail open in a tab (I prefer to use mutt as my email client), so, to see "Gmail: Email fro..." - as I currently see in the tab directly left of this one - is disorienting for me. I expected the article on phishing.
However, even without it, this attack isn't exactly mature. Different browsers will render the javascript differently. My browser tried to execute the page-changing javascript as it was loading the page, and I was viewing the page. Obviously, in a few months or so, this will change, but for the first reason, I remain firm in my stand that this attack doesn't really mean much.
But the 1Password thing is a recent thing; I could easily have fallen for one of the bank attempts, since I usually leave them open in another tab while it's loading, or if I get bored, so it's not unusual for me to tab over and be surprised by a "you've been logged out!" screen.
If it weren't for Roboform this might work if it were some service I actually used.
It's so interesting how not using an adverb was a mark of bad grammar, so now people over use them, which is way worse to me for some reason.
This won't work against most savvy users on their best days. It will probably work against most savvy users on any given bad day.
What's interesting to me is that it'd be pretty easy for a site owner to target very specific users who visit their site. I could easily see this being used by a rogue employee at a web company to gather credentials/info on a specific target VIP and then covering their tracks later.