new wave of phishing attacks against eBay

A new wave of phishing attacks against eBay is exploiting a clever combination of wildcard DNS records and cross-site scripting (XSS) vulnerabilities to use other people’s websites to help steal credentials from victims.

The first attacks using this combined method of wildcard DNS records and XSS were detected by Netcraft on February 10th, although the source code behind the attacks suggest that the planning had begun a day earlier. The attacks have continued to the present day, and the fraudulent eBay login form remains accessible through the wildcard domains.

Fraudsters launched the attack using a number of sites that host vulnerable versions of iRedirector Subdomain Edition. This PHP and MySQL based system allows website owners to use wildcard DNS records on their domains to forward subdomains like http://user.example.com to URLs like http://www.example.com/members/~username.

A cross-site scripting vulnerability on the affected iRedirector sites is allowing the fraudsters to inject framesets into specific pages. These framesets load content from one of the fraudsters’ websites hosted in France at http://df0x.54.pl, which in turn loads an iframe located at http://0xdc4bdd88:88/ws/eBayISAPI.dll/. This injected iframe presents a fraudulent eBay login page, which prompts the victim to submit their eBay User ID and Password to a site hosted by Sudokwonkangnambonbujang in South Korea.

Because the vulnerable sites can be accessed via wildcard DNS records, the fraudsters have made the attacks look all the more convincing by making the hostnames look similar to those used by the genuine eBay login page. For example, the attack has used many hostnames that are similar to this:

phishing

phishing address

The hostnames used in these attacks also contain a seemingly random string of hexadecimal digits. These are simply MD5 hashes of small integers. It is likely that this semi-random measure is being used to try and bypass simplistic firewalls or email filters, which may not recognise fraudulent URLs if part of the hostname changes.

The unobtrusive methods used in the current wave of attacks have obvious appeal to fraudsters — the wildcard DNS records mean that it’s easy to use arbitrary hostnames for each attack, allowing each vulnerable site to be convincingly used for many different targets. Furthermore, there is no need for the fraudsters to fully compromise a website, as the cross-site scripting vulnerability allows the fraudulent content to be placed on the sites without gaining internal access to the server. Finally, all it takes is a simple Google search to find additional sites with the same vulnerabilities. The combination of these factors makes it entirely feasible to automate the whole process.


Sursa
2009-02-18 15:15:52



Comenteaza





Ultimele 25 posturi adăugate

05:03:22ÎNTRE PROZĂ ȘI YES-EU —» Leo Butnaru
15:11:26„O societate puternică înseamnă o societate informată și unită” – Rodica Lilica, studentă la programul dual Finanțe și Bănci, ASEM 💫 —» Sandu GRECU
15:04:29„Europa nu este doar o destinație, ci cel mai sigur plan prin care ne putem moderniza fiecare localitate” – Cristian David, Președinte ILD România 💫 —» Sandu GRECU
12:10:57Feteasca Run: prima cursă care unește vinăriile din Cricova —» Fine Wine
11:53:47Festivalul vinului de autor: 4-6 septembrie —» Fine Wine
18:11:55FIECARE COPIL MERITĂ ȘANSA DE A-ȘI URMA VISUL! 💙💛 —» Sandu GRECU
05:11:19DIN REVISTA TINERILOR —» Leo Butnaru
12:37:25Under 15. Jucători din țară și de peste hotare, convocați de FMF la un nou trial ⚽️ —» Sandu GRECU
12:18:35„Ca primar, nu sunt aici pentru declarații, ci pentru fapte” – Viorel Jardan, primarul comunei Lozova 💫 —» Sandu GRECU
09:46:20Biblioteca – punct de întâlnire între diasporă și acasă —» BPR Ungheni's Blog
18:40:53„ALB DUPĂ ALB” – expoziție de Doina Mihăilescu, la Muzeul Național de Artă al Moldovei din Chișinău 🏦 —» Sandu GRECU
18:25:21Derzamăgit de organele de drept, vrea să plece afară —» Curaj.TV | Media alternativă
12:19:46DIN REVISTA TINERILOR —» Leo Butnaru
15:24:47🎾 ROMINA HÎNCU, AL TREILEA TROFEU DIN 2026! 🇲🇩🏆 —» Sandu GRECU
15:24:47🎾 ROMINA HÎNCU, AL TREILEA TROFEU DIN 2026! 🇲🇩🏆 —» Sandu GRECU
04:54:53CARTE NOUĂ PENTRU COPII —» Leo Butnaru
13:45:15Arta nu tace: Perjovschi cu David —» Curaj.TV | Media alternativă
16:59:59NU CÂT ȘTIE, CI CÂT ÎȘI PERMITE... —» Leo Butnaru
11:49:49Petru Racu: jucători pe pile la Națională și cei care veneau să se odihnească. Pariuri: prețul unui galben 💥💥💥 —» Sandu GRECU
11:46:26Vin cu aur la Mondial de Bruxelles – 55 mdl —» Fine Wine
11:45:31Cardinalul fotbalului, Nicolai Cebotari. Portar de top, cearta cu Ciobanu, arbitraje, dinastia 🔥🔥🔥 —» Sandu GRECU
11:41:00De la pasiunea pentru sere moderne la „Agricultura Inteligentă”: Povestea lui Piotr Caraman, masterandul care dă tonul inovației la UTM 💥 —» Sandu GRECU
11:40:41AGG Group investește în producția locală: un exemplu de reinvestire strategică în economia Republicii Moldova 💫 —» Sandu GRECU
11:31:45Agricultura modernă te așteaptă! În aceste zile se desfășoară admiterea la instituțiile de învățământ agricol ✍️ —» Sandu GRECU
10:25:22Sălcuța intră pe piața spumantelor —» Fine Wine