Attacks/Breaches
1/15/2013
10:13 PM
Tim Wilson
Tim Wilson
Quick Hits
50%
50%

New 'Bouncer List' Exploits Turn Phishing Into Clubbing

Targeted email attacks mirror your favorite night club; if you're not on the list, then you don't get in

In the old days, phishing worked like spam -- the more users it hit, the more successful it was considered to be. But a new attack concept uncovered this week turns fraudulent email attacks in the opposite direction.

A new, laser-targeted form of spear-phishing is the subject of a blog posted Tuesday by security researchers at RSA.

The new attack is called "bouncer list phishing" because it works like the bouncers at your favorite night club -- if users are not on the list, then they don't get phished.

"The bouncer phishing kit targets a preset email list for each campaign," the blog explains. "A user ID value is generated for the targeted recipients, sending them a unique URL for access to the attack. Here's the interesting part – much like a night club's bouncer list – any outsider attempting to access the phishing page is redirected to a '404 page not found' error message." RSA compares the attack to a "black hat whitelist."

"When victims access the phishing link, their name has to be on the list and their 'ID' value is verified on the fly as soon as they attempt to browse to the URL," the blog states. "After a scan of the "bouncer list," unintended visitors are stirred away from the phishing page; in fact, the page is not even generated for eyes it was not meant for.

"As for validated users -- the less fortunate that are let in -- the kit immediately generates an attack page, creating it on the very same hijacked website," the blog continues. "The kit's code is programmed to copy pertinent files into a temporary new folder and send victims to that page in order to steal their credentials.

"After the kit collects victim credentials, it sends them to yet another hijacked website -- taken over using the exact same method of vulnerability exploit and web-shell -- where the password-protected attack page lies in wait to steal user credentials," the blog explains.

The attack is a complete reversal of traditional phishing attacks designed to infect as many users as possible, the blog observes. "...the phisher is laser-focusing the campaign in an effort to collect only the most pertinent credentials for his purposes," RSA states. "Keeping out uninvited guests also means avoiding security companies and prompt takedowns of such attacks."

The highly targeted approach is likely the work of a gang or a fraud service vendor supplying credentials to specific geographical regions and targets, RSA postulates.

Scott Greaux, vice president of product management and services at anti-phishing service PhishMe, doesn't expect the new tactic to make a huge impact on enterprises.

"While phishing kits are an interesting technology, they are more consumer-focused in nature, and I don't expect to see them incorporated by the types of APT attacks that we've seen targeted at large organizations," Greaux says. "Phishing kits are not personalized and thus don't employ what we've found to be the most effective weapon a phishing email can use: personal details that make it appear genuine.

"However, the increased sophistication and prevalence of phishing kits underscore the need to train employees to recognize all types of phishing emails," Greaux states. "A savvy user will be able to recognize the signs of a suspicious email -- regardless of whether it's from a phishing kit or is a traditional spear phish -- and react appropriately."

Have a comment on this story? Please click "Add a Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?