Follow us on RSS or Twitter for the latest updates.

July 26, 2012

Download spt v0.6.0 – Simple Phishing Toolkit


spt is a simple concept with powerful possibilities. It is what it’s name implies: a simple phishing toolkit.

Download spt v0.6.0

The basic idea we (the spt project) had was that wouldn’t it be cool if there were a simple, effective, easy to use and free (most importantly!) tool that information security professionals could use to evaluate and train what we all know is the weakest link in any security minded organization: the people.

Since the founders of the spt project are themselves information security professionals by day (and possibly either LOL cats or zombies by night), they themselves faced the frustration of dealing with people within their own organizations that claimed to know better, but 9 times out of 10 fell for the most absurdly obvious phishing emails ever seen. A malware outbreak here, a stolen password and loss of critical organizational data there and the costs of dealing with the results of phishing can get to be astronomical pretty darn quickly!

Enter spt. spt was made from scratch, like a baby (or maybe a zombie) with the goal of giving over-worked and under-staffed information security professionals a simple tool (more like a framework, as we hope to add more features over time) that could be used to identify and train those weakest links. spt is a fully self-contained phishing email toolkit that can be installed, configured and phishing in less than 15 minutes. Its design is modular and open-ended allowing for future expansion and additional features via easy to snap-in modules that are simply uploaded in the administration dashboard. Why not try out spt today and see who your weakest link is?

You can download spt here:

sptoolkit_0.60_zip.zip

Or read more here.

Author: dfgdfg,

Categories: , ,

February 11, 2012

How to Know a Malicious Link Without Clicking It


Even the best security software can’t protect you from the headaches you’ll encounter if you click an unsafe link. Unsafe links appear to be shortcuts to funny videos, shocking news stories, awesome deals, or “Like” buttons, but are really designed to steal your personal information or hijack your computer. Your friends can unknowingly pass on unsafe links in emails, Facebook posts, and instant messages. You’ll also encounter unsafe links in website ads and search results. Use these link-scanning tips to check suspicious links. All of these solutions are free, fast, and don’t require you to download anything.

Hover Over the Link

Sometimes a link masks the website to which it links. If you hover over a link without clicking it, you’ll notice the full URL of the link’s destination in a lower corner of your browser. For example, both of these links connect you to PCWorld’s home page, but you wouldn’t know that without hovering:

Click Here!

http://www.prohackingtricks.blogspot.com/

Use a Link Scanner

Link scanners are websites and plug-ins that allow you to enter the URL of a suspicious link and check it for safety. There are many free and reliable link scanners available; I suggest you try URLVoid first. URLVoid scans a link using multiple services, such as Google, MyWOT, and Norton SafeWeb, and reports the results to you quickly.

URLVoid scans several security databases for information on sketchy Web domain names.

Check Out Shortened Links

URLVoid can’t properly handle shortened URLs from services such as bitly, Ow.ly, and TinyURL (URLVoid will scan the shortening service website instead of the link to which it points). To scan the mysterious shortlinks you’ll often find on Twitter and Facebook, use Sucuri. Sucuri automatically expands the shortlink and draws upon a handful of services, such as Google, Norton SafeWeb, and PhishTank, to determine if the real link is safe. You can also use Sucuri for scanning nonshortened links, but URLVoid checks more sources.

Sucuri can help you determine whether shortened links are safe or not.

Copy a Link--Safely

Services like URLVoid and Sucuri require you to type in or paste a suspicious link—but how do you quickly and safely grab the URL without opening anything? Easy. Just right-click the link to bring up a context menu, then click Copy shortcut (in Internet Explorer), Copy Link Location (in Firefox), or Copy Link Address (in Chrome). The URL is now copied to your clipboard and you can paste it into any search field.

Author: dfgdfg,

October 14, 2011

Norton blocks Facebook as Phishing Site


norton.jpg
Symantec has withdrawn an update to its Norton consumer security software that branded Facebook a phishing site on Wednesday.

The snafu meant that users of Norton Internet Security were blocked from accessing the social networking site and were told a "fraudulent web page" had been blocked, as illustrated in a discussion thread on Symantec's support forums here.

While wags might joke that Facebook is all about persuading punters to supply personal information to a website that ought not to be trusted, it's a bit of a stretch to even compare Zuckerberg's Reservation to a fraudulent banking site. Symantec responded to the problem within hours. From the looks of support forum postings affected users were left dazed and confused rather than seriously inconvenienced or aggrieved by the screw-up.

Security firms update their signature definition files to detect either rogue applications or questionable websites at increasing frequency in order to keep up with malware production rates. Plenty of effort is put into the quality assurance process across the industry but even so mistakes sometimes occur. False positives are a cross-industry problem that affects all vendors.

Author: dfgdfg,

Categories: , , ,

August 5, 2011

Sanford Wallace Indicted for hacking 500,000 Facebookers


Sanford_wallace
One of the first figures to plaster the internet with millions of spam messages before being driven underground has been criminally charged for hacking some 500,000 Facebook accounts, stealing their personal information, and sending 27 million unwanted advertisements.

Sanford Wallace, now 43, first figured out a way to evade Facebook's spam filters and then employed a script that automatically logged in to the accounts he had compromised and retrieve a list of all the users' friends, according to an indictment filed Thursday in federal court in San Jose, California. He then allegedly posted junk messages on each of the friends' Facebook wall.

When people clicked on a link in the message, they were directed to a website that phished their name, and account credentials, prosecutors said. He allegedly carried out the scheme in just five months, starting in November 2008.

“Wallace continued his spamming scheme by storing the information provided by Facebook users, such as email addresses and passwords,” the indictment stated. “Wallace then used the user's email address and password to log into Facebook in order to continue to send spam messages.”

The indictment comes almost two years after Facebook was awarded $711m in damages from Wallace after suing him over the alleged scam. He faced a similar lawsuit from MySpace that in 2008 resulted in a $230m judgement. It's doubtful the company has recovered a dime of either judgement.

Wallace surrendered to FBI agents in Las Vegas on Thursday. He made his initial appearance in court a little while later and was released on $100,000 bail. He was ordered not to access Facebook or MySpace.

The indictment charges Wallace with six counts of fraud and two counts of intentional damage to a protected computer. He was also charged with two counts of criminal contempt for logging in to Facebook after the federal judge in the civil action brought by the site ordered him not to. One of the forbidden logins occurred while Wallace was aboard a Virgin Airlines flight from Las Vegas to New York.

If convicted, he faces a maximum of three years in prison and a $250,000 fine for each fraud count and 10 years and a $250,000 fine for each intentional damage count. Penalties for the contempt charges are up to the judge.

Author: dfgdfg,

Categories: , ,

July 26, 2011

Phishers Targeting Google AdWords account


Cybercrooks have launched a "Google AdWords" phishing campaign in an attempt to trick marks into handing over sensitive login credentials to a bogus, newly registered, website.

Spam messages promoting the ruse falsely claim that a recipient's campaign has been stopped and they need to login to their "Adwords account" in order to reactivate it. The widely distributed spam messages link to a realistic replica of the Google AdWords page, net security firm Sophos warns.

phishers-attack-googleadwords
The dodgy site – google-oa.net – was only registered this week.

Google AdWords accounts normally use the same login credentials as other associated Google accounts (Gmail, Google Docs etc). It could be that the fraudsters behind the scam are just as interested in these accounts as in compromised access to Google AdWords accounts, though this much remains unclear.

The whole scheme further illustrates that phishing fraudsters are going after a wider range of targets outside of old favourites such as PayPal and online banking accounts. Phishing fraudsters in Brazil, for example, have begun targeting air miles accounts, trading stolen vouchers as a form of currency in exchange for renting access to botnets via underground markets.

Intended victims of the air miles or Google AdWords scams might be less aware of the risk and therefore more likely to respond to fraudulent emails, perhaps.

Author: dfgdfg,

Categories: ,

June 2, 2011

Chinese Hackers Targeted U.S. Officials in Gmail Phishing Attack


Google has detected a targeted campaign to collect hundreds of personal Gmail passwords, many of them belonging to senior US government officials, Chinese political activists, military personnel, and journalists.


The accounts may have been compromised using spear phishing techniques in which victims received highly personalized messages that contained links to counterfeit Gmail pages, according to a blog post published in February that Google cited when disclosing the attacks on Wednesday. Google said the campaign “appears to originate from Jinan, China” but didn't share any evidence supporting that claim.

“The goal of this effort seems to have been to monitor the contents of these users' emails, with the perpetrators apparently using stolen passwords to change people's forwarding and delegation settings,” Google's blog post, titled “Ensuring your information is safe online,” stated. “Google detected and has disrupted this campaign to take users' passwords and monitor their emails. Company officials have alerted the victims and “relevant government authorities.”

According to the February blog post, some of the phishing pages were hosted using the free dyndns.org service and contained images and text that were almost indistinguishable from those hosted on the real Google service. The links were “customized and individualized for each target,” independent security researcher Mila Parkour wrote.

Once accounts were compromised attackers created rules to automatically forward all received email to accounts under their control, Parkour said. The attackers then used the purloined email to “gather information about the closets associates and family/friends” and exploited “the harvested information for making future mailings more plausible.”

Parkour's post showed a half-dozen emails exchanged in the campaign, several of which contained Pentagon and US State Department addresses.

“This is the latest version of the State's joint statement,” one fraudulent email read. “My understanding is that State put in placeholder econ language and am happy to have us fill in but in their rush to get a cleared version from the WH, they sent the attached to Mike.”

The email contained what appeared to be a Microsoft Word document as an attachment.

The incident harkens back to a separate attack Google disclosed in January 2010, that targeted the company's source code and the Gmail accounts of human rights activists in China. Unlike the most recent phishing campaign, the “highly sophisticated and targeted attack” from 2010 exploited vulnerabilities on Google's network to gain unauthorized access. Dozens of other companies were also targeted in the earlier attack.

Google's blog post provides a variety of tips for keeping accounts secure. They include use of a two-step verification procedure when logging in to accounts to add an extra layer of security to the login process. Gmail also warns users of suspicious logins to their accounts.

Gmail isn't the only free email service to be targeted recently. Last month, attackers exploited a vulnerability in Microsoft's competing Hotmail that allowed them to steal confidential correspondences and user contacts without warning. The in-the-wild attacks came to light only after they were disclosed by third-party researchers.

Microsoft has yet to say how many users were affected or whether it alerted authorities and compromised users of the attacks.

Author: dfgdfg,

Categories: , ,