27.06.2013 Views

Hack Security Pro.pdf - Index of

Hack Security Pro.pdf - Index of

Hack Security Pro.pdf - Index of

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

We can see that CrashFr is now in bold characters! This means the HTML code is not filtered and well<br />

interpreted by the client's navigator. From then on, the pirate will for example create a fake form in<br />

HTML by using the url instead <strong>of</strong> the form. In the case <strong>of</strong> the above example, the hacker can display<br />

CrashFr in bold characters by going to the following url:<br />

css.php?nickname=CrashFr<br />

Here is a URL that will display a fake form enabling the hacker to steal the login/pass <strong>of</strong> a client:<br />

css.php?nickname=CrashFrPlease identify yourself : Login :Password :<br />

Here is what the client will see on his navigator if he clicks on the link above:<br />

The hacker must make his victim click on this link to have him believe that the form is part <strong>of</strong> the<br />

website itself, which is in fact not the case. If the client falls for this trap, he will enter his login/pass and<br />

when he clicks on “Sign-in”, this information will not be sent to the bank's website but to the<br />

“recov_info.php” file on the “hacker server” server belonging to the hacker. Generally, the hacker will<br />

use url encoding, the sending <strong>of</strong> emails in HTML and SE to trap his victim. Here is an example an<br />

HTML email that the hacker could send to his victim:<br />

<br />

<br />

<strong>Hack</strong>er Bank Paris<br />

<br />

<br />

Dear client,<br />

We would like to inform you that your transfer request has been taken into account, you can check your<br />

balance account at click here. We thank you for your trust.<br />

Yours sincerely Pierre Dupart.<br />

Financial adviser for <strong>Hack</strong>er Bank Paris.<br />

<br />

<br />

The <strong>Hack</strong>ademy DMP -131/209- SYSDREAM

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!