Welcome to the Comodo Forum
Welcome,
Guest
. Please
login
or
register
.
November 12, 2009, 07:32:12 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
334386
Posts
36950
Topics
83802
Members
Latest Member:
derf2005
more news...
Search:
Advanced search
|
Tag Cloud
Welcome to the Comodo Forum
General Category
Melih's Corner - CEO Talk/Discussions/Blog
Phishing: A Lazy man's fraud!
« previous
next »
Pages:
[
1
]
Author
Topic: Phishing: A Lazy man's fraud! (Read 6471 times)
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8215
Phishing: A Lazy man's fraud!
«
on:
June 10, 2006, 05:41:58 PM »
Phishing: A Lazy man's fraud!
Phishing is a type of fraud that is ideally suited to a lazy fraudster! After all, what work do they have to do? They don't have to build a website, just simply copy one of the bank's site, and they don't have to even send the email themselves, just go to your nearest spammer who will be more than happy to do that for you! And writing the email!!?? Worry not Mr Lazy Fraudster, you will also get that from your nearest bank. All you have to do is add your domain voila, now you can collect people's bank account details. And we are sorry, Mr. Fraudster that we can't automate the withdrawals from each account - you have to do that manually! But then again maybe a 14 year old script kiddie could automate that for you too! Just ask your nearest nerd.
The point is Phishing is not even intelligent, nor require such hard work! It hardly is your "Italian Job"! Where is your strategist, disciplined and clever fraudster who is after your money!
Well, they are on their way!
When I invented this tool called Verification Engine to verify web content, people said what for? I said: Wait and see! I called it a tool to eliminate "spoofing a website" – today’s term for "phishing". Was I a “scare monger” then? Time has proving that I wasn't! Am I scare mongering now when I claim that these phishers are just the "first wave of attackers" or the foot soldiers . Unhappily, this first wave will be followed by the "armoured cavalry" as the next wave and they will keep coming! Just wait and see! Today, we mainly have the opportunist fraudster, but we are seeing the organised crime with more resources moving into the Internet feeding ground. Now it’s commercially viable for organised crime to exploit Internet.
We have this castle called Internet and someone has left the castle gates open so all these opportunists fraudster are waltzing in! We have built the internet with no authentication “doors”, no verification whatsoever!
Is that wrong? No of course not. In any technological development you first get it to work, then you get it to work, faster, more secure, more efficient etc. It’s the way the technology gets built! Just look at cars, in 1950s security was not the biggest selling feature - was it! It is now! People were getting killed at 30 Miles an hour crashes, because they did not have seat belts and cars were not built with security in mind! Compare that to today's cars with Side Impact Bars, Air bags everywhere, with Anti Lock Brake systems and so on...
What’s important is to understand when we need security, authentication and assurance! Did we need assurance technologies on the internet on early 90s, maybe we did maybe we did not. But do we need it now because now we have built "Value" into Internet which needs protection. We do our banking there, we purchase things there and we share confidential information with other people on the Internet. And anything of value it must be protected!
Where would we be without Side impact bars, air bags, Anti lock brake systems? Roads would be more dangerous for all of us. Internet must be secured, authenticated and I as a user must have assurances that I can confidently use Internet......... Funny.. As I am writing this article, I just received an email from "Paypal" asking me to login to my account and I don't have a paypal account and the URL is not a Paypal URL, but nevertheless I went to that side and entered my "Username and password" for the lazy fraudster who now has to enter one more password to paypal account only to realize that its the wrong one
. ...................
Anyway, here is the point - let’s understand the underlying problem and fix that! The reason why Phishing and Pharming exist is because we cannot verify what we see! It has little to do with the way we receive emails. Unless we give the users the ability to "verify what they see" we will continue to suffer from this vulnerability called phishing. Instead of trying to fight the enemy once they through the open castle doors, let’s close the doors!
Melih
«
Last Edit: November 25, 2007, 11:28:08 AM by Melih
»
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7438
... and I say to myself, "What a wonderful world"
Re: Phishing: A Lazy man's fraud!
«
Reply #1 on:
June 10, 2006, 06:08:56 PM »
Quote from: Melih on June 10, 2006, 05:41:58 PM
Phishing: A Lazy man's fraud!
As I am writing this article, I just received an email from "Paypal" asking me to login to my account and I don't have a paypal account and the URL is not a Paypal URL, but nevertheless I went to that side and entered my "Username and password" for the lazy fraudster who now has to enter one more password to paypal account only to realize that its the wrong one
. ...................
Are you saying you've stolen my " F U [at]paypal.com" ID??? LOL
e
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8215
Re: Phishing: A Lazy man's fraud!
«
Reply #2 on:
June 11, 2006, 01:13:59 AM »
Quote from: panic on June 10, 2006, 06:08:56 PM
Are you saying you've stolen my " F U [at]paypal.com" ID??? LOL
e
LOL :-) and your bank of America account (even though you are in the Aussie land :-)
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
1nf3s73d
Newbie
Offline
Posts: 11
Re: Phishing: A Lazy man's fraud!
«
Reply #3 on:
July 18, 2006, 12:52:21 PM »
I don't know if this would catagorize as phishing but my favorite (and feared) are the full paged duplicate bank pop ups almost exactly the same as the banks or credit card companies... may be just one letter off and voila a form of phishing and if you don't look close enough at the url you just gave some schmuck your money/account and ID / info.
I mean how many so far were affected
citi bank
amex
red cross
and how many others....
Logged
you're 'bout as ate up as a soup sandwich in the middle of the ocean dur'n a tsunami...
Wiz619
Newbie
Offline
Posts: 3
Re: Phishing: A Lazy man's fraud!
«
Reply #4 on:
July 20, 2006, 08:22:12 PM »
Aloha, Melih
Panic nudged me to read your posts. He likes your humor. Now, So do I .
Allow a brief introduction. I'm an old timer.
Built a Xerox CP/M machine from chips in '81 (could not afford to buy one.)
Started a company called A. Blinkin' in S.F. Got named in the top ten homebrewers in the U.S.
(For quality rather than quantity, only actually sold a few hundred).
Realized my real love was troubleshooting. Went freelance in '91. Prospered, grinned a lot
Then got real lucky and worked as an independent contractor for Intel for 3 years.
Most fun I've ever had.
Went into harness with Intel in '97 as a Server Support Specialist. Least fun I'd had in a long time.
Good product, good people, trapped in corporate hell. Would put Dilbert on the phone to Kevorkian.
I tell you all this, why?
So, you will know that it is not "faint praise" , when I write a testamonial for your Firewall of the first water, and for Comodo as an entity
Companies have a personality and a heart, (sometimes ;-})
The approachability of this company warms my heart. And, that's a very good thing when you consider that my favorite recent quote has been;
" No matter how cynical you get, you just can't keep up!" -Lily Tomlin.
So, for the first time in more than 5 years, I wrote a little testamonial to your Firewall and stuck it in your He'p us forum.
Phew! now to the topic.
The first 3 or 4 paypal phish phorays came to an address that the real
PayPal is unaware of. So, I promptly forwarded to Spoof[at], etc.
When they kept coming, I got irritated, and used NeoTrace to track down the site.
They were using a host in Italy.
Now, I'm no hacker, but getting to their directory on the server was trivial. That's about as far as I went. Suppose I could have just quietly scrambled the captured passwords, given an Italian/English lookup and a little time.
It's not the ethics that detered, more the legality.
"Just 'cause a bugger deserves to be shot, don't mean it's legal to shoot 'em." -Will Rogers
What I did, was capture all the info and send it to the security guys at PayPal.
That was last month. Just checked the bogus site, it's still up. I hope they are at least keeping an eye on it.
Mahalo nui loa for your fine work. If there's anything I can do for you folks, don't be shy.
You have a friend on the Island.
John Scott
Onna rock inna ocean
Logged
Melih
Comodo's Hero
Administrator
Comodo's Hero
Offline
Posts: 8215
Re: Phishing: A Lazy man's fraud!
«
Reply #5 on:
July 20, 2006, 09:38:33 PM »
Quote from: Wiz619 on July 20, 2006, 08:22:12 PM
Aloha, Melih
Panic nudged me to read your posts. He likes your humor. Now, So do I .
Allow a brief introduction. I'm an old timer.
Built a Xerox CP/M machine from chips in '81 (could not afford to buy one.)
Started a company called A. Blinkin' in S.F. Got named in the top ten homebrewers in the U.S.
(For quality rather than quantity, only actually sold a few hundred).
Realized my real love was troubleshooting. Went freelance in '91. Prospered, grinned a lot
Then got real lucky and worked as an independent contractor for Intel for 3 years.
Most fun I've ever had.
Went into harness with Intel in '97 as a Server Support Specialist. Least fun I'd had in a long time.
Good product, good people, trapped in corporate hell. Would put Dilbert on the phone to Kevorkian.
I tell you all this, why?
So, you will know that it is not "faint praise" , when I write a testamonial for your Firewall of the first water, and for Comodo as an entity
Companies have a personality and a heart, (sometimes ;-})
The approachability of this company warms my heart. And, that's a very good thing when you consider that my favorite recent quote has been;
" No matter how cynical you get, you just can't keep up!" -Lily Tomlin.
So, for the first time in more than 5 years, I wrote a little testamonial to your Firewall and stuck it in your He'p us forum.
Phew! now to the topic.
The first 3 or 4 paypal phish phorays came to an address that the real
PayPal is unaware of. So, I promptly forwarded to Spoof[at], etc.
When they kept coming, I got irritated, and used NeoTrace to track down the site.
They were using a host in Italy.
Now, I'm no hacker, but getting to their directory on the server was trivial. That's about as far as I went. Suppose I could have just quietly scrambled the captured passwords, given an Italian/English lookup and a little time.
It's not the ethics that detered, more the legality.
"Just 'cause a bugger deserves to be shot, don't mean it's legal to shoot 'em." -Will Rogers
What I did, was capture all the info and send it to the security guys at PayPal.
That was last month. Just checked the bogus site, it's still up. I hope they are at least keeping an eye on it.
Mahalo nui loa for your fine work. If there's anything I can do for you folks, don't be shy.
You have a friend on the Island.
John Scott
Onna rock inna ocean
Interesting info John.
Paypal might not have a "take down" service to take these people down. Thats why we have VE
www.vengine.com
which allows the users to see what is real what is not.
thanks for your support!
spread the word! tell everyone! write to magazines, inform the univerisities/schools, about what Comodo is trying to do.
thank you
Melih
Logged
Who is Melih? What is he trying to do?
--
Follow me on Twitter
Alwin
Newbie
Offline
Posts: 3
Re: Phishing: A Lazy man's fraud!
«
Reply #6 on:
June 22, 2009, 01:28:19 AM »
Hi,
I am new to this forum. I have heared about
www.LivePCSupport.com
and I have also gone through that website...
When I googled for a techsupport website I have found a similiar website like LivePCSupport. Here is the one
www.vsupportu.com
.. Is that a phishing website of LPS or it belongs to you...?
Quote from: Melih on June 10, 2006, 05:41:58 PM
Phishing: A Lazy man's fraud!
Phishing is a type of fraud that is ideally suited to a lazy fraudster! After all, what work do they have to do? They don't have to build a website, just simply copy one of the bank's site, and they don't have to even send the email themselves, just go to your nearest spammer who will be more than happy to do that for you! And writing the email!!?? Worry not Mr Lazy Fraudster, you will also get that from your nearest bank. All you have to do is add your domain voila, now you can collect people's bank account details. And we are sorry, Mr. Fraudster that we can't automate the withdrawals from each account - you have to do that manually! But then again maybe a 14 year old script kiddie could automate that for you too! Just ask your nearest nerd.
The point is Phishing is not even intelligent, nor require such hard work! It hardly is your "Italian Job"! Where is your strategist, disciplined and clever fraudster who is after your money!
Well, they are on their way!
When I invented this tool called Verification Engine to verify web content, people said what for? I said: Wait and see! I called it a tool to eliminate "spoofing a website" – today’s term for "phishing". Was I a “scare monger” then? Time has proving that I wasn't! Am I scare mongering now when I claim that these phishers are just the "first wave of attackers" or the foot soldiers . Unhappily, this first wave will be followed by the "armoured cavalry" as the next wave and they will keep coming! Just wait and see! Today, we mainly have the opportunist fraudster, but we are seeing the organised crime with more resources moving into the Internet feeding ground. Now it’s commercially viable for organised crime to exploit Internet.
We have this castle called Internet and someone has left the castle gates open so all these opportunists fraudster are waltzing in! We have built the internet with no authentication “doors”, no verification whatsoever!
Is that wrong? No of course not. In any technological development you first get it to work, then you get it to work, faster, more secure, more efficient etc. It’s the way the technology gets built! Just look at cars, in 1950s security was not the biggest selling feature - was it! It is now! People were getting killed at 30 Miles an hour crashes, because they did not have seat belts and cars were not built with security in mind! Compare that to today's cars with Side Impact Bars, Air bags everywhere, with Anti Lock Brake systems and so on...
What’s important is to understand when we need security, authentication and assurance! Did we need assurance technologies on the internet on early 90s, maybe we did maybe we did not. But do we need it now because now we have built "Value" into Internet which needs protection. We do our banking there, we purchase things there and we share confidential information with other people on the Internet. And anything of value it must be protected!
Where would we be without Side impact bars, air bags, Anti lock brake systems? Roads would be more dangerous for all of us. Internet must be secured, authenticated and I as a user must have assurances that I can confidently use Internet......... Funny.. As I am writing this article, I just received an email from "Paypal" asking me to login to my account and I don't have a paypal account and the URL is not a Paypal URL, but nevertheless I went to that side and entered my "Username and password" for the lazy fraudster who now has to enter one more password to paypal account only to realize that its the wrong one
. ...................
Anyway, here is the point - let’s understand the underlying problem and fix that! The reason why Phishing and Pharming exist is because we cannot verify what we see! It has little to do with the way we receive emails. Unless we give the users the ability to "verify what they see" we will continue to suffer from this vulnerability called phishing. Instead of trying to fight the enemy once they through the open castle doors, let’s close the doors!
Melih
Logged
eXPerience
Malware Researcher Virus Removal Helper Advanced Tweak Freak Crazy Little Devil
Global Moderator
Comodo's Hero
Offline
Posts: 6407
Why not ? The choice is yours !
Re: Phishing: A Lazy man's fraud!
«
Reply #7 on:
June 22, 2009, 02:46:28 AM »
Hi,
I'm not sure, they copied most of the text from Comodo, but as far as I know, it's not Comodo's. So I guess you're safer logging in here :
http://www.livepcsupport.com/
I'll pm Melih in the meantime
Xan
Logged
panic
Global Moderator
Comodo's Hero
Offline
Posts: 7438
... and I say to myself, "What a wonderful world"
Re: Phishing: A Lazy man's fraud!
«
Reply #8 on:
June 22, 2009, 04:05:17 AM »
Doesn't look good
Have a look at the whois record for the IP of vsupportu.com
http://whois.domaintools.com/65.55.194.74
Smell phishy or what?
Logged
As your mums would say, "If you can't play nice with all the other kiddies, go home".
All users are asked to please read and abide by the
Comodo Forum Policy
.
If you don't like it, don't use the forum.
Eric Cryptid
Global Moderator
Comodo's Hero
Offline
Posts: 1683
Security Saskquatch
Re: Phishing: A Lazy man's fraud!
«
Reply #9 on:
June 22, 2009, 06:44:37 AM »
Not W.O.T. (Web Of Trust) rating.
Incidentally, you can check ratings for any website by going to
www.mywot.com
Definately fishy though.
Logged
Moderator:
forum policy
.
System:
32 bit Windows Vista SP3
Realtime Protection:
Comodo Internet Security 3.10
Internet Security
On Demand:
MBAM & SAS
Other:
CSE,CSC,CTC,CEVPN,CVE.
Alwin
Newbie
Offline
Posts: 3
Re: Phishing: A Lazy man's fraud!
«
Reply #10 on:
June 22, 2009, 06:50:14 AM »
Hi all,
Thanks for replying to my post. If that website a phishing website then is there any way to block that website?
Logged
LaserWraith
Usability Study Member
Comodo's Hero
Offline
Posts: 3080
I report myself to the mods.
Re: Phishing: A Lazy man's fraud!
«
Reply #11 on:
June 22, 2009, 07:48:51 AM »
I just had to post a comment on WOT.
Logged
Visit my site!
Some of my articles - click for blog page.
Alwin
Newbie
Offline
Posts: 3
Re: Phishing: A Lazy man's fraud!
«
Reply #12 on:
June 22, 2009, 12:25:41 PM »
Hi,
Thank you. Any updates on this phishing website
www.vsupportu.com
?
Quote from: eXPerience on June 22, 2009, 02:46:28 AM
Hi,
I'm not sure, they copied most of the text from Comodo, but as far as I know, it's not Comodo's. So I guess you're safer logging in here :
http://www.livepcsupport.com/
I'll pm Melih in the meantime
Xan
Logged
Ovidiu Bucsa
Newbie
Offline
Posts: 11
Re: Phishing: A Lazy man's fraud!
«
Reply #13 on:
June 23, 2009, 04:31:57 AM »
Hello,
The services on the site that Alwin mentioned are not provided by Comodo's Live PC Support Team or by any Comodo employees.
Logged
Tags:
Pages:
[
1
]
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Want to help Comodo?
-----------------------------
=> Help Spread the Word - Official Comodo banners and logos
=> How can you help Comodo? (Please we do need you!)
===> Help spread the word! (Please read and help)
===> Comodo website issues for submitting website problems only
=> Please tell us your views and Vote here!
-----------------------------
General Category
-----------------------------
=> Melih's Corner - CEO Talk/Discussions/Blog
=> Comodo.TV - Our Internet Video Channel
===> Comodo.TV - Program Lineup
===> Comodo.TV - News and Announcements
===> Audience Feedback and Suggestions
=> Which Product do you want Comodo to develop next?
=> General Discussion (off topic) Anything and everything...
===> Member Confessions :-)
===> Funny Photos :-)
===> Cool Stuff
-----------------------------
Desktop Security Products
-----------------------------
=> Comodo Internet Security - CIS
===> Overview - CIS
===> Help - CIS
=====> Anti Virus Help
=====> Firewall Help
=====> Defense+ Help
=====> Install / Setup / Configuration Help
===> FAQ - CIS
=====> Anti Virus FAQ
=====> Firewall FAQ
=====> Defense+ FAQ
=====> Install / Setup / Configuration FAQ
===> Feedback/Comments/Announcements/News - CIS
===> Guides - CIS
=====> Anti Virus Guides
=====> Firewall Guides
=====> Defense+ Guides
=====> Install / Setup / Configuration Guides
===> Wishlist - CIS
=====> Anti Virus Wishlist
=====> Firewall Wishlist
=====> Defense+ Wishlist
=====> GUI -Graphical User Interface - Wishlist
===> Bug Report - CIS
=====> Anti Virus Bugs
=====> Firewall Bugs
=====> Defense+ Bugs
=====> Other - General - GUI etc Bugs
=====> False Positive/Negative reporting - (Is this a malware that CIS has/not detected?)
===> Virus/Malware Removal Assistance
===> Leak Testing/Attacks/Vulnerability Research
=> Comodo Time Machine - CTM
===> Frequent Asked Questions (FAQ)
=> Comodo Instant Malware Analysis Online - CIMA
=> Comodo Disk Encryption - CDE
===> Overview - CDE
===> Help - CDE
===> FAQ - CDE
===> Feedback/Comments/Announcements/News - CDE
===> Wishlist - CDE
===> Beta Corner - CDE
===> BUG Reports - CDE
=> Comodo Secure Email - CSE
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about CSE
===> Bug Reports
===> Help for Comodo SecureEmail
=> Comodo TrustConnect - Securing the Wireless world!
=> Comodo EasyVPN - CEVPN
===> Frequently Asked Questions (FAQ)
===> Feedback/Comments/Announcements/News about Comodo EasyVPN
===> Bug reports
===> Help for Comodo EasyVPN
=> HopSurf (Bringing Internet to you)
=> Comodo Online Backup - COB
=> Comodo Backup - CB
===> Comodo Backup - FAQ
===> Comodo Backup - Help
=> Verification Engine - CVE
=> Comodo Vulnerability Analyzer - CVA
=> Comodo AntiSpam - CAS
-----------------------------
Desktop Utilities
-----------------------------
=> Comodo System Cleaner - File/Registry/Privacy Cleaner
=> Live PC Support (geeks ready to help 24/7/365)
-----------------------------
Enterprise Security
-----------------------------
=> Comodo Endpoint Security Manager
-----------------------------
Compliance
-----------------------------
=> PCI DSS Compliance
-----------------------------
Learn about Computer Security and Interact with Security Experts
-----------------------------
=> Computer Firewalls
=> Anti Virus/Malware Products/Other Security products
=> Free Virus/Spyware/Trojan/Malware Removal by Comodo Experts
=> HIPS (Host Intrusion Prevention Systems)
=> Anti Phishing solutions
=> Digital Certificates, Encryption and Digital Signing
=> General Security Questions and Comments (not product related)
-----------------------------
Free Services for End Users
-----------------------------
=> UserTrust - First Independent Website Rating - Empowering our users!
=> Hacker Guardian
=> Trustfax (free Trial) (online faxing)
-----------------------------
Free Products
-----------------------------
=> Link to Free Comodo Products
-----------------------------
International Comodo Forums
-----------------------------
=> International Comodo Forums
===> 汉语语言, 漢語語言 / Chinese Simplified, Traditional
===> Nederlands / Dutch
===> Francais / French
===> Deutsch / German
===> ελληνικά / Greek
===> Magyar / Hungarian
===> Italiano / Italian
===> Nihongo / Japanese
===> Norsk / Norwegian
===> Polski / Polish
===> Português/Portuguese
===> По-русски / Russian
===> Espanol / Spanish
===> Svenska / Swedish
===> Turkce / Turkish
===> Українська / Ukrainian
===> tiếng Việt / Vietnamese
===> Slovenský / Slovak
-----------------------------
Digital Certificates
-----------------------------
=> Code Signing Certificate
=> Content Verification Certificate
=> Email Certificate
=> SSL Certificate
-----------------------------
Web Server Products
-----------------------------
=> Two Factor Authentication for Web Applications
=> Trustlogo
-----------------------------
Other
-----------------------------
=> Forum Policy Violation Board
-----------------------------
Archive Boards
-----------------------------
=> Comodo Diskshield
=> Comodo Firewall
===> Feedback/Comments/Announcements/News
===> Help for v3
===> Help for v2
===> Frequently Asked Questions (FAQ) for Comodo firewall
===> Comodo Firewall Translations
===> Bug Reports
=> Comodo Anti-Viruspyware (CAVS)
===> Help for Comodo AntiVirus
===> FAQ for Comodo Anti-ViruSpyware
===> Feedback/Comments/Announcements/News about CAVS
=> Launch Pad (Discontinued)
=> Trusttoolbar (Discontinued)
=> Comodo Meet (Web Conferencing Product) (Discontinued)
=> User Anywhere (Remote Access product) (Discontinued)
=> Trustix Enterprise Firewall
=> ZTL
=> Comodo BOClean Anti-Malware
===> Announcements
===> Comodo BOClean Anti-Malware FAQ
=> Comodo Memory Firewall(Buffer Overflow Protection)
===> Comodo Memory Firewall Beta Corner
===> Help
===> Frequently Asked Questions (Comodo Memory Firewall)
===> Feedback/Comments/Announcements/News
=> i-Vault
=> Safesurf
Page created in 0.061 seconds with 19 queries.
Powered by SMF 1.1.10
|
SMF © 2006, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks
Design by
7dana.com