Slashdot Mirror


Phishers Build Deceptive Links with DNS Wildcards

1sockchuck writes "In the continuing evolution of the phisher, the latest scams are crafting deceptive email links that include a bank's URL, but send victims to a phishing spoof site. The phishers are combining wildcard DNS, URL encoding and redirection services to construct the URLs. Netcraft has examples of emails that presented barclays.co.uk in the URL but sent clicks to a spoofed page at a server in Moscow. A DNS cache poisoning attack over the weekend also highlights the potential use of DNS tricks in 'pharming' (phishing using redirection rather than bait emails)."

16 of 245 comments (clear)

  1. Help on the horizon for Windows users! by EmptyBuffalo · · Score: 5, Funny

    Wow! Talk about a great opportunity to educate the masses - now we've just gotta pharm the www.microsoft.com/help website to www.slashdot.com!!! ;)

    --
    cat life | grep joy >> memory
    1. Re:Help on the horizon for Windows users! by LMCBoy · · Score: 5, Funny

      Slashdot.org...it's DOT COM!
      </homestar>

      --
      Liberal (adj.): Free from bigotry; open to progress; tolerant of others.
    2. Re:Help on the horizon for Windows users! by dedazo · · Score: 1, Funny

      No, no. Use http://it.slashdot.org/ so they can appreciate the subtle graphic prowess of the open source community.

      --
      Web2.0: I love when people Flickr my cuil and digg my boingboing until my google is reddit and I start to yahoo
  2. That's it by Anonymous+Crowhead · · Score: 5, Funny

    Time to scrap this whole "DNS" thing. I don't know what it is, but it sounds dangerous.

    1. Re:That's it by ScrewMaster · · Score: 5, Funny

      It stands for "Defensive Nuclear Strike". What that has to do with the Internet and email fraud I don't know.

      --
      The higher the technology, the sharper that two-edged sword.
  3. Who has money any more? by bigtallmofo · · Score: 4, Funny

    After sending all my money to various Nigerian organizations, I wish I had some money for someone to siphon in a phishing scam!

    --
    I'm a big tall mofo.
  4. Re:FYI: by EmptyBuffalo · · Score: 2, Funny

    This I know, but if you try to type _anything_.ORG in Windows you're likely to get a General Protection Fault so they'd have to use the .com derivative (feel the love). The .com was actually intentional, but I didn't explain myself in the post for the sake of comic timing. "www." isn't included in slashdot.org either, but I put it in there too, also for the sake of what I thought most people would consider the joke.

    --
    cat life | grep joy >> memory
  5. In other news.. by pherthyl · · Score: 3, Funny

    The recommended solution to this problem is to bypass DNS and type in all IP addresses by hand.

    I can sell you attractive hand made table of domain to IP mappings for the top 25 sites on the internet for just $5!

    1. Re:In other news.. by earthbound+kid · · Score: 2, Funny
      The recommended solution to this problem is to bypass DNS and type in all IP addresses by hand.

      I can sell you attractive hand made table of domain to IP mappings for the top 25 sites on the internet for just $5!


      Oh shoot, I hope IPv6 doesn't catch on soon, or I'll get carpal tunnel for sure.
  6. Re:dns? links? by Hoch · · Score: 4, Funny

    Did you change your host file to get work done, only to end up memorizing the slashdot ip? Happens to the best of us.

    --
    2*31*37*263
  7. Re:Paypal got it right by jdreed1024 · · Score: 2, Funny

    That should have said www..com. Stupid HTML.

    --
    There is no sig, there is only Zuul.
  8. Re:Phishing? Pharming? by rob_au · · Score: 5, Funny

    phucked (v. tr.): To be taken advantage, betrayed, cheated or victimised by a phishing scam.

  9. Re:Its very simple... by gordon_schumway · · Score: 2, Funny

    I wonder how that affects https connection. Even if they steal the DNS, they shouldn't be able to get their certificate.

    Well, verisign.com could be poisoned, too, you know...

    --

    Ha! I kill me!

  10. Re:Just don't read emails from the bank-Digital Fa by rs79 · · Score: 4, Funny

    "How do you tell bad bits of html from good bits?"

    Check the evil bit in the TCP/IP header.

    --
    Need Mercedes parts ?
  11. Slashdotting "name" change? by AndroidCat · · Score: 2, Funny

    "Looks like our site has been 66.35.250.150'ed!"

    --
    One line blog. I hear that they're called Twitters now.
  12. Re:Just don't read emails from the bank by mph · · Score: 2, Funny
    Advice that doesn't make sense is worse than useless.
    Here's the directions from a can of Campbell's Soup from my cupboard:
    • 1. Lift tab to rim.
    • 2. Pull back slowly.
    • Do not use if tab is lifted.
    D'oh!