Stopping phishing campaigns with Bash
blog.haschek.at
blog.haschek.at
I was hired to look into why a WordPress site was so slow back in 2010. It turned out the site was hacked and they were hosting a spam viagra site on the side. When I brought it to their attention, the owner asked: "Can we keep it up? It will help our traffic numbers for investors and probably our Google ranking."
I literally face-palmed.
On topic, it's crazy how willing some people are to defraud their investors.
Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised).
Plus, you didn't solve anything, from the pattern you used it's pretty easy to cleanup the data for the adversary, get rid of your garbage and put the thing back on the next day, so you've only temporarily disrupted their operation.
A more appropriate response is to report the abuse who manages the infrastructure (most likely a legitimate provider) and the domain registar; both usually have appropriate channels and response procedures just for that. If you feel kind and keen to do some free work, you can find out if the infrastructure has also a legitimate purpose and contact the legitimate administrator. Also, there are a lot of abuse lists that accept contributions, as in submitions for malicious sites, where you can report this (so it gets fetched by a variety of stuff and blocked by others while it's operational before it gets eradicated).
I understand this does not give you any credit or allow you to write a blog post about looping requests in bash but still.
As per the box legitimate owner, while I agree that there is all kind of crazy out there and you can avoid this if it makes you uncomfortable (abuse-at-provider will most likely contact them shortly without involving you), I don't see the lash out or strike at you scenarios likely, in my experience usually you get a thank you.
To be clear, I'm not suggesting email "Bro, you are compromised, bye", I mean, you can just inform them that you received the link and were taken to a phishing site that looks like hosted on his machine, attach screens, advice them on next steps if you want to go the extra mile in niceness. You're doing them a favour without breaking any law, why would they get mad at you?
I have, and my experiences have been that:
* The domain registrars are apologetic and well-meaning, but tend to explain that they aren't empowered to take this stuff down without being ordered to by Law Enforcement or similar. There typically isn't a mechanism available for getting LE to respond before the phish campaign is over.
* The hosting providers chosen by phishing sites are either "bulletproof hosts" who are tacitly complicit, or more commonly are so low-end that the support departments are massively underfunded and abuse reports take eons to be processed.
Either way, the phisher achieves their objectives before the site is taken down. That being the state of affairs then, although I don't choose to use the kind of tactics outlined in the blog myself, I find it pretty hard to condemn those who do.
EDIT: I do agree with you that submitting the URL/IP to abuse blacklists is a helpful and positive thing to do. Here are a couple of submission URLs (there are many more): https://pulsedive.com/submit/, https://www.abuseipdb.com/report.
I understand the will to take action, but doxing a phishing site can cause collaterals you did not foresee and you want to avoid, legally and otherwise. And it doesn't solve anything, as previously explained, it just temporarily turns them down, which leads to a comparison between the time invested by the adversary (who will block your source as first thing) and yours (and you don't want to go there). Definitely is not something to suggest to inexperienced people as "a good way to fight phishing" (which they'll take literally, because it looks cool). There might be exceptions to this (as in, calculated risks) but they go far beyond what makes sense for someone alone to do.
Fortunately I got ahold of Roots via Twitter and the scam seems to have been shut down.
Think of all of the false take down requests registers would receive.
[0] https://www.icann.org/resources/pages/faqs-2013-11-26-en
Unless of course it's behind Cloudflare - then you cannot find out whose infrastructure the criminals are operating from and Cloudflare itself does not give a fuck. Best case scenario: they will forward your complaint to their customer - an unknown party to you who might be the criminals themselves, putting you in danger.
Thank you, Cloudflare.
Turned out someone uploaded like 1000 child pornography images to the demo site, cloudflare didn't once send me anything or block an image before being uploaded.
I wrote their support and they pointed me to the abuse form you mentioned (which would had reported the content to myself?)
I thought they'd look into their logs and send interpol the uploaders IP addresses but no, they didn't do anything.
In the end I got interpol and the local BKA (Federal Criminal Police Office) and they were so awesome and I prepared excel sheets for them with all ip addresses and log entries of every consumer and uploader.
all attempts got responses like "cool, but we don't do any of that. please contact google safe-site(tm) beta or something and get it blocked on the browser via that".
Everyone here posting that they replied probably used email from a domain that is an expensive paid customer from them. I used a @gmail one.
> Phishing sites can be / are often served by compromised hosts, so you might as well end up doxing a box who is not run by the bad guy, causing all sorts of mayem for the legitimate owners / admins (in addition to they be compromised).
Well, they are already compromised. If they were lucky, it was just an automated system that scanned for vulnerabilities and only dropped the phishing webserver – for now. It could be used as a jump box to compromise further systems in the host's network. Who knows what else may be running in the box. If it is being used for 'legitimate purposes', whatever purpose it is, it is at a large risk.
The fact that it is still compromised indicates that it is not actively/properly monitored.
Taking it out will draw much more attention to the system from their owners. If I had a compromised system that I didn't know about and it was taken out, I'd be thankful it wasn't left running for longer.
It's not the 'correct' thing to do, but I'm not convinced that putting the system out of comission is more harmful than leaving it running doing who knows what.
Anyone could hack a site put malware and if they are caught claim they hacked in to remove the malware they put.
I phished the seller into giving me their Zelle email which was a full name and presumably tied to a legit bank account with a legit person associated with it.
I reported them, will all the facts I'd collected to the AG office in the state I believed them to be in (OH- b/c they offered shipping to anywhere + local delivery in Cleveland). I reached out to other dog owners that I could identify and urged them to also file reports.
I passed along this information to a friend who works in cyber crimes law enforcement (specifically in crimes against children). He verified the information I provided to the best of his ability and passed to his peers in another agency.
Months later, nothing except an automated thanks from the AG office and the site is still up.
The main issue I'm told is I don't have any victims who actually tried to purchase and never receive a puppy.
https://www.qualitygreatdanepuppies.com/available-puppies
"Johnny" is my dog. That photo is in front of my old apartment.
I do not condone this approach of striking back, but I am frustrated that even when I identify the culprit of a scam, theres nothing I can do.
I've successfully used the DMCA against spammers who used my photos in their spam. Hosting providers and platforms usually have process in place to deal with copyright infringement even if they're turning a blind eye to fraud.
Unfortunately, that is the only success I've had against them.
Not saying this to keep anyone from repeating this, though; just that when doing so, keep in mind that you're probably not just hurting a scammer alone.
This is what I expect the relevant text in the CFAA is...
knowingly causes the transmission of a program, information, code, or command, and as a result of such conduct, intentionally causes damage without authorization, to a protected computer;
When in doubt - yes. It's the same reasoning forbidding you from shooting criminals in the street, you'd just open up mob justice.
Of course, this is a pretty clear cut case and you might argue that this is an emergency (as people are clearly in danger of being scammed unless you act right now), but overall this is a very blurry line.
I'd be careful with computer crimes on the Internet though.
Exactly. Let us say you break into a shop owned by some mafia to put out a fire, then you might be fine w.r.t. authority, but you might be in trouble w.r.t. criminals. Similarly, say you break a car window to pull out a pit-bull left alone in the sun, you might have some issues with the owner if he turns out to be part of some drug trafficking gang.
There is no reason to believe that phishing websites are run by script-kiddies, there are obviously criminal rings running all sorts of businesses on the Internet too. I would rather leave the work to the authorities rather than risk going through trouble with unknown criminals, just so that I could have my funny revenge over them.
Unless authorities are looking for an excuse to prosecute you, of course, but there's plenty of bad PR to be had for authorities acting on behalf of criminals trying to steal people's banking credentials.
Depends on who you fear more: law enforcement or organized crime.
It's definitely better to not do this.
Always remember that U.S. courts are courts of law, not courts of justice. That's usually a good thing (less left to interpretation), but it does have downsides.
Are they? My impression is that US courts rely heavily on the whims of a jury and the judge, leading to very different outcomes for similar cases. Though often leading to injustice (heavy punishments for poor and/or black people, light punishments for rich and/or white people) rather than justice.
Hard to say if this would be a better fit for the US though -- I've no idea if that's causing issues elsewhere in more corrupt societies or not.
Now you pay up or cops are called.
Trying to play a hacker may get you in more trouble unless you really are one.
I did the following:
- I found out where it was hosted and send them an email explaining them why and how that shop is a scam
- I found out where they hosted the domain and wrote the registrar an abuse email
- I wrote an email to the banks where the bank accounts where active
The scammer had a webchat module active and he/she did wrote back to me, nothing came out through that, nonetheless:
next day, both webshops were gone due to being taken offline from the hosters.
I do believe, that they do have a chance because literaly no one cares. I have seen mentioning of one of those two shops older then 6 month. I pissed at them with very little effort in a very short time.
I do hope i helped out.
I've seen reports of this in the UK at least, maybe they managed to stop it.
We got similar spam mails in our work inboxes. Whipped up a little ruby script that spammed bum login data to the spammer's form url. We had our scripts running on a couple of Heroku instances and all.
At some stage we realized that the password field in the form accepted arbitrarily sized payloads. So we base64 encoded some 10MB file and sent that as the password. The thinking was if we could not DoS them, we can at least clog up their works with some real hefty payloads.
More can be seen here: https://github.com/dj-louw/spamscam
It would be quite interesting to do a study on both options using a honeypot-account (to detect whether the login could be extracted by the spammer).
But yeah you are probably right. 10MB passwords possibly made it too easy for the scammer to filter out the bum data.
We did only make the 10MB change very late in our attack, so the scammer got 1000's of fake names and emails before we cranked up the mass of each individual request.
I also try to send an email to the registrar "abuse" email to let them know that a specific domain is hosting a phishing page (with the exact link as proof). That takes it down quickly as well, which forces the website owner to do some remediation.
They hit back, ten times as hard, and completely destroyed a well-established forum, with thousands of users, that had experienced an annoying (but not crippling) "penis pill" spam attack.
Backups are for, like, squares, dude.
We live on the edge, dude!
Extreme! YOLO!
In all fairness, the person involved was a truly brilliant young man, and the experience pretty much shattered him, emotionally. He has yet to recover from it.
In a way, it can be satisfying to be able to say "I told you so," but seeing the human cost kinda takes the fun out of smugness.
Can I ask what made it hard / infeasible to continue once the spammers had stopped hitting back?
> seeing the human cost
It seems the forum meant a lot to him/her
My understanding is that a forum spammer started registering fake accounts, and then did what they do. The admin saw this. He was quite smart, and figured out who they were, then executed some kind of attack on their server. I think it was a DDoS attack.
When they responded, the used a bunch of privilege escalation attacks to promote some of their registered users (It was a badly-maintained phpBB site; otherwise known as "Swiss Cheese"), and blew away a lot of the site structure and templates, so it basically imploded.
Yeah, it was his "baby." He was also involved in a running battle of nerd egos with some other folks, who used the incident to discredit him, and drove him out.
Crazy spammers who have time for such things
Sad to hear how this affected him
You'd be surprised how easy it is to scan+pwn some wordpress site left in default config or vulnerable to the latest joomla exploit. They then upload a $20 phishing kit and start spamming. If you look at the directories' root in the path you sometimes get lucky enough to get the zip/tar file they forgot to remove (includes their email, to which stolen creds are sent, you probably spammed the crap out of their mailbox too). A few times I've even found unsecured webshells they left behind (just booted them out, got emails of people who fell for it and did the standard rfc-whatever notification)
One thing I wanted to try was to include tracker URLs when stuffing them with fake usernames like 'bob@bob.com https://bobscompany.com/login.php?trackerid=1345556' or make it a 1x1 pixel image link so when they see the fake creds I will know their IP
Wich had a lot of spammers and they worked around the Google Human verification script for logging in.
Humans won't add a Title + Url + text since it shouldn't be used this way.
So ... that flow now returns a xml bomb.
Spam stopped immediately after deploying this. I'm a bit curious how long they spend looking why the memory of their server suddenly went through the roof :p
What you did does nothing against flexible and adaptive adversaries.
We're employed similar tactics against DDoSers at work. Start returning 500s or just tarpit their requests, they think the site is down and they go home.
Regarding its legality, I will paraphrase Bishop Berkeley: if a tree falls in the forest, and no one is around to hear it, does it make a sound?
What I am getting at is until there is a complaint, there is no crime, and as at least another pointed out, criminals will usually not report crimes that reveal their own crimes. "They kidnapped my kidnap-victim!"
>Sadly the server didn't enable indexing otherwise I would have seen all victims, but it was funny nonetheless.
It's actually very lucky for Haschek, because otherwise the only thing stopping Raiffeisen from suing him for stealing credentials would be a bad publicity.
So probably the phishers were annoyed with the fake data and moved servers
Defending our democratic institutions > messing with scammers
Found some random blog which suggests it was circa 2007. http://www.craigmurphy.com/blog/?p=634
I'm asking because my (German) bank only very recently changed to requiring 2FA every X days for login. I'm very curious if they are actually compliant, since I used to be able to log in just with 1 factor to see my current balance (but not conduct any transactions).
IMO implementing the bare minimum this does nothing for security. However, often banks do that, and even if you try to look intentionally suspicious (say, use a VPN in United States with another web browser on another operating system) they don't care and won't ask you for 2FA.
2. It's just a little dev step away: http://blog.cmpxchg8b.com/2020/07/you-dont-need-sms-2fa.html . Phish kits will evolve, UX will still be bad, and phishing will still happen.
And yes the login one might be every 90 days, but to do a transaction there might be an extra one
(yes Germany did away with paper tans (2fa codes) in 2019 yay - thankfully not all banks are that stupid)
Wow that's bad.
Here in Norway we use a system called BankID that uses the SIM in your mobile and it does it every time I log in.
However you can't do this to WebAuthn (or its non-standard predecessor U2F). The WebAuthn challenge is bound to a DNS name, by the client browser. So https://fake-bank.example/important/urgent/thing/ignore/the/... can't get credentials for real-bank.example even if the human is utterly convinced the fake site is their real bank, because you need to fool the web browser not just a human.
AFAIK zero banks use WebAuthn...
I assume that if the banking backend told them the verification sms or whatever is sent, they would have asked the user about it and just forwarded it
If a 2FA challenge is presented, it is relayed to the victim on the phishing website, and as soon as the code is submitted, is it relayed to the real banks website in turn.
In fact, in past when in collage I was trying to learn some hacking basics to find vulnerable servers. And as on the googled article like most scripting kiddies, I searched and found a vulnerable site which was already hacked and had installed shell.php on it. What that vulnerability did was, it found a way to inject the browser navigator name into php script using /proc/self/environ. after studying attack what I did was, remove the shell and patched the vulnerable file with some obfuscation. I was so naive(what would have happened if my IP was tracked and I became suspected criminal),now seeing past luckily I never got my self involved in legal things.
Useless use of cat
`cat /dev/urandom | tr -dc '0-9' | fold -w 7 | head -n 1`
Can be accomplished in two steps instead of 4:
`tr -dc '0-9' < /dev/urandom | head -c 7`
tr: Illegal byte sequence
which I got around by changing the locale:
( export LC_ALL=C; tr -dc '0-9' < /dev/urandom | head -c 7 )
with help from: https://unix.stackexchange.com/questions/141420/tr-complains...
One important thing is to report the phishing attempt, both to the hosting providers involved and to the mail service used to send the emails.
These days I usually try to write an email to the abusar and to the hosting services. I also did a bunch of this "flags" on Instagram ads.
Instagram is the worst, cause they open a website in their app, hiding the true URL of the phishing site. I sent a complain to them about that. Never heard back.
If that's the case then surely you're also flooding the bank's real site with GET requests after the redirection.
Even if, I'm sure the bank appreciates someone working against phishing. A few GET requests is something they're meant to handle. They have to be resistant to DDoS attempts from malevolent actors
Realistically, I don't think I'd do it though -- who knows what 0 days you are putting on your box when you connect to those sites.
If it's at the end of the line it's just signifying that the line continues underneath and to run that block as "one line". It's just escaping the newline character.