Slashdot Mirror


Phishing Site Using Valid SSL Certificates

UnderAttack writes to tell us the Washington Post SecurityFix blog has an interesting article about a new and rather sophisticated phishing scheme. The email not only used the first few digits of the users card number to look more plausible (even though the first part of the number is the same for all cards), but it also used a valid SSL certificate for its domain name."

78 of 368 comments (clear)

  1. un-possible! by conJunk · · Score: 4, Insightful
    What? An electronic system that didn't function properly? Color me SHOCKED!!!

    /sarcasm

    Seriously. I remember in the early 90s, tv ads for banks that ended with "...and remember, our staff will never ask for your credit card number over the phone." I think people *eventually* got the message on that one. How long will it take online? Remember, unsolicited email that links to a website ready to take your credit card number is bullshit, mom.

    1. Re:un-possible! by mgh02114 · · Score: 5, Interesting

      Seriously. I remember in the early 90s, tv ads for banks that ended with "...and remember, our staff will never ask for your credit card number over the phone." I think people *eventually* got the message on that one.


      They do this all the time. Just last week, Discover called and left a message on my machine "This is the security department, we have a question about the activity on your account, please call 800-###-#### to ensure continued service." When I called that number, they started off saying "Please tell me your card number, your mother's maiden name, etc." all to "confirm my identity" I of course refused, hung up, and called the 800 number printed on my credit card. They were understanding, but never acknowledged that they were essentially asking me to give all my personal information to a random person who called my home phone number.

    2. Re:un-possible! by leenks · · Score: 2
      Remember, unsolicited email that links to a website ready to take your credit card number is bullshit, mom.

      If only this were true :( Take this email I recently received:

      Hi MR FRY Your Virgin Credit Card statement will be winging its way to you any day now, but why wait for postie to pop it through your door? You~Rve already enrolled in our Online Banking Service, so in 2 clicks you can view your account 24/7. Just visit: www.virginmoney.com/service to see your most recent transactions, payment info and last six months statement history. If you~Rre a shopaholic, we hope it~Rs not too scary!

      Naturally, I complained to my card supplier (Virgin UK) and received the following pathetic reply:

      Dear Mr Fry, Thank you for contacting Virgin Money. Although some customers have, in the past, been targets of fraudulent 'phishing' emails, the email you are referring to was sent from our colleagues at MBNA Europe Ltd. As you are probably aware, MBNA Europe Ltd issue and manage the Virgin credit card. In this case, it is safe to click on the link contained within the email - it will in fact redirect you to the Virgin Money website. I would still like to thank you for your vigilance and would ask that if you receive any more suspicious emails, that you forward them on to us at info@virginmoney.com. We always take matters of internet security very seriously and will investigate any suspicious emails as soon as we can. If you need any further help in the meantime, please don't hesitate to email again to info@virginmoney.com, or give us a call on 0800 068 7768. Kind regards

      The best bit is that in early 2004 I had an email telling me this:

      At the start of this week, a number of Virgin Credit Card Customers received an e-mail claiming to be from MBNA (issuers of your Virgin Credit Card) asking them to divulge personal information via hoax internet sites. On discovering this we acted immediately to close down the sites that Customers were being directed to. ... Remember, MBNA and Virgin do not, and never will, send e-mails that ask for confidential information or your security details.

      Sigh...

    3. Re:un-possible! by gutnor · · Score: 5, Interesting

      I got exactly the same here in the uk unless that instead of stopping immediatly I do like any joe user I called back the number, gave my credit card number, birth date but before answering for my mother maiden name, I just realised what I was saying and felt the little tickling in the belly meaning stress ...

      I asked the women on the other hand what was that about - why I need to give this info?
      She told me she need 'security check - blabla'
      I asked why they asked me to call and where I was exactly she just told me the name of the bank (thanks,easy) but she needed the security check to give the reason of the call (best excuse ever)...

      I hang up - ( I start to sweat ) - I went straight to the website to find the number I just called in the bank public phonebook but nada ... the number was not even close to any number used by the bank. I googled the number, nothing ... ( arghhhh )

      I called the bank, this time I have to give the security ID again ( after the previous experience, even if you pick the number yourself in your monthly statement, you really feel uneasy )
      I asked the girl what was this number I just called, and what I'm suppose to do know ... she took less than 2 min ( from my point of view, a very big value of 2 ) to find out that this number is not in the bank private directory either...

      Hopefuly the girl ring herself to the mysterious number and found out that it was only a number setup for the billing departement ( yeah I missed a payment :-) ) ...

      They had a valid reason to contact me, I had an urgent action to take but why in hell do they use the same trick the spammers use?
      They use an unknown number not even known from the bank employees ?
      If I did as we are told in the security leaflet given by the very same bank, I should have called the fraud departement of the bank to report the phishing attempt instead of ringing back!

    4. Re:un-possible! by jacksonj04 · · Score: 4, Interesting

      Why can't banks use a similar system to the "mother's maiden name" to prove who they are? You tell them three pieces of information, and then when they call you can ask for any one of them (They may need to prompt you first).

      --
      How many people can read hex if only you and dead people can read hex?
    5. Re:un-possible! by mikeleigh · · Score: 2, Interesting

      Actually if you use First Direct then this is exactly what they do. Sometimes they will call me and ask me for details and I simply say sorry but I refuse to give these out over the phone when you rang me. The answer I get is ok sir thats fine. Please wait 5 minutes before calling the banks number and a note will be on your file for the operator to direct you back to me. Now thats what I call banking. None of the staff at the bank mind if you tell them that. Also when you ring them they access you for random letters from your password or a memorable place or a combination of things that you should know.

  2. What? by cosmotron · · Score: 5, Insightful

    Did people honestly think that their techniques were going to get worse rather than better?

    --
    Ryan - http://www.thecosmotron.com/
  3. In other news - Stupid People Still Stupid by Anonymous Coward · · Score: 4, Funny

    If you get scammed on the intarweb, your intarweb license should be revoked.

  4. Clues for phishers from Geotrust by 14erCleaner · · Score: 3, Funny
    From TFA: Mp> Geotrust has a rigorous process in place to check for phishy certificate requests that relies on algorithms which check cert requests for certain words, misspellings or phrases that may indicate a phisher is involved. In this case, she said, the technology did not flag the request because there was nothing in the Internet address to indicate the site was at all related to a financial institution.

    If they rely on misspellings, they'll only catch the dumb phishers. They're generally the ones that don't catch a lot of people anyway, or at least not anybody who doesn't deserve to be scammed.

    --
    Have you read my blog lately?
    1. Re:Clues for phishers from Geotrust by AndyBassTbn · · Score: 5, Insightful

      They're generally the ones that don't catch a lot of people anyway, or at least not anybody who doesn't deserve to be scammed.

      You know, I hate hearing that anybody deserves the financial ruin that results from falling for one of these scams.

      Remember, the more that geeks put on the "you're stupid so you deserve what you get" attitude, the fewer folks who are less-computer-savvy will buy computers for fear of being taken for a ride (and knowing no one will help them.)

      This, in turn, results in less money floating around in the tech sector, which, in turn, results in less money being invested to develop convieniences upon which we have come to rely - such as online banking.

      Which, of course, results in less money in the pocket of the geeks that were so callous to begin with. Remember - we NEED the end user just as much as the end user needs us.

      --
      I hope the land around you yields, a crop like all the other fields, and then your waiting might make sense...
    2. Re:Clues for phishers from Geotrust by zacronos · · Score: 3, Interesting

      I think when it says "misspellings", it doesn't mean the "I trenslated this miself" kind of misspelling in the email body, but rather the "this looks almost like a legitimate URL, unless you notice that it's not spelled correctly" kind of mispelling, which is usually spelled correctly in the link text. Like, for instance, www.citibank.com (as a hypothetical example).

      This is why TFA goes on to say "[...] the technology did not flag the request because there was nothing in the Internet address to indicate the site was at all related to a financial institution." -- because they try to catch URLs that are similar to, but not quite the same as, legitimate URLs of financial institutions.

    3. Re:Clues for phishers from Geotrust by The-Bus · · Score: 4, Insightful

      Take Commerce Bank. They have CommerceOnline.com for their main domain and CommerceOnlineBanking.com for their online banking. But why not CommerceBankHome.com as GoDaddy suggest? Or CommerceBanking.com? Or CommerceBankingOnline.com?

      Unfortunately their domain names are a soup of common names and it's impossible to remember. With common names, a small alteration of the site and that's all you need to confuse some folks.

      The best phishing URL I've ever seen was one that was www.amazon.com.exec-obidos.com. If anyone remembers, previously Amazon URLs always had an exec-obidos in their path when the link lead to a product. Even I had to blink a few times before I realized it was a phishing scam. (All the links went to a working Amazon section).

      --

      Small potatoes make the steak look bigger.

    4. Re:Clues for phishers from Geotrust by massysett · · Score: 4, Informative

      Good point on the bank. Even worse about Amazon is the way the URL instantly changes anytime you type in www.amazon.com. It appends a bunch of random-looking letters and numbers to the end. "Average user" then concludes that any URL with "amazon" and a bunch of random letters at the end is a legitimate Amazon page.

  5. Signed SSL certs worthless by Spazmania · · Score: 4, Insightful

    Proving once again the relative lack of worth of requiring SSL certificates to be signed. All it does is make a few companies rich.

    --
    Moderating "-1, Disagree" is simple censorship. Have the guts to post your opinion.
    1. Re:Signed SSL certs worthless by psyclone · · Score: 3, Insightful

      How does paying "extra" for a DNS server do anything with respect to phishing? The days of cache-poisoning DNS servers are going the way of the open SMTP relay. They are almost non-existant.

  6. That's why I don't click html links... by the_humeister · · Score: 4, Insightful

    ...and also why I hate html email and use pine as my mail client. Unfortunately, most people don't know enough to not click html links sent to their email account. As a result, this is especially worrisome because it looks legit.

    1. Re:That's why I don't click html links... by Ctrl+Alt+De1337 · · Score: 5, Insightful

      I hate html email and use pine as my mail client

      I hate to break it to you, but the vast majority of computer users would not be willing to use a terminal-based email system. Most are afraid of using terminals period. I'm glad that you found something that works for you and can score you cool points on Slashdot, but I hope you weren't stating that as a recommendation. Links in email aren't necessarily A Bad Thing so rather than do away with them completely, it's better to fight the phishers instead of the links.

    2. Re:That's why I don't click html links... by Professor_UNIX · · Score: 2, Insightful
      I hate to break it to you, but the vast majority of computer users would not be willing to use a terminal-based email system.

      You know, that's a bunch of bull... users are capable of doing it if they weren't ignorant. 10 years ago when GUI mail readers barely existed, I knew dozens of fellow students that would telnet into a UNIX box and read their mail with pine or elm (and later mutt) without any problem at all. Usually their history would show them alternating between pine and logging into a MUD to game for hours. These weren't all Computer Science students either, they just happened to have grown up with DOS and were quite familiar with actually typing characters into the big glowing screen thing using the keyboard thingy. Windows is to blame for dumbing down our computer users to the point of being completely incompetent when it comes to dealing with a non-clicky-clicky interface.

    3. Re:That's why I don't click html links... by EvanED · · Score: 2, Insightful

      You know, that's a bunch of bull... users are capable of doing it if they weren't ignorant. 10 years ago when GUI mail readers barely existed, I knew dozens of fellow students that would telnet into a UNIX box and read their mail with pine or elm (and later mutt) without any problem at all.

      Okay, what YOU say is a bunch of bull. 10 years ago you would have used Mosaic to browse the web. Maybe Netscape 1. You would have been using a 150 mHz (tops) computer from a dial up modem.

      You were perfectly capable of dealing with all that. I suspect that you were quite satisfied at the time.

      And yet, I bet that you're not sitting in front of a decade old machine now.

      So why should we be stuck with a CLI-based mail client just because people are capable of using it? I use mutt from time to time (mostly to send mail, rarely to recieve), and I wouldn't at all trade Thunderbird or any modern client for it.

    4. Re:That's why I don't click html links... by 93+Escort+Wagon · · Score: 3, Funny

      "...users are capable of doing it if they weren't ignorant. 10 years ago when GUI mail readers barely existed... Windows is to blame for dumbing down our computer users to the point of being completely incompetent when it comes to dealing with a non-clicky-clicky interface."

      Congratulations! You've earned extra Slashdot Coolness Points for 1) slamming Windows; 2) insulting the average user; and 3) being blissfully unaware that most normal people actually prefer a GUI interface!

      --
      #DeleteChrome
    5. Re:That's why I don't click html links... by msbsod · · Score: 2, Insightful

      Exactly, the problem has to be addressed at the source (the phishing e-mail), not somewhere inbetween by some technique that has never been designed to combat phishing (SSL). Unfortunately neither your government nor your bank understand this matter. If people would simply block all HTML message this show would be over in no time. Earlier this evening I posted an example, and promply someone called it "off topic". Well, this is /. and you just cannot educate everybody, I guess.

      http://it.slashdot.org/comments.pl?sid=177291&cid= 14712732

    6. Re:That's why I don't click html links... by techno-vampire · · Score: 2, Interesting
      So why should we be stuck with a CLI-based mail client just because people are capable of using it?

      Er...uh...well...maybe, because we're not, and the OP never said we should be. The OP was only listing his own preferred newsclient, and not insisting that anybody else in the world use it. Just because you think GUI mail clients that parse html, automatically open attachments and run executables are the greatest thing since punched cards doesn't mean everybody else has to use them.

      --
      Good, inexpensive web hosting
    7. Re:That's why I don't click html links... by value_added · · Score: 3, Interesting

      ...users are capable of doing it if they weren't ignorant. 10 years ago when GUI mail readers barely existed... Windows is to blame for dumbing down our computer users to the point of being completely incompetent when it comes to dealing with a non-clicky-clicky interface."

      Congratulations! You've earned extra Slashdot Coolness Points for 1) slamming Windows; 2) insulting the average user; and 3) being blissfully unaware that most normal people actually prefer a GUI interface!

      Perhaps, but more importantly, he offered a reminder that 1) the "Ease of Use" design of Windows and many Windows-based apps does encourage stupidity; 2) GUI apps, despite their added features, can often be inferior to terminal-based programs (in this particular case, even dangerous); and 3) terminal-based programs need not be difficult to use as ordinary people were once perfectly happy typing cryptic-looking commands on a bare screen.

      I'd say each of those is reminders is valuable, and the distinctions made are important.

      This isn't so different than refering to Windows-based viruses as worms as "computer viruses." Put another way, if everyone does indeed want clicky programs and text/html email as another poster suggested, it's perfectly appropriate that they have a clear understanding that any problems they encounter are mostly the result of their preferences. A few comparisons and a little background are always useful.

    8. Re:That's why I don't click html links... by heinousjay · · Score: 2, Funny

      Yeah, I don't know where people get off not doing things your way. I can't imagine why people would prefer to use a GUI. The more natural interaction, superior information organization, and overall higher visual appeal can't have anything to do with it. It must be ignorance.

      (in keeping with a prior story, can anyone guess the intended tone of my post?)

      --
      Slashdot - where whining about luck is the new way to make the world you want.
  7. Revoke SSL cert? by spicyjeff · · Score: 2

    Couldn't the SSL Certificate issuer just revoke the certificate of anyone using said certificate for malicious or illegal purposes? That would at least give some warning to uses with a bad or unknown certificate message.

    1. Re:Revoke SSL cert? by EvilMonkeySlayer · · Score: 3, Interesting

      The problem with that is, in order for the revocation to take effect the user needs to download the root certs update which will be provided by their browser vendor (which in this case will more than likely mean MS) and lets face facts the majority of users never even bother updating, the fickle masses that they are.

      A revoked cert isn't the solution, the solution is fixing the process by which people can get SSL certificates in the first place. There need to be more checks and balances. The current process is essentially; give us your money please, ok here's your certificate.. Enjoy!

    2. Re:Revoke SSL cert? by hackstraw · · Score: 2, Interesting

      The problem with that is, in order for the revocation to take effect the user needs to download the root certs update which will be provided by their browser vendor (which in this case will more than likely mean MS) and lets face facts the majority of users never even bother updating, the fickle masses that they are.

      A revoked cert isn't the solution, the solution is fixing the process by which people can get SSL certificates in the first place. There need to be more checks and balances. The current process is essentially; give us your money please, ok here's your certificate.. Enjoy!


      So true. Revoking certs basically requires realtime lookup of every cert requested to make sure its not revoked. So, can there be a secure and efficient way to validate every cert on connect? Either way, something needs to be checked on connect, I don't know the solutions.

    3. Re:Revoke SSL cert? by afidel · · Score: 4, Informative

      Actually all you have to do is go into Tools, Internet Options, Advanced, and under Security select Check for server certificate revocation which tells IE to check the OCSP of the publisher before accepting a certificate (Tools, options, advanced, security, verification under Firefox). I'm not sure why other than speed that these options aren't enabled by default but you are right that better controlls on certificate issuance would be nice.

      --
      There are 4 boxes to use in the defense of liberty: soap, ballot, jury, ammo. Use in that order. Starting now.
    4. Re:Revoke SSL cert? by squidguy · · Score: 3, Informative

      The problem with that is, in order for the revocation to take effect the user needs to download the root certs update which will be provided by their browser vendor/

      Err...sort of. The user would need a root update if the SSL vendor's root isn't already contained in the user's browser cache. If they didn't have the correct root, then the "valid" SSL cert would appear invalid to the browser because the cert couldn't be traced back down the chain.
      To check for certificate revocation, you have to have your browser set to do so. The latest build of IE6 doesn't have this enabled by default for the target server (although it does have publisher revocation checking enabled by default). Not sure about Firefox. Both Firefox and Windows (though not via IE) provide the ability to upload certificate revocation lists locally.

    5. Re:Revoke SSL cert? by croddy · · Score: 2, Interesting
      Perhaps the solution is for people not to equate a secured network transport layer with the legitimacy of the business on the other end of said transport.

      Sure, you may be speaking with a scumbag using strong encryption, but he's still a scumbag.

    6. Re:Revoke SSL cert? by Anonymous Coward · · Score: 2, Insightful

      A revoked cert isn't the solution, the solution is fixing the process by which people can get SSL certificates in the first place. There need to be more checks and balances. The current process is essentially; give us your money please, ok here's your certificate.. Enjoy!

      For some of the bargain basement certificate authorities this may be true however for the better known companies (Thawte and Verisign for instance) the opposite is sometimes true.

      I work for an ecommerce company and the number of hoops we have to jump through to get some SSL certificate issued is ridiculous. Sometimes in a CA's quest to ensure the legitimacy of an order they go overboard.

      Case in point: we enrolled for an SSL certificate using an organization name of xxx DBA yyy. That order (and several others like it) were accepted without problem. A few orders later the same certificate authority was telling us we can't enroll with a DBA in the organization name.

      I've can give you lots of other examples but suffice it to say more policies are not always the answer.

      A better solution to this problem may be web browsers that support OCSP (online certificate status protocol) - which checks the certificate status in real time.

    7. Re:Revoke SSL cert? by Vellmont · · Score: 3, Interesting


      the solution is fixing the process by which people can get SSL certificates in the first place. There need to be more checks and balances. The current process is essentially; give us your money please, ok here's your certificate.. Enjoy!


      How is any cert provider going to know that a phisher is going to use a cert for a similarly named website? If I go and buy the domain mountain-america.com, setup a website that looks like I'm going to sell vacations to the mountains on that URL, get my signed cert, then turn around the next day and make it look like the mtnamerica.org website, how is the cert issuer going to read my mind and know that?

      No, the answer is that banks need to be issueing some kind of security device that does all the verification. I'm fairly certain all of this is technically possible via everyday encryption.

      --
      AccountKiller
    8. Re:Revoke SSL cert? by Sloppy · · Score: 2, Informative
      Couldn't the SSL Certificate issuer just revoke the certificate of anyone using said certificate for malicious or illegal purposes?
      Sure, but Equifax would have to have up-to-date contact info for the crooks. If they had that, then they could call the crooks, and say, "Hi, we've revoked your cert. Here's the revocation packet. Please -- pretty please! -- have your web server start transmitting it to your potential victims, so that they'll know that our original certification is no longer valid. Thanks."
      --
      As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  8. better link for this storey by UnderAttack · · Score: 5, Informative

    A better link, with more screenshots:

    Phollow the Phlopping Phish

    --
    ---- join dshield.org Distributed Intrusion Detec
  9. Geez... by razzamatazm · · Score: 4, Funny

    Soon all the good ideas will be taken and I'll be stuck selling penis pills again. Ugh...

  10. Also written up at SANS/ISC by Kelson · · Score: 3, Interesting

    The Internet Storm Center did a write-up on this case inclusing a hypothetical tale of Joe Sixpack trying to verify the phish, doing (almost) everything right -- typing in the address instead of clicking on the link, checking for an SSL certificate, checking who the cert is registered to, etc, and still getting caught.

    The fatal flaw in the hypothetical course of action is trusting the non-standard domain name...but you can hardly blame Joe Sixpack for that one when so many financial institutions actually use one-off domains or partner sites. I was working on some phishing rules last year and counted something like 5 domains that Citibank used alone.

  11. It's all a matter of time by Jorkapp · · Score: 3, Insightful

    These phishers are getting more and more sophisticated, but it's only a matter of time before they're caught. To get more sophisticated requires better services and equipment, which requires the phishers to either:
    a) Give out their true information - name, address, etc, making for easier law enforcement tracking
    b) Give out flase information - which may buy them some time, but will only cause the bite taken out of their ass by law enforcement to be that much bigger.

    Even still, Valid SSL certificates and whatnot don't mean shit against a true savvy user who knows better. Any user who actually reads the warnings by their banks/credit card companies/etc will know that said companies will never send emails asking for credit card information.

    --
    Frink: Nice try floyd, but you were designed for scrubbing, and scrubbing is what you shall do.
  12. Assuming too much for signed SSL certs by Vellmont · · Score: 5, Insightful

    Beyond the cert saying the business was in Salt Lake City Utah, I don't really see how there was some big confidence broken here. The SSL cert was issued for "www.mountain-america.net". The bank in question is "www.mtnamerica.org". Whoever thinks that a signed SSL certificate is supposed to verify anything other than the person/entity asking for the cert is the same person who owns the domain is assuming waaaay to much.

    In essense signed certs are only supposed to protect from a man-in-the-middle attack, not someone being fooled into going to a similarly named website. Why shouldn't I be able to get a signed cert for mountain-america.net if I own it? There's plenty of similarly named legit businesses that all have certs issued to them.

    --
    AccountKiller
    1. Re:Assuming too much for signed SSL certs by iabervon · · Score: 4, Insightful

      Browsers are designed to make people assume that CA-signed SSL certificates actually mean something they care about. The only thing this stops is somebody who manages to take control of a site's DNS or TCP traffic but somehow fails to use this control to get a certificate issued. But browsers treat self-signed certificates as really suspicious and CA-signed certificates as perfectly secure. The user isn't given any useful information, and has to make the decision based on information which, as you say, is not actually relevant. (Actually, CA-signed certificates are less trustworthy in many cases than self-signed ones, because the browser doesn't report that a CA-signed certificate is unfamiliar, while a self-signed one is saved, so it's obvious when it's not the same.)

      What would prevent this sort of scam is if people were told that any certificate your browser doesn't already have saved is suspicious, and shown what can be demonstrated about the certificate. If you have a prior relationship with this site, check that this string: (fingerprint of certificate) appears in the information you received. If not, decide whether you believe one of these organizations (signers of certificate, using PKI, based on certificates which come with the system) to make the operation you are doing today safe. In either case, choose a description of the site, which will be displayed when you return to this site in the future. Ideally, the user would be asked to choose whether they recognize the site before they are told more about the certificate, so they don't just look for a reasonable-looking signer.

      That way, people click the link, get the real certificate for something that isn't their bank, and they notice that the window doesn't say "Secure connection to: My Bank" (if they've done this before), or notice that the fingerprint doesn't match the fingerprint on their bank statement, and then they know that, whoever this is, it's nobody they've got an existing business relationship with, and the claim about an existing account is clearly bogus.

      (Last detail: the certificate with the fingerprint in question should be a self-generated CA certificate, not the actual SSL certificate in use, so the bank can change domain name while keeping the same saved info. The CA cert should be signed by the FDIC and other banking-related organizations, who wouldn't be tempted to possibly sign a sporting-goods store certificate, but that's only at all relevant to people trying to choose a bank online, because the instructions will clearly state that this is not the user's current bank.)

  13. SSL Certs by thomble · · Score: 5, Informative
    Most people don't understand the function of SSL certificates, nor do they understand how EASY and INEXPENSIVE it is to get one from a reputable company.

    1. Register the domain JFBVB.COM
    2. On your own DNS servers create a record for EBAY.JFBVB.COM
    3. Purchase a legit SSL certificate from RapidSSL on that domain for $69
    4. Create your phishing site
    5. (Illegally) profit!

    Many people think that an SSL certificate somehow guarantees a trustful vendor. On the contrary, it simply guarantees that no one will view the information en route. The vendor can do whatever he wants with the information you send.

    1. Re:SSL Certs by Kelson · · Score: 2, Informative

      Many people think that an SSL certificate somehow guarantees a trustful vendor.

      This is the result of years of advertising by cert authorities, Verisign in particular.

      Admittedly, Verisign used to make a much greater effort to verify their clients than GeoTrust or Thawte. (This may or may not have changed.) I remember having to provide Verisign with business IDs, wait a month for them to verify things, go back and forth with address corrections, etc.

      These days you can have an SSL cert up and running in less than an hour. If you give GeoTrust a valid phone number and you can answer it, you're pretty much set.

  14. Sophisticated Phishing by Kelson · · Score: 4, Interesting

    No, but a lot of people still have the silly idea that phishing is only as sophisticated as it was 2 years ago, back when it was plaintext, full of misspellings, and sent you to an IP or a GeoCities page.

    Back then, it was hard to imagine people getting fooled by the crude "Send me yore passwerd" level of "attacks" -- and yet people fell victim to it just the same. These days, they're polished enough that you basically have to assume any email that claims to be from your bank is forged, then examine it and try to prove otherwise.

    1. Re:Sophisticated Phishing by kampit · · Score: 5, Informative

      Easiest thing to do is just not to trust any email you receive that deals with important matters such as a bank account, say you do your online banking with YourBank and receive an email that claims to be from them, if you can't immediately tell it's fake.. just go to your browser and manually type in the url for the bank (or use a bookmark), if there's no notification of whatever problem is described in the email, it's definitely fake.

    2. Re:Sophisticated Phishing by glwtta · · Score: 3, Insightful
      These days, they're polished enough that you basically have to assume any email that claims to be from your bank is forged, then examine it and try to prove otherwise.

      Well, yeah, why wouldn't you assume that? In fact, there's no need to examine it to try to prove otherwise, just go to your online banking site (which, it doesn't take a genius to bookmark when you sign up for it), if the bank wanted to tell you something, you'll be notified there too.

      What, are you saying I should also assume that the letters I get telling me I won 10 million dollars are not real either?

      --
      sic transit gloria mundi
  15. Just call up and ask for the (finger|thumb)print! by Goyuix · · Score: 3, Funny

    You have never truly had fun with the support staff at your bank/credit union/credit card/whatever until you have called and asked them to verify the thumbprint/fingerprint of their SSL cert for you.

    Unfortunately, it looks like Geotrust lost this round, and it probably would be considered good practice to actually do that from time to time. For the truly paranoid, remove all root certificates, and only after verifying the thumbprint proceed to install that cert into your cache. No more trust hierarchy.

  16. why is this a suprise? by Triumph+The+Insult+C · · Score: 3, Insightful

    the ssl cert companies don't verify who you are, just who you say you are

    they're in it for the buck. why would they go that extra mile when it just cuts into their bottom line?

    --
    vodka, straight up, thank you!
  17. Digitally signed confession... by ave19 · · Score: 4, Insightful

    You know, if that SSL certificate traces back to a valid human, then you can arrest him/her for phishing and they've provided all your evidence for you.

    It's like leaving your digitally signed confession at the scene of the crime. No CSI team needed. Only the crooks know the corresponding private key.

    If you can't trace that certificate it back to a valid human, than the CA needs to be beaten with a large stick.

    --
    ...or maybe not.
  18. Banks should protect the money, not us by Anonymous Coward · · Score: 4, Interesting

    It amazes me that people forget that a banks job is to protect your money.

    The phisher in the end shouldn't be able to get any money from this.

    The banks should have in place a system that secures your money much better than this. It reminds me of the wild west where banks were robbed all the time.

    Like, why do the retailers have to protect the banks? Why do they have to ask for ID when you already presented a valid banking card to them? Is this system insecure? Yes, and that's why they ask for ID. WTF?

    People should consider this the same as a bank getting robbed over and over. If the banks got enough bad press from this then maybe they would do something about it.

    But never forget, this is not money, it's currency backed by nothing of value and could become wortless in a day. People have been trying to tell you this for years, but you people won't read any simple banker history, it's too booring.

    http://www.apfn.net/Doc-100_bankruptcy13.htm
    http://www.federal-reserve.net/
    http://www.converge.org.nz/pirm/fr_paul.htm
    http://batr.org/verity/id6.html

  19. It's just a numbers game by Alwin+Henseler · · Score: 5, Insightful
    Seriously. I remember in the early 90s, tv ads for banks that ended with "...and remember, our staff will never ask for your credit card number over the phone." I think people *eventually* got the message on that one. How long will it take online? Remember, unsolicited email that links to a website ready to take your credit card number is bullshit, mom.

    You mean people would never give out credit card numbers, when asked over the phone? I think you place too much faith in humanity.

    Most people would agree it's stupid, and fewer people will behave stupid after an education campaign (or after being bitten in the ass). Scam artists may not bother anymore with a certain method. But not because it wouldn't work; but because they've moved onto easier methods, methods that (these days) give them more return for their effort.

    For the same reason, e-mails with attachments like "Anna Kournikova.jpg.pif" will keep getting clicked on. You may think it's silly, but there's a new sucker born every day.
  20. Tracking these people?? by Stephen+Samuel · · Score: 4, Insightful

    My question is: Did these dogs give equifax enough information for the cops to have some hope of tracking them down? I'm guessing that at least some of this information is faked, but if there's nothing here that the cops can use, then the identity information in SSL certificates is less than worthless.

    --
    Free Software: Like love, it grows best when given away.
  21. Re:So, your point is? by rekoil · · Score: 4, Informative

    I say that because this is the first incident ever being reported where an SSL cert was obtained illegitimately.

    Um, no.

  22. Re:Cyber-Squatting lawsuit by forsetti · · Score: 2, Interesting

    What if I have a website for mountain climbers to discuss their American tours? Wouldn't mountain-america.net be a valid name? Shouldn't I be allowed to purchase an SSL certificate to secure logins to my fourms?

    I fear the day that commercial entities own the namespace of the internet, all for name recognition and protecting users from themselves. Trademark law worked great for localized commerce, but with global environments (like the internet), how can one guarantee and protect unique naming without outlawing much of the english language?

    --
    10b||~10b -- aah, what a question!
  23. Gotta hand it to these guys by Douglas+Simmons · · Score: 2, Funny
    I am very impressed that in spite of all the money there is to be made and all the money that gets lost as a result of loose security, and all the time that has passed for people to cash in on this huge demand for iron clad software, that the AOHellers out there keep coming up with ways to steal cards by getting around new deterrents. I mean, great security is something credit card companies and online services have been marketing themselves upon, spending lots of cash-money for these campaigns... they might as well come through with security a la openbsd.

    To add to this craziness, the culprits behind these accomplishments, in this case certificate hacking of all things, are brilliant enough to get ultra-high paying jobs and hire a nude secretary. With this new age of cyber-terrorism threats, I gotta side with the pro-hacker mantras claiming that they help the world by exposing threats with mostly benign things like pbrushing a hitler mustache on Bush before the real bad guys, the ones who have similar high levels of expertise [though in bombs], figure out the holes. High five, 31337-speakers.

  24. Re:Public school system by misleb · · Score: 2, Interesting

    Do browsers check revocation lists? I didn't think so. Without reference to a revocation list, there is no way to tell if a cert has been revoked. It is either signed by a recognized authority or it isn't.

    -matthew

    --
    "THERE IS NO JUSTICE, THERE IS ONLY ME." -Death
  25. Re:Public school system by sqlrob · · Score: 4, Interesting

    Do browsers check revocation lists? I didn't think so

    Yes. At least IE does. It slows things down if you're on an isolated network, so it's one of the first things I turn off on those machines.

  26. How does SSL prevent phishing? by psyclone · · Score: 2, Informative

    SSL doesn't prevent phishing. A signed SSL cert from a trusted Certificate Authority only assures the user that the information passing between the user and the domain is encrypted. SSL can't tell you if a site is "real" or not.

  27. has to be retired-- a rebuttal by way2trivial · · Score: 4, Interesting

    you say, eventually an old trick has to stop being used, I say read the following

    http://www.historybuff.com/library/refbarnum.html

    --
    every day http://en.wikipedia.org/wiki/Special:Random
  28. This bears repeating - by MadMidnightBomber · · Score: 2, Insightful
    "A commercial CA will protect you against anyone from whom they won't take money." -- Matt Blaze

    SSL certs are great for end-to-end encryption. They are not good for authentication, because people don't usually check on the certificate - however, here even a check wouldn't have done any good. I only buy SSL certs because people don't like the extra confirmation dialogue that comes with self-signed ones.

    See also this ISC piece.

    --
    "It doesn't cost enough, and it makes too much sense."
    1. Re:This bears repeating - by Craig+Davison · · Score: 4, Insightful

      If the domain name of the website you're visiting is correct, and you didn't get an SSL error, you know for sure that you're connecting to the right server, and your communication to the server won't be modified or eavesdropped in transit.

      What's going on with this phishing site is that they have a bogus domain name, which unfortunately is good enough to fool people. If you know know that your bank's website is citibank.com, not secure-citibank-website.com or something like that, you will never fall prey to this. You're wrong that a check would not have done any good.

      And a "self-signed" cert is useless because a man-in-the-middle could issue his own "self-signed" cert and just replay traffic between the client and your server.

  29. Nice story and I gotta say it again ... by khasim · · Score: 3, Insightful
    Finally, banks and credit unions that send out email with clickable links teach their customers incredibly dangerous habits. Financial institutions that use multiple domain names are setting their customers up for disaster. And, of course, any financial institution that isn't checking their referrer logs for odd and unknown sites is a time bomb waiting to explode.
    All any bank would have to do to end phishing is to PUBLICLY state that they will NEVER use email to communicate with ANY of their clients.

    They have your phone number.
    They have your address.

    They can send you a letter, they can call your phone. And their phishing rate would drop to almost zero.
  30. Nice try, but I can tell you're trolling by rsilvergun · · Score: 5, Funny

    you spelled 'intarweb' right both times.

    --
    Hi! I make Firefox Plug-ins. Check 'em out @ https://addons.mozilla.org/en-US/firefox/addon/youtube-mp3-podcaster/
  31. All-or-nothing sucks by Sloppy · · Score: 2, Insightful
    The all-or-nothing system used by the whole X.509/SSL system sucks. What should happen after this instance, is that everyone realizes, "Oh, Equifax certifies without actually checking identities," and then they go into their database and delete Equifax.

    But if they do that, then a whole bunch of certs immediately become untrusted, because those certs only have one signature: Equifax.

    OpenPGP is better. In a world ruled by OpenPGP instead of X.509, people would go into their databases and set their "how much I trust Equifax" to a lower setting. Then if someone's identity was only certified by Equifax, they'd start to look iffy, but if someone has been certified by many CAs (in addition to Equifax), they'd still look ok.

    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
    1. Re:All-or-nothing sucks by Grey_14 · · Score: 2, Insightful

      And then you'd promptly get services offering to add a dozen signatures for one low low fee.

  32. Phishers have been using SSL since 2004 by miller60 · · Score: 3, Interesting

    Phishing scams have been using SSL in attacks since 2004. Last year Netcraft identified more than 450 phishing attacks that used SSL certificates in one form or another. However, the tactics seen in the Mountain America attack are more sophisticated than previous attempts. In many previous attacks the phishing crews have used an https URL with an SSL cert they know will trigger a browser alert, banking on the likelihood that many users will trust the padlock and ignore the certificate. This one is designed to fool more sophisticated users who actually check the certificate.

  33. Re:Public school system by Anonymous Coward · · Score: 5, Insightful

    IE used to have a bug where they would check the revocation list for every domain except microsoft.com. Worked well until someone walked into VeriSign's office one day impersonating Microsoft and walked out with several signed certs for microsoft.com. Hee hee. I don't know when MS fixed this, but as I recall they weren't in a big hurry to issue a patch.

  34. Re:So, your point is? by clymere · · Score: 3, Informative

    One can at least mitigate the money issue. http://cacert.org/ is an alternate "open" root cert authority. They're working hard to gain the acceptance of the likes of verisign. I've had converstions with a few of them, and its arguable that their verification procedures are _more_ rigorous than those conducted by the the CA's that are charging high prices.

    Nevermind the fact that if noone is buying certs, theres no finanical pressure to cause them to make any compromises for those willing to pay the right price.

    --
    once you go slack, you never go back
  35. How to stop it by jonwil · · Score: 2, Insightful

    Basicly, the email addresses attatched to these phishing scams are one of 3 things:
    1.An address comming from a domain name owned by target (i.e. bank etc)
    2.An address comming from a domain name that looks like its owned by the target (e.g. www.paypalsupport.com)
    or 3.Something totally unrelated to the bank

    If everyone (both the pishing targets and the email providers) implemented GOOD SPF record checking, it should stop point 1
    Point 2 can be stopped by enforcing the trademark and forcing the domain name to be handed over to the trademark owner (who can then enforce SPF on it)

    It wont stop all phishing scams (i.e. those that come from or something like that) but it will certainly help.

    Unfortunatly, even the biggest phishing targets like amazon, ebay, paypal etc dont implement proper SPF records that say "These machines are the only machines to send email for this domain" (they implement a default "permit all" and not a default "deny all" unfortunatly)

    Also, banks need to actually implement better security, if banks had decent security, phishing would be useless.
    Here is a security model that would be very difficult for a phisher to defeat:
    You open the webpage of your bank and go to the login page. The banks computers then calculate a random number and store it along with the IP address that made the request. The login webpage displays a box for the username, a box for the password and another box for a hash. You enter the random number the bank computer generated into a little calculator like device that contains another random number generated by the bank and stored in the banks computers as well as the device. Then, the device uses a hash algorithim (one designed so that there is no value of that will result in an output value of or that if one exists, it is different for each value of ) to combine the login page number and the stored number.
    The result is entered into the login page along with the username and password.

    The bank then pulls the secret device number from its database and checks that the hash matches. Also, if the IP address of the machine making the requests to the banks webpages doesnt match with the IP stored alongside the session ID, it will assume its fake and terminate.

    Now, when you want to transfer money to someone not on your "approved payee" list or add someone to your "approved payee" list, you get another random hash which you have to enter into the little calculator. To prevent the phisher from simply tricking you into typing this second hash in (i.e. transfering all your money to them instead of transfering the amount you wanted to transfer to who you wanted to transfer it to), you would have to enter the amount being transfered into the calculator device too with it being used as part of the hash.

    Anyone who is dumb enough to press "Funds Transfer" then then doesnt deserve to be using a computer, much less the internet.

    A big education campaign by the banks would help too For example, include a phamphlet with the next bank statement or other junk mail that gives a clear warning about phishing scams and to never ever trust any email pretending to be from the bank no matter what. Also it would tell you to change your password or contact your bank if you think you have been hacked or phished.
    If the phamphlet said in big bold letters something like "Warning: Your money could be at risk from hackers, read this to find out how to prevent it" and was sent out to every bank customer (or every bank customer with online banking enabled on their account), people would probobly read it.

  36. The fatal flaw by Sloppy · · Score: 2, Interesting
    The fatal flaw in the hypothetical course of action is trusting..
    ..Equifax.

    I have nothing against Equifax, but I don't know them either. I don't know their policies, I don't know how they protect their signing key, and I don't know how they verify identities. Neither do you (well, ok, you know a little about their stated policies, because you RTFA). Neither does Joe Sixpack.

    People are farming trust out to faceless strangers that they have never met. It's pretty insane when you think about it.

    Who the hell is Equifax? Who is Verisign? Thawte? They're just names. I don't know anything about them, but somehow when I installed a web browser, it came with a database that says these companies should be trusted introducers. Why the web browser doesn't come with an empty database, I have no idea. Well, I'm lying, of course. I know why. Because people would stop and ask, "Hey should I trust Equifax?" and we don't want most people thinking about that. We just want them to buy stuff.

    --
    As copyright owner of this comment, I authorize everyone to defeat any technological measure which limits access to it.
  37. Removing the broken CA from Firefox 1.5 by Nicopa · · Score: 2, Informative
    1. Open the preferences and go to "Advanced".
    2. Then click on "Security".
    3. Push the certificates button and then choose the "authorities" tab.
    4. Find equifax.
    5. Select all those entries.
    6. Push "edit", uncheck the checkboxes for each certificate.
    Done, you no longer trust these folks.
  38. Re:So, your point is? by Rich0 · · Score: 3, Informative

    The problem is that they're having a hard time even getting mozilla to trust them. There's a bugzilla entry with about 500 CC's listed all of whom are waiting patiently for the root cert to be installed...

  39. Geotrust hasn't revoked the phisher's cert yet by Animats · · Score: 4, Insightful
    Check it out. Still listed. Doesn't even seem to be in the certification revocation database.

    Let's quote what Geotrust says about relying on certificates:

    GeoTrust's solution is that the browser should display ... "The name and logo of the CA who issued the certificate. Consumers will soon learn from news reports which CAs to trust and which CAs use sloppy procedures and should not be trusted."

    We should take Geotrust at their word. Now that we're certain that their procedures are sloppy and they can't be trusted, their certs should be pulled from all browers. New releases of Firefox should not contain root certs for Geotrust. They had their chance, and they blew it.

  40. Firefox does by Weaselmancer · · Score: 4, Informative
    --
    Weaselmancer
    rediculous.
  41. Netcraft Toolbar by OneFix · · Score: 2, Informative

    This is why everyone should install the Netcraft Anti-Phishing Toolbar...unless they really know what they are doing (read IT professional)...

    All of your users/customers should have this installed...besides rating the risk of the site based on previous reports, it would also have shown how long the site was registered...which even on this phishing site was probably a matter of days...as a matter of fact, I can see this as a good feature to include within Firefox...whenever you view the SSL certificate, show the domain registration info...

    Looking at some of the domain registration info, it's obvious that including the DNS Admin, Organization, and Nameserver Organization, you would have easily identified a fake...

    Even better yet, why not have a certification process for banks and such that could opt to have their ISP verify their identity...then when you visit their SSL site, your browser could display the verification info beside the "security lock"...

    Of course, if you want to change the way the "Security Lock" works in browsers, in the US you could set something up with the FDIC that would use a DNS lookup similar to the way DNS Block Lists operate...only this one would tell you if the site was a valid banking site...I guess the "Lock" could change to a "$" or something if it was verified as a banking site...web sites could simply request the check in some way (HTTP header or something)...the header value could represent the type of site (US Banking Site...check with FDIC...)

  42. This scheme won't work by dananderson · · Score: 2, Informative

    SSL certs are not sold for domain names, just host names. They only work for ONE host. You can't buy a SSL cert for *.JFBVB.COM and setup EBAY.JFBVB.COM latter. You can only buy a cert for one host, say WWW.JFBVB.COM.

  43. eBay Phishing Received This Weekend (Screenshots) by nuxx · · Score: 2, Interesting
    This weekend I got a very, very impressive eBay phishing message which appeared to ask if I accepted PayPal. I was so impressed by the continuity of the fake site that I took some screenshots of it:
    - Original Email
    - Fake eBay Login Page
    - Fake Message Composition Page
    - Fake Sent Email Confirmation
  44. There is a Solution by magixman · · Score: 2, Insightful

    We can argue all night about the level of security afforded by an SSL certificate. I think most people don't have a clue about http vs. https and just follow the links where ever they go. If the artwork looks good, the "rap" sounds good and offers something they would want, they just "give it up" without worrying about the little lock icon. If the phisher is good enough, they won't give it a second thought, even after being fished (e.g. "congratulations you have been enrolled in Verfied by Visa").

    The solution to the whole phishing thing should be obvious to us in the technology world. Remember mutual authentication. Yes it still works. Bank of America let's you choose a 'picture' that they promise to always show you before you give up your password. The solution is marginal at present because you only know about it if you use their online services to start with. A serious mutual authentication scheme would involve printing every statement with this picture and drilling into peoples minds that - no picture, no password. It requires a serious PR campaign.

    Right now I have no sympathy for the banks who get ripped off (mtnamerica.org - give me a break). I do have sympathy for the innocent people who fall victim to this and for the shareholders of banks who have to put up with the slow uptake on solutions to this problem.

    OK. I get off soapbox now.

    Cheers.

  45. part of a larger issue by nexeruza · · Score: 2, Insightful

    I think part of the problem is the push to pretend the internet is safe and perfect. Since when has anything in our world been safe for the ignorant? The reality of computers and the internet needs to be common knowledge that you can get into trouble, especially if you don't know what you're doing. If I jumped in a car and put the petal to the floor and wrecked would it be pontiac's fault or the department of transportation that a flawless safety net wasn't put in place? I'm not saying its ignorant computer users fault if they get scammed, but the bullshit promises that you can give out your bank account number over the internet without worry. I don't care how computer savvy you are, we've all had a moment where we were momentarily tricked, imagine somebody that has no idea. I mean remember, those AOL security commercials claim they have single handedly foiled hackers, spam, etc. Computer technology is too wild to pretend the good guys are always in control, lets be honest and admit if you connect to the internet you are taking a risk.

  46. SiteKey: Mother's maiden name, for your bank? by Gary+W.+Longsine · · Score: 2, Interesting
    Why can't banks use a similar system to the "mother's maiden name" to prove who they are? You tell them three pieces of information, and then when they call you can ask for any one of them (They may need to prompt you first).
    Bank of America has a system like this, called SiteKey. If you click on a link and it doesn't go through a verification routine called SiteKey, you know you're not at the real web site of the bank.

    There are several issues with this system, however. The biggest one seems to be that it requires the customer to remember still more crap... ^h^h^h^h ... bits of arbitrary information which are required to perform their daily business with the bank. People are already crushed under the load of the information they must master to interact with banks, online retail vendors, and credit card companies. Now they have to remember some essentially random combination of pictures and words. Let's see, is that sitekey a dog, a mutt, a hound, a puppy, or a poodle? (Hint: the same picture could be any of those things. It's right on the tip of my tongue...)

    Another issue is that several times a year now online shoppers are faced with learning entirely new paradigms and associated rules for how to know if they are being scammed. It's hard to keep up with this stuff when it's your full time job to do so let alone as a casual internet shopper. (That's the same issue you say? One, there is One big issue! I'll just go out and come back in...)

    Another recent example is the Verified by Visa program which has recently been levered to provide a new social engineering angle for a phishing scam. I predicted this a few months ago when I was first exposed to the Verified by Visa system, but I just got around to blogging about it only ten days ago. (see: Verfied by Visa (Veriphied Phishing?) for a description of my unsettling first exposer to this major security initiative from Visa.) I wish I had blogged sooner, I need more points to get my "fortune teller" merit badge!

    More fodder:
    Joris Evers of CNet blog on SiteKey with links to stories and discussions
    Slashdot discussion on SiteKey

    By the way, have you noticed that the time horizon for "recent" is now minutes and hours. I can remember a time when it used to be at least weeks.
    --
    If you mod me down, I shall become more powerful than you could possibly imagine.