Honeynet Revealing Actual Phishing Techniques
edsonie writes "CircleID is reporting on the recent Honeynet Project, 'Know your Enemy: Phishing', aimed at discovering practical information on the practice of phishing. The study reports on a number of real world examples of phishing attacks and the typical activities performed by attackers during the full lifecycle of such incidents. The research also suggests that phishing attacks "are becoming more widespread and well organized". Also with regards to the speed of such attacks, "phishing attacks can occur very rapidly, with only limited elapsed time between the initial system intrusion and a phishing web site going online with supporting spam messages to advertise the web site, and that this speed can make such attacks hard to track and prevent." Check out the full report here presenting actual techniques and tools used by phishers."
I've discovered that these Phishers ask questions and stupid people give them answers.
Lets not make it into brain surgery. Do we need honeynets to tell us there are stupid people out there? And there always will be stupid people out there.
End users are the target and there's no way in hell ANYbody will ever change that little term in the equation.
Is it fascism yet?
...is still the education of users. I can't tell you how many e-mails get stuck in our company SPAM filters that mimick phony PayPal accounts. You get that one user who thinks the message is real, and there goes your identity.
IGB: More fun than eating oatmeal!
"Password harvested fishing"??? What a crock! The 'ph' is just a 'cooler' version of an 'f'. Like 'phreaking' or 'phat'.
Someone clearly tried too figure out where the term came from, and completely missed the obvioius
That might have been true once upon a time, but the phishers are getting VERY good at hiding their phish.
I've seen a PayPal phish that was very sophisticated, doing things like putting bogus info into the URL bar, duplicating the layout of PayPal's site EXACTLY... it turned out to be very difficult to spot the smoking gun - I had to go look at the raw HTML to find it.
Had I not been as paranoid as I am, it could have easily suckered me.
Read the article, and follow some of the links to the actual attacks. It's amazing how good they are. (It's equally amazing that a web browser would do anything on link mouseover EXCEPT show the real target of a link!)
Yes, there are plenty of stupid people - some people actually buy products from spam, or send money to Nigeria, etc etc. But the quality of the phishers is getting so good that it is hard to tell (in some cases) what is valid or what is not.
DG
Want to learn about race cars? Read my Book
Consider:
I think computers mystify older people to the point where they lose their mind. I see it in general. My friend's father-in-law had a "computer question" for me about ebay. He wanted me to tell him how to determine the price he should sell something for. I tried to explain to him that his question had nothing to do with ebay itself, but he was so caught up in the process of selling on ebay, he was totally confused.
Maybe phishing works so well because some people are so confused by computers in general, they simply assume that their bank would ask them for this information over email (from an account named bank_stealer@hotmail.com).
Dealing with this kind of leads to the appropriate saying:
You can give a man a fish and feed him for a day, or teach him to fish and feed him for the rest of his life.
You can't get rid of phishing by blocking sites. You have to do it by educating people not to enter their info.
/. ++
Try complaining to the bank or other business being targeted, and identify the ISP in your complaint.
As papers like this one reveal the methods of phishers, it's going to be much more difficult for ISPs to claim ignorance of the problem, because knowledge of tools and methods contribute to standards of due care from which liability arises. The threat of legal action might improve the overall response.
#!
You bank is never going to ask you for your account number over email. They already have it!
Part of the reason this social engineering is successful is that companies, banks, large organizations are so lousy at keeping accurate records. Have you never had a bank screw up your name, or your balance, or some other company you do business with charge you for something you never ordered or fail to charge you for something you have ordered? I've had all these things happen, and it makes it completely unsurprising that a bank would lose your information or even have a policy of verifying your account password via e-mail. It is ridiculous and insecure and generally a really stupid idea, which is why it seems plausible that some lumbering bureaucracy would do it. Obviously, I would never give out sensitive information via e-mail, but I would actually not be surprised if some company requested it via that method. Just because it looks like phishing, does not mean it is, it could just be someone being really dumb. There is plenty of blame to go around here.
Huh?
Maybe you should read TFA, especially if you're comparing them with a bunch of criminals..
What I've read of the Honeynet projects, they set up a network of easy marks and record and examine what traffic they receive. In the case of spammers/phishers, they blast their crap across the net already - it's not like the Honeynet is their only target or its existence is influencing when a phish-run is made.
It's not entrapment. It's research.
hooked up funny
This way, the phishers are doing all the hard work (mass email spam, etc), and getting none of the benefit.
The article even goes on to tell you what tools to use ... so expect this to be the next level of phishing scam.
I'm almost tempted ... must resist the dark side ... do you think we can get the phishers to offer up free pr0n? [tt]
I would venture a guess that among the vulnerable are the parents and/or grandparents of most of the people who read Slashdot. You don't see an ethical obligation on the party of the technically savvy to care about and protect the technically unsavvy? Shame on you.
Software can be anything we make it be. The technologists who have shaped the world have made many choices and will continue to make choices about what our programs will and won't do, how information will be presented, etc. They make those choices on behalf of the public, and they cannot simply shirk responsibility in this way.
Almost all technological problems of this kind reduce to our desire to get as far as possible as fast as possible, and damn any ill side-effects. If browsers required you to know and approve each site before you connected to it, this wouldn't happen. "But that would slow us all down," I can hear you say. The world needs this now, now, now. Indeed, we get benefits by not holding back. But we get ill effects, too, and we can't just poo poo those as not our responsibility. They follow directly from the design decisions we make on behalf of our parents and friends, people who often don't know we're making them nor the consequences of their having been made.
If we spent half as much time, energy, and intellect solving social problems as we do solving technical ones, I suspect the world would be happier.
Kent M Pitman
Philosopher, Technologist, Writer
What prevents someone from simply setting up an online store site, complete with pictures of items and everything, and with rockbottom prices? Run it for a week, collect credit card numbers from orders, then close shop. If you do it right, it can be untraceable.
100% correct. Even for companies I do have an account with, no reason there would ever be a link in an email I need to click. I do have one credit card set up to send me an email when the monthly statement is ready, but when I view that statement, I'll sure use my bookmark, not a link in the email.
Of course most phishing attempts are from companies I have no association with, so that's easy to catch. And 100% of phishing emails I get are filtered by SpamBayes.
> 100%- Simply treat them ALL as phishes.
This is what the banks refer to as "brand damage". My bank would love to sell me a money market account and actually link to their own promotion. Maybe not right to my account page, but what stops a phisher from copying entire site structures?
I realize that you're one of the superior enlightened few that cannot be marketed to, but banks do have products to promote to the rest of the unwashed masses.
I am no longer wasting my time with slashdot