Showing posts with label Phishing. Show all posts
Showing posts with label Phishing. Show all posts

Monday, March 2, 2015

IDN Homograph Attack (Undetectable Phishing URL)


Phishing pages are detected by many websites and antiviruses. So the phishing attacks are almost over. Here i got some great information about "Undetectable Phishing pages". I will not show you the actual phishing attack by IDN Homograph Attack. I will show you an example for this and it is same as you can use in your Phishing URL.


How attackers can trick users into clicking on links which appear to be genuine but lead to malware or phishing sites etc. I mentioned that one method used would be to replace characters of the genuine URL with characters from other language sets (Russian languages for example) which look the same as the English characters in the browser. In short the attacker can perform a homograph attack.


Internationalized Domain Name(IDN) homograph attack. This kind of spoofing attack is also known as script spoofing. For example, a person frequenting citybank.com may be lured to click a link in which the Latin "C" is replaced with the Russian "С".


Some time you make phishing page, But problem is the link of that phishing page, Due to that link it is possible to detect phishing page by target. Here i will show you how to change the alphabet that looks like english but it is not.


Here i will search my name "urvish sandanshiv" in the normal Google search engine and see what result i got.


The search result i got is 138

And now see the magic what happens with the result same name i search in the Google.

There is no result for my name. So what Google is unable to seach me. Search engines are stronger than me and intelligent too but i fooled them. What i did i just replaced the  English character "a"  to Russian "a" from my name it looks like same but it is different. And see the result what it happened. The same thing you can do in Phishing URLS. Replace the English characters with Russian  character while making Phishing URLS.

Original   ;- urvish sandanshiv
Duplicate :- urvish sаndаnshiv

You can not identify this thing so as the search engines.

Now the trick i will show you how to do this. And this can be use in making Phishing URL also. Just open this link Russian character set. You will see some of the letters that are same in English and in Russian but the meaning and pronunciation are different than English. You can make Undetectable phising URL with the help of this.


REFERENCE

en.wikipedia.org

www.securityninja.co.uk/




 Terms & Warning:

Use this script for educational purposes only and for your self knowledge.
Pro Hack Tricks Blog Team, its Author, Admin cannot be held responsible for any legal action or other action taken against you if you use this script illegally. Use at your own risk. But remember no one is untraceable.


Sunday, November 23, 2014

Phishing - Smishing & Vishing

Phishing is the attempt to acquire sensitive information such as usernames, passwords, and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, banks, online payment processors or IT administrators are commonly used to lure unsuspecting public. Phishing emails may contain links to websites that are infected with malware.

Phishing emails may contain links to websites that are infected with malware. Phishing is typically carried out by email spoofing or instant messaging, and it often directs users to enter details at a fake website whose look and feel are almost identical to the legitimate one. Phishing is an example of social engineering techniques used to deceive users, and exploits the poor usability of current web security technologies.

SMS Phishing or SMShing is a form of criminal activity using social engineering techniques. SMS phishing uses cell phone text messages to deliver the bait to induce people to divulge their personal information. The hook (the method used to actually capture people's information) in the text message may be a website URL, but it has become more common to see a telephone number that connects to an automated voice response system. 

The SMS phishing message usually contains something that demands the target's immediate attention.

Example:"We confirm that you have signed up for our dating service. You will be charged $2 a day unless you cancel your order on this URL: [URL]". Or (Name of popular online bank) confirms that you have purchased a computer from (name of popular computer company). Visit [URL] if you did not make this online purchase", and "(Name of a financial institution): Your account has been suspended. Call 0xxxxxxxxxx immediately to reactivate". The hook will be a seemingly legitimate website that asks you to "confirm" (enter) your personal financial information, such as your credit/debit card number, CVV code (on the back of your credit card), your ATM card PIN, SSN, email address, and other personal information.

If the hook is a phone number, it normally directs to a legitimate-sounding automated voice response system, similar to the voice response systems used by many financial institutions, which will ask for the same personal information.
This is an example of a (complete) SMS phishing message in current circulation: "Notice - this is an automated message from (a local credit union), your ATM card has been suspended. To reactivate call urgent [sic] at 866-###-####."

In many cases, the SMS phishing message will show that it came from "5000" instead of displaying an actual telephone number. This usually indicates the SMS message was sent by email to the cell phone rather than from another cell phone.
This information is then used to create duplicate credit/debit/ATM cards. There are documented cases where information entered on a fraudulent website (used in a phishing, SMS phishing, or voice phishing attack) was used to create a credit or debit card that was then used halfway around the world within 30 minutes.

Voice Phishing is the criminal practice of using social engineering over the telephone system to gain access to private personal and financial information from the public for the purpose of financial reward.
Voice Phishing is known as Vishing. The combination of both words Voice and phishing.
The Vishing is done for getting personal and financial details of the victim. Some of the fraudsters use Voice Over IP (VOIP) by this they can spoof their caller ID.

Voice phishing or Vishing is difficult for legal authorities to monitor or trace. To protect themselves, consumers are advised to be highly suspicious when receiving messages directing them to call and provide credit card or bank numbers — vishers can in some circumstances intercept calls that consumers make when trying to confirm such messages.
 
Example: In this case there are two character Attacker ‘A’& Victim ’B’. Now Attacker ‘A’ somehow contacted Victim ‘B’ with his number that is spoofed and telling u some banks name (My name is XYZ calling from bank) now he will tell you that your card has been blocked or some new schemes are available for you so you please provide your debit card number and if you give 14 digit number he will ask you for CVV number that is of 3 digit. So by mistake you will give your number to him and then he will ask you for your OTP if the facilities is activated, if not then your bank password used for online transection or for online shopping. So directly he will purchase something from website or he will transfer your money.

Another simple trick used by the fraudsters is to ask the called party to hang up and dial their bank - when the caller hangs up, the fraudster does not, keeping the line open and remaining connected when the victim picks up the phone to dial. When in doubt, calling a company's telephone number listed on billing statements or other official sources is recommended as opposed to calling numbers received from messages or callers of dubious authenticity.

However, sometimes hanging up and redialing is insufficient: if the caller has not hung up, the victim might still be connected and the fraudster spoofs a dial tone down the phone line when the victim dials and a fraudster accomplice answers and impersonates whoever the victim is trying to call. Hence consumers are advised to use a different phone when dialing a company's number to confirm.
 
What to do for not getting into scam?
1. First of all avoid giving your information on telephone. (Because the banks will never ask such details (your 14 digit debit card number and your 3 digit CVV number)
2. If you get such calls from the bank avoid that call or ignore it and don’t give your personal information to anyone.
 
If this happen, what to do?
1. Immediately contact to your banks toll free number and deactivate your Debit card or credit card so he will not be able to use your card again.
2. File a complaint against that calling number.

In-Session Phishing is a form of phishing attack which relies on one web browsing session being able to detect the presence of another session (such as a visit to an online banking website) on the same web browser, and to then launch a pop-up window that pretends to have been opened from the targeted session. This pop-up window, which the user now believes to be part of the targeted session, is then used to steal user data in the same way as with other phishing attacks.


The advantage of in-session phishing to the attacker is that it does not need the targeted website to be compromised in any way, relying instead on a combination of data leakage within the web browser, the capacity of web browsers to run active content, the ability of modern web browsers to support more than one session at a time, and social engineering of the user.