new wave of phishing attacks against eBay

A new wave of phishing attacks against eBay is exploiting a clever combination of wildcard DNS records and cross-site scripting (XSS) vulnerabilities to use other people’s websites to help steal credentials from victims.

The first attacks using this combined method of wildcard DNS records and XSS were detected by Netcraft on February 10th, although the source code behind the attacks suggest that the planning had begun a day earlier. The attacks have continued to the present day, and the fraudulent eBay login form remains accessible through the wildcard domains.

Fraudsters launched the attack using a number of sites that host vulnerable versions of iRedirector Subdomain Edition. This PHP and MySQL based system allows website owners to use wildcard DNS records on their domains to forward subdomains like http://user.example.com to URLs like http://www.example.com/members/~username.

A cross-site scripting vulnerability on the affected iRedirector sites is allowing the fraudsters to inject framesets into specific pages. These framesets load content from one of the fraudsters’ websites hosted in France at http://df0x.54.pl, which in turn loads an iframe located at http://0xdc4bdd88:88/ws/eBayISAPI.dll/. This injected iframe presents a fraudulent eBay login page, which prompts the victim to submit their eBay User ID and Password to a site hosted by Sudokwonkangnambonbujang in South Korea.

Because the vulnerable sites can be accessed via wildcard DNS records, the fraudsters have made the attacks look all the more convincing by making the hostnames look similar to those used by the genuine eBay login page. For example, the attack has used many hostnames that are similar to this:

phishing

phishing address

The hostnames used in these attacks also contain a seemingly random string of hexadecimal digits. These are simply MD5 hashes of small integers. It is likely that this semi-random measure is being used to try and bypass simplistic firewalls or email filters, which may not recognise fraudulent URLs if part of the hostname changes.

The unobtrusive methods used in the current wave of attacks have obvious appeal to fraudsters — the wildcard DNS records mean that it’s easy to use arbitrary hostnames for each attack, allowing each vulnerable site to be convincingly used for many different targets. Furthermore, there is no need for the fraudsters to fully compromise a website, as the cross-site scripting vulnerability allows the fraudulent content to be placed on the sites without gaining internal access to the server. Finally, all it takes is a simple Google search to find additional sites with the same vulnerabilities. The combination of these factors makes it entirely feasible to automate the whole process.


Sursa
2009-02-18 15:15:52



Comenteaza





Ultimele 25 posturi adăugate

12:54:55PRINTRE LAUREAȚI —» Leo Butnaru
07:22:51Grand Gold pentru The Governor Saperavi Forte —» Fine Wine
13:52:30Carolina Bogatiuc: „Republica Moldova lucrează deja cu UE pe toate grupurile de capitole de negociere” ✨ —» Sandu GRECU
11:43:14Ambasada Chinei nu are loc de Falun Dafa?! —» Curaj.TV | Media alternativă
10:35:26Equinox lansează două vinuri noi —» Fine Wine
15:33:45Cine a trăit aici înainte de daci? Ce dezvăluie ADN-ul —» Curaj.TV | Media alternativă
12:39:32Mă simt un mesager al culturii moldovenești… —» Biblioteca de Arte 'Tudor Arghezi'
09:16:54Federația Moldovenească de Fotbal a creat Fondul destinat susținerii Centrelor de Pregătire a Copiilor și Juniorilor din Republica Moldova 💲 —» Sandu GRECU
08:33:35Patru stiluri, o confirmare: Radacini ia aur la Mondial de Bruxelles —» Fine Wine
05:50:28DESCHIS MIRĂRII —» Leo Butnaru
16:32:18„O afacere europeană înseamnă să fii mereu alături de oameni, prin fapte reale” – Cristina Aramă, Manager Afaceri Corporative, Kaufland Moldova 💫 —» Sandu GRECU
08:52:29Agenția de Investiții lansează un nou apel pentru ediția 2026-2027 a Programului BRIDGE Export: Granturi pentru consolidarea prezenței produselor moldovenești pe piețele externe 🌉 —» Sandu GRECU
08:43:26Republica Moldova lansează platforma oficială www.moldova.md, un nou instrument de prezentare a țării 💫 —» Sandu GRECU
18:24:00Nicolae Usatîi: Mi s-a propus să-l kidănesc pe tata. Secretul Petrocub. Schemele din fotbal 💥💥💥 —» Sandu GRECU
11:33:39Achiziții noi, 2026 —» Biblioteca de Arte 'Tudor Arghezi'
07:13:13DIN REVISTA TINERILOR —» Leo Butnaru
14:49:09Proiect inedit în vinuri: Calendar —» Fine Wine
19:51:38Datele a 50.000 de cetățeni ai Republicii Moldova pe Dark Web —» Curaj.TV | Media alternativă
19:51:38Datele a 50.000 de cetățeni ai Republicii Moldova pe Dark Web —» Curaj.TV | Media alternativă
04:24:49patriarchy and capitalism —» turn up the silence
06:21:22Luna mai a adus mai multe solicitări pentru bibliotecare —» BPR Ungheni's Blog
21:35:18Aceeași scenă, alt unghi —» APort | "Pentru un român care știe citi, cel mai greu lucru e să nu scrie." I.L. Carag
05:31:28JURNALUL LUI ORFEU —» Leo Butnaru
17:07:46De la Polul Nord la Polul Sud: o aventură de 73.000 de kilometri, transpusă într-o carte lansată la Ploiești —» Curaj.TV | Media alternativă
17:07:46De la Polul Nord la Polul Sud: o aventură de 73.000 de kilometri, transpusă într-o carte lansată la Ploiești —» Curaj.TV | Media alternativă