Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
December 15, 2009, 02:36:09 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
342688
Posts
37864
Topics
86002
Members
Latest Member:
U4ea708
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
Learn about Computer Security and Interact with Security Experts
Anti Phishing solutions
Phishing sites from miss-spelling?
« previous
next »
Pages:
[
1
]
Author
Topic: Phishing sites from miss-spelling? (Read 16569 times)
Calypze
Comodo Member
Offline
Posts: 26
Phishing sites from miss-spelling?
«
on:
January 30, 2008, 10:00:59 AM »
From what I've heard, the most common form of phishing is by sending fake e-mails asking for personal information.
I wonder if there exist a kind of phishing that is caused by users by mistake entering a very similar address to the real site, but which is fake. Then when the user enters the username and password, the site is made so to sign this in into the real site, getting the user into the real bank account, e-mail box or whatever. Thus, the user would have hard to notice that it was a phishing site. Does this kind of phishing exist? Occasionally I read about this kind of thing, but it never gets detailed. Most phishing information seems to be concerned with spurious e-mails asking for information. But I sometimes worry about false sites. Do I need to? I would be kinda stupid to worry about something that doesn't exist!
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7630
... and I say to myself, "What a wonderful world"
Re: Phishing sites from miss-spelling?
«
Reply #1 on:
January 30, 2008, 07:15:50 PM »
G'day,
You're right in worrying about this kind of thing.
Spoofed sites (ones that resemble real sites) work by making your think you really are at XYZ.COM. When you enter your login credentials into the fake login screen on the fake site, they are recorded on the fake site and simultaneously passed to the legitimate site and you are redirected to the real site. To the end user, it appears that you have logged into the real site, because you have ended up at the real site. What they don't know is that they had a little side trip on the way and the bad guys now have your credentials to the real site. Bye bye bank balance!
A great tool to use to help avoiding these fake sites is Verification Engine (
http://www.verificationengine.com
).
Another variant of these phishing emails is where the content of the phishing email looks like a HTML email but is actually an image (typically a JPG) designed to appear to be a HTML email (sort of like a photo of an email). This image can be linked to a spurious site or can have malware embedded in it itself.
Another simple way you can get trapped is to misspell a web address ("goggle" instead of "google")
DO NOT TEST THIS THEORY BY TYPING WWW.G O G G L E.COM into your browser. GOGGLE is rife with drive by infections - do a search on YouTube for "goggle" and watch what happens as soon as you open the site. I accept no responsibility if you do.
To prevent this, you can manually add entries in your local HOSTS file (in Windows XP, the HOSTS. file is located in c:\windows\system32\drivers\etc\hosts.), misdirecting the addresses. For example, you could add the following,
www . goggle . com 127.0.0.1
This would redirect all attempts to go to www.g o g g l e.com to the local loopback and thereby fail.
Hope this helps,
Ewen :-)
EDIT BY RAGWING: I fixed the link so that no one clicks it by mistake
«
Last Edit: February 04, 2008, 01:09:20 PM by Ragwing
»
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Calypze
Comodo Member
Offline
Posts: 26
Re: Phishing sites from miss-spelling?
«
Reply #2 on:
January 31, 2008, 05:00:27 AM »
Thank you for the reply.
Though judging from the Youtube videos, the g o g g l e . c o m wasn't really a phishing site. I.e it didn't show up as real Google.com does, not similar in apparance or so.
I can understand that such fake sites exist for banks, but do they also exist for e-mails, like Hotmail and GMail If so, then can they recognize where I am like Hotmail and GMail can? For example, if I enter
http://mail.google.com
or
http://www.hotmail.com
I get to the Swedish language varieties of those sites, wheraes if I entered the same addresses in let's say Australia I would get those sites in English? Would a phishing site be able to do that? Would it bother to?
I do have VE, but sometimes after I've signed in I get a feeling that "did I really check if this site was green?", "was this site really green?" etc. I'm a bit paranoid.
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7630
... and I say to myself, "What a wonderful world"
Re: Phishing sites from miss-spelling?
«
Reply #3 on:
January 31, 2008, 06:43:17 AM »
Quote from: Calypze on January 31, 2008, 05:00:27 AM
Thank you for the reply.
Though judging from the Youtube videos, the g o g g l e . c o m wasn't really a phishing site. I.e it didn't show up as real Google.com does, not similar in apparance or so.
Correct, the goggle site wasn't intended to be an example of a phishing site. Rather, it was intended to be an example of how easily we can get stung. Imagine how many miliion times a day the word "google" gets typed, and now think about how few minutes have passed since you last mistyped something. Something as simple as a typo or transposed characters can lead us to the darker side of the web, albeit unintentionally.
Quote
I can understand that such fake sites exist for banks, but do they also exist for e-mails, like Hotmail and GMail If so, then can they recognize where I am like Hotmail and GMail can? For example, if I enter
http://mail.google.com
or
http://www.hotmail.com
I get to the Swedish language varieties of those sites, wheraes if I entered the same addresses in let's say Australia I would get those sites in English? Would a phishing site be able to do that? Would it bother to?
I'm not aware of any attempts to spoof the major webmail providers, but that doesn't mean it hasn't/won't happen. The auto-redirect based on system language/locale would actually work in the favour of non-English speakers, as most spoofed sites tend to be English language ones. I don't doubt that it happens in other languages.
Quote
I do have VE, but sometimes after I've signed in I get a feeling that "did I really check if this site was green?", "was this site really green?" etc. I'm a bit paranoid.
Just because you're paranoid, it doesn't mean they're not out to get you.
Cheers,
Ewen :-)
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1716
Security Saskquatch
Re: Phishing sites from miss-spelling?
«
Reply #4 on:
February 04, 2008, 01:41:45 AM »
Netcraft Toolbar was recently voted the best for anti-phishing.
With running Netcraft, Crawler WebSecurityGuard and Firefox with No Script and CPF3 with Defense + I'm quite protected from this sort of thing. When I use IE7 my arsenal also includes Haute Secure.
Eric
Logged
Moderator:
forum policy
.
System:
32 bit Windows Vista SP3
Realtime Protection:
Comodo Internet Security 3.13
Internet Security
On Demand:
MBAM & SAS
Other:
CSC,CBU,CEVPN,CDragon.
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1716
Security Saskquatch
Re: Phishing sites from miss-spelling?
«
Reply #5 on:
April 06, 2008, 06:28:18 AM »
Gosh I'm a boring no lifer, reading some of my messages back... Still with netcraft toolbar and WOT.
Logged
Moderator:
forum policy
.
System:
32 bit Windows Vista SP3
Realtime Protection:
Comodo Internet Security 3.13
Internet Security
On Demand:
MBAM & SAS
Other:
CSC,CBU,CEVPN,CDragon.
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - News and Announcements
===> Comodo.TV - Program Lineup
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
=====> Video Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Dragon - CD
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in -0 seconds with 18 queries.
Powered by SMF 1.1.11
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com