CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

phishing question

 
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
rswc90

Lieutenant
Lieutenant
Premium Member

Joined: Sep 10, 2003
Posts: 265
Location: USA
Premium

PostPosted: Sat Nov 06, 2004 9:32 pm    Post subject: phishing question
Reply with quote

I received this email and want to know if it's true. Can anyone tell me if i should disable this scripting?

Thanks!
-------------------------
This new danger is a phishing attack. Phishing is computer slang for attacks in which criminals pretend to be a bank or other institution.

They try to trick you into giving up your password and user name.

Most people have learned not to fall for this. But this new attack could fool the most careful people. Here's how it works:

The criminals send you an e-mail (spam). When you open the e-mail, a small program called a script runs. Note that you only need to open the e-mail; there is no attachment.

The scripting program goes to your HOSTS file, located deep in your computer. The actual path in Windows XP is:

C:\Windows\System32\Drivers\Etc\HOSTS

It enters your bank's Web address--for instance, www.YourBank.com--in the HOSTS file. It also enters an Internet Protocol (IP) number for the criminals' address.

The next time you need to surf to your bank, you attempt to go to www.YourBank.com. When you enter that address, or any other address,

the browser first goes to the HOSTS file to find the IP number. If it isn't there (it normally would not be), it goes to a special computer on the Internet to find the IP number.

However, the criminals have put your bank's address in the HOSTS file,
along with their IP number. So you are automatically sent to that IP number, which is the criminals' computer. It looks like the bank's Web site, so you enter your user name and password. That gives the criminals the information they need to enter your account and steal your money.

How can you protect yourself? Some anti-virus programs guard against this kind of thing; others do not. To be safe, you must disable your computer's scripting ability. To do that:

--In Windows XP, click Start > My Computer. Click Tools >Folder Options.

Select the File Types tab. Click File Types, then scroll to and click VBScript Script File. Click Advanced. In the Actions box, click Open.

Click Remove.

If you need to restore scripting, click New. Put Open in the Action box. In the next box, click Browse. Find wscript.exe in C:\Windows\System32. Double-click it.

-----------------------------

Back to top
View users profile Send private message Send email Visit posters website AIM Address
TobyR

Cadet
Cadet


Joined: Nov 06, 2004
Posts: 5
Location: UK

PostPosted: Sun Nov 07, 2004 7:51 pm    Post subject:
Reply with quote

The e-mail sounds genuine, but I'm not sure whether or not these days by default e-mail clients do allow such scripts to be automatically run by e-mails. If you are reluctant to make any internet options changes then to protect yourself against this specific threat you could make the 'hosts' file read-only.

Back to top
View users profile Send private message
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16536

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Sun Nov 07, 2004 8:26 pm    Post subject:
Reply with quote

Ha! There's so much stuff that wants access to the host file that this won't last long. Rolling Eyes In fact it seems some legit apps that make use of this file, just go ahead and reset the read-only flag, change the host file, but leave the read-only flag reset. Evil or Very Mad

Back to top
View users profile Send private message
sfpdiaspora

Cadet
Cadet


Joined: Dec 17, 2004
Posts: 3
Location: USA

PostPosted: Sat Dec 18, 2004 5:02 am    Post subject:
Reply with quote

Actually, there are some really evil trojans that I've come across that modify /etc/hosts...but as far as I know this is impossible without actually running an application to do this.

It is true that this is the most dangerous scenario because you could in actuality be going to www.citibank.com in your browser, but since your computer checks HOSTS before actually resolving any domain names, you could be redirected to a phishing site without knowing it.

I think you can delete the /etc/hosts file but I'm not sure...I'll look into it. By default it's empty except for mapping localhost to 127.0.0.1 or something.

Mike

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Phishing, Fraud and Dastardly Deeds All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer