CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer
image Beware!: PayPal Phishing Site Exploits Google XSS Vulnerability image
Phishing
There is a new PayPal phishing site that is crafty and cunning in attempting to hide its true address from the surfer. Unsuspecting users might fall for this devious trickery. Unfortunately, Google is vulnerable to a XSS attack to which they are aware and are working to resolve. Actually this isn't a "traditional" javascript or similar XSS vulnerability, it is a a redirect that is prone to being abused. It is this venue that the phishing site uses to begin its lure and deception of the surfer.

A 1024x768 flash film of the whole visitation is available in the extended entry of this blog item. It shows the whole email delivery, thru the Google exploit, and the execution of the scam sites cunning.

Securiteam displays the jist of a similar exploit involving UTF-7:


Two XSS vulnerabilities were identified in the Google.com website, which allow an attacker to impersonate legitimate members of Google's services or to mount a phishing attack. Although Google uses common XSS countermeasures, a successful attack is possible, when using UTF-7 encoded payloads.
The problem is, the advisory says the solution has been implemented already. But I'm able to replicate this still via the email that just arrived in my inbox.

Needless to say, an email is being sent to Google with this information. And this data is being made aware to the public such that users won't get taken in by the scam.

Below is a "thumbnail" of the full screen video of my journey in this nefarious scam. You'll see what the scam site does to conceal your true address location, and spoofs an entirely different address.

Even without the Google XSS exploit, this is a very dangerous phishing scam. The video is about 18 megabytes, so give it time to download. Spread the word, don't let anyone fall victim!


[click here to see 1024x768 view]


Here is an example of the XSS attack the phishing scam uses, this one will redirect you from Google Portugal to the main Google site:

http://www.google.pt/url?sa=U&start=4&q=http://google.com

Update: There is a second site now using this same phishing attack method:

http://www.google.pt/url?sa=U&start=4&q=http://210.110.166.167:8000/1st/index.php

Redirects to http://210.110.166.167:8000/1st/index.php.

Note: Correction 11 Jan: Securiteam is referenced, not Secunia.
Update 11 Jan: There is a second phishing site using this same attack method.
Posted on Wednesday, 11 January 2006 @ 00:32:29 UTC by Paul (16462 reads)
[ Trackback ]
image

"Beware!: PayPal Phishing Site Exploits Google XSS Vulnerability" | Login/Create an Account | 3 comments | Search
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register

Re: PayPal Phishing Site Exploits Google XSS Vulnerability (Score: 1)
by houmantx  on Thursday, 12 January 2006 @ 20:10:03 UTC
(User Info | Send a Message)
I've had this thrown at me several times. In each case, the text was FULL - just as this one is - of misspelled words. Being a good speller, red lights immediately went off. I don't think any multi-national website would have a single misspelled word, much less many of them. Sometimes I think people just don't use their common sense....



Re: PayPal Phishing Site Exploits Google XSS Vulnerability (Score: 1)
by gralicwrap  on Monday, 16 January 2006 @ 04:11:17 UTC
(User Info | Send a Message)
I have seen your phishing example video and I must say you have done an excellent job. Keep up the good work.

We are a software development company based in India and have developed an anti-phishing software which automatically BLOCKS ACCESS to such phishing websites in the users browser.

We have added more than 1800 phishing url's to our phishing database in the last 60 days. You might suggest to your users to try it out.

The anti-phishing software can be downloaded from our website www.gralicwrap.com. It is totally free to use.

Thank you.


 
Login
spacer
Nickname

Password

Security Code: Type Security Code: Usage signifies AUP acceptance
· New User? · Click here to create a registered account.
block bottom
Related Links
spacer
· del.icio.us!
· digg it!
· reddit!
· TrackBack (0)
· PHP HomePage
· HotScripts
· Google Search Engine
· W3 Consortium
· More about Phishing
· News by Paul


Most read story about Phishing:
False PayPal Charges!

block bottom
Article Rating
spacer
Average Score: 1
Votes: 2


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


block bottom
Options
spacer

Printer Friendly Page  Printer Friendly Page

block bottom
spacer spacer