31.07.2015 Views

Download

Download

Download

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

include the phishing site in question. Plus, you might want to note the port this site is runningon (i.e., 2006). While the example has been removed from the Internet, a minorchange to the URL will result in a valid link.Original phisher’s URL:http://www.google.com/pagead/iclk?sa=l&ai=Br3ycNQz5Q-fXBJGSiQLU0eDSAueHkArnhtWZAu-FmQWgjlkQAxgFKAg4AEDKEUiFOVD-4r2f-P____8BoAGyqor_A8gBAZUCCapCCqkCxU7NLQH0sz4&num=5&adurl=http://211.240.79.30:2006/www.paypal.com/webscrr/index.phpUpdated example URL:www.google.com/pagead/iclk?sa=l&ai=Br3ycNQz5Q-fXBJGSiQLU0eDSAueHkArnhtWZAu-FmQWgjlkQAxgFKAg4AEDKEUiFOVD-4r2f-P____8BoAGyqor_A8gBAZUCCapCCqkCxU7NLQH0sz4&num=5&adurl=http://cnn.comHere is another Shorter one in Google found in August 2006:http://www.google.com/url?q=http://66.207.71.141/signin.ebay.com/Members_Log-in.htmXSS Theory • Chapter 4 103NOTEGoogle has since instituted a change to stop the URL function from doingautomatic redirection, and instead it alerts users that they may be being redirectederroneously. Unfortunately, that is only one of the dozens of redirectsin Google that phishers know about.Phishing is not the only practical use for bad guys. Here is another redirection used toforward users to spam found around the same time:www.google.com/pagead/iclk?sa=l&ai=Br3ycNQz5Q-fXBJGSiQLU0eDSAueHkArnhtWZAu-FmQWgjlkQAxgFKAg4AEDKEUiFOVD-4r2f-P____8BoAGyqor_A8gBAZUCCapCCqkCxU7NLQH0sz4&num=5&adurl=http://212.12.177.170:9999/www.paypal.com/thirdparty/webscrr/index.phpAnother example doing the same thing, but notice how the entire string is URLencodedto obfuscate the real location the user is intended to land on:

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!