How Phishers Think, Act, and Make a Profit
whitehartstag writes with a write up of "the excellent session at Black Hat that detailed 'how phishers create sites, share info and code, and basically are lazy.' They store their stolen data 'on websites that they have hacked into, or on [publically available] sites like guestbooks. And even worse, they are not protecting their stolen data ... which means that all one needs to do to find this info is to reverse engineer a real phisher's website, look at their PHP script, and find out where they are storing the data.'"
I wish the article had good suggestions for how to prevent phishing attacks. Instead, it seems like this article is suggesting I can easily steal already stolen credit-card data.
http://blindscribblings.com - Tasty pop-culture in conceptual fashion.
"...[Phishers] basically are lazy"
I'm lazy, maybe I could be a phisher king...
"...all one needs to do to find this info is to reverse engineer a real phisher's website, look at their PHP script..."
Shit, I instrinsically fail.
...does involve 'securing' data, just not in the way you think it does.
The next logical step would be hackers hacking hacker-hacking hackers.
GAAH! MY PRINTER IS ON FIRE!!! PUT IT OUT! PUT IT OUT!
This article is an old Trope. In fact, Confucius once said: "Give a man a fish, he eats once. Teach a man to phish and he gets a post in /."
Engage brain before clicking.
Sounds like a coincidence to me. I charge way more than that to install any OS on any computer, as the job usually involves backup and migragation of the client's files, tracking down drivers, and other mundane stuff. For $35 it sounds like the guy was just trying to pickup some cash on the side. Even in the technical fields at my university I know there were *many* people who would never attempt something as trivial as installing an OS. Downloading and installing a printer driver is voodoo to those people, even though they themselves installed the printer via the 'quick setup poster' that came with it when it was new. Trying to show these sorts of people how to do this stuff themselves is an exercise in futility. I doubt the phisher in question would have the know-how to even be able to install Vista anyways...I heard they're quite lazy. :)
Buffalo buffalo Buffalo buffalo buffalo buffalo Buffalo buffalo.
...they aren't protecting it? The fact that my personal information is in the hands of people with intentions of using it, is not as bad as them not protecting it? I'd hate to imagine the kinds of people that might get their hands on my personal information!
Modding me -1 troll doesn't make me wrong.
"even who-is'd him for them in the e-mail (it appeared to be an Indian name).... I called the number on the ad... He had a thick Indian accent. Same guy? Coincidence?"
No way that was a coincidence. I mean, how many Indians are there?
With the advent of MPack and other tools from the RBN, it doesn't take a "hacker" anymore to phish. You buy a toolkit, you buy the exploit, you buy a trojan and the scripts for your server, and off you go. The reason why it's successful is simply that there are people who know less than the attacker about security.
Detach yourself from the idea that phishers are in any way required to be security gurus, or that they're in some way intimate with the inner workings of PCs or networks. Those that know how to code don't attack anymore. They sell their attacking toolkits to others who then conduct the attacks.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
Oh yeah? Well I see your smelly Buffalo, and raise you a James while John had had had had had had had had had had had a better effect on the teacher
I wish I knew about this while I was in high school and had to write boring 500 word essays. A few of these and I would be nearly done! :D
Best "String" Ever!
... I saw two white guys in a day. And was like, whoa -- are you folks following me?
Then I saw another one. I knew it. Never trust white guys.
-- A white guy (but just because I'm paranoid doesn't mean I'm not out to get me!)
Help poke pirates in the eyepatch, arr.