Showing posts with label phishing. Show all posts
Showing posts with label phishing. Show all posts

Sunday, April 27, 2008

Zero Day Exploit: Safari Address Bar URL Spoofing

There is a zero day threat to all Safari users both in Windows and Mac, where a remote attacker can hide the actual URL address of the web page in the browser location bar. Let's see how this works ...

Since URL and web page spoofing is very common to phishing, I created this sample email with crafted URL on it.


I clicked the link and here's what I got in Safari 3.1 for Windows.


Here's the screenshot in Mac.


So, what happened here?

A security flaw was found in Safari, when you input a URL containing a special characters followed by "@" which indicates the actual hostname. The special characters was crafted long enough to hide the URL of the page.



As most of Safari users experience the spinning wheel of death, it is evident that there are multiple vulnerabilities that lies within this application.

Is there available security patch/fix ? None, at the moment. So, please refrain from clicking or browsing untrusted websites.

Juan Pablo Lopez Yacubian has recently discovered this vulnerability.

Wednesday, February 20, 2008

MySpace Spammers Are Back

What is Crowdguard.com ? This is the question asked by MySpace user after getting a message from a friend telling her to visit this site.
You need to login your MySpace email address and password to view your pictures. For some people this site seems harmless, but behind this page the objective is to lure people in giving out their Myspace credentials.

Once you give your login credentials, a cgi script will take these informations to a remote server.


And, this message box will pop-up.

To make the story short, the user will not be able to see any pictures - because there's none. This site is phising for your login details so a remote attacker could use it and send spam bulletins or messages to your MySpace friends. It also generates web traffics for all visited sites.

Similar to Crowdguard is Stalkertrack.com. This site promises for free tracking tool that will let you track or "stalk" all profiles that visits your Myspace page.

Once you entered your MySpace login details, this spammer will start using it to spam your friends.

Not only that, your email address and password are sent to multiple IP addresses in clear text form.

**Note: IP address may change.

Do you wonder how many spams were already created in Myspace?

There are 4 million generated post relating to StalkerTrack and this number will keep increasing if more and more vulnerable MySpace users will get deceived by this trick.

Stay away from these sites!