Personal tools
You are here: Home Newsletters NetCraft Thursday, Jan 3, 2008

Thursday, Jan 3, 2008

2.0

Phishing kits take advantage of novice fraudsters

A phishing kit targeting the Bank of America contains an interesting insight into the intellectual hierarchy involved in Internet fraud. At first glance, the phishing kit looks attractive to any fraudster – it is straightforward to deploy on any web server that supports PHP, and a single configuration file makes it easy to specify an electronic mail address to receive captured financial details. In addition to requesting the credit card numbers and bank account details, a second form on the phishing site asks for the victim's SiteKey challenge questions and answers, which can help a fraudster gain access to the victim's Internet banking facilities.

bofa-config.png

The email address configured in the phishing kit.

However, while the phishing kit is easy to use, an encrypted component within the kit is used to send a copy of the captured details to an additional gmail address, which belongs to the author. This will not be obvious to most fraudsters using the kit, as the relevant code is detached from the configuration file and is heavily obfuscated, requiring some effort to decode.

bofa-obfuscated.png

The obfuscated code which sends a copy of the financial details to the author.

Such deception is a useful tactic for any fraudster who wishes to maximize the number of successful attacks, as the work of deploying the phishing sites and sending the mails is then carried out free of charge by novice fraudsters on behalf of the author. This relieves the author of the burden of having to carry out the more time consuming aspects of phishing – finding bulletproof web hosting, hacking into host web sites, and sending millions of phishing mails – whilst benefiting by receiving mails from each and every deployment of their own phishing kit.

bofa-screenshot.png

The phishing kit in action.

Posted by Paul Mutton at 10:15 AM UTC on Jan 3, 2008 in Security | Link to this article |

Subscription Details

Copyright © Netcraft Ltd 2007

DATA RECOVERY SERVICE
If you're looking for professional data recovery service, check this site!
Ink Jet Cartridges
Here you can find inkjet cartridges for all major printers.
ink cartridge
Get a great ink cartridge for a great price. We bring you the top brands as well as our own fully guaranteed compatible ink cartridges!
IT support London
Connect is a London based Personal Computing company. We can provide you with unlimited access to an IT helpdesk and on-site support.
DEDICATED Servers
Dedicated servers have to be instantly accessible.
Laptop
Visit CheckCost UK to compare, review and buy latest computers, laptops, scanners, printers, hard drives, LCD monitors and many more.
Software
Visit Ecost Software to find your favourite brands like Adobe, Apple, Microsoft, Autodesk, Codegear, Corel, Symantec and more.
Internet Services
Looking for web design, web hosting or online application development, try Encryptec!