Attacks/Breaches
7/30/2008
06:58 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Phishing Kits Widely Compromised To Steal From Phishers

From 21 different distribution sites, the authors of the Usenix Conference paper identified 379 distinct phishing kits, 129 of which contained back doors.

Would-be phishers can buy, or obtain for free, phishing kits, which include the files necessary to duplicate a targeted Web site and scripts to steal information submitted by phishing victims. They're widely available online, but they're also untrustworthy.

In January, Netcraft security researcher Paul Mutton identified a phishing tool kit distributed by a group of Moroccan cybercriminals that had been compromised with a back door. Unbeknownst to its users, the phishing kit sent copies of stolen information to its creators.

Now it turns out that more than 40% of the live phishing kits found online (61 out of 150) have back doors designed to steal from the information thieves using them.

In a paper presented on Monday at the Usenix Conference in San Jose, Calif. -- "There Is No Free Phish: An Analysis Of 'Free' And Live Phishing Kits" -- security researchers Marco Cova, Christopher Kruegel, and Giovanni Vigna from the University of California, Santa Barbara, have found that the big phishers -- the authors of phishing kits -- feed on the little phishers who deploy phishing kits.

And there are a surprising number of phishing tool kits. From 21 different distribution sites, the authors of the paper identified 379 distinct phishing kits, 129 of which contained back doors.

The phishing kits targeted 49 different organizations, mainly banks and auction sites, but also e-mail providers and gaming portals. Among the kits downloaded from distribution sites, the five most common targets were Bank of America (21 kits), eBay (19), Wachovia (18), HSBC (18), and PayPal (15).

Most of the live backdoor phishing kits send hijacked information to e-mail drop accounts. Two of the kits stored hijacked information in a file on the phishing site server, and one sent the information to an outside server using a POST request.

And in an attempt to conceal the true nature of their software, phishing kit authors frequently obfuscate their code and include comments in their code designed to discourage modifications that might close their secret back door.

However, comments like "Don't need to change anything here" do more to invite suspicion than to allay it.

"In other cases, comments sound outright sarcastic," the paper said. "In one instance, the indexes of the array used in a permutation-based obfuscation read 'good for your scam.'"

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-4801
Published: 2014-12-18
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.