Auteur Sujet: [MMPC]Phishing: not just for banks  (Lu 4533 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[MMPC]Phishing: not just for banks
« le: juin 30, 2012, 07:01:07 »
Phishing: not just for banks

<div class="ExternalClass965739E9E84D4F7998EF3104A8E66084">
<p>When people think of phishing (a deception to trick a user into sharing their credentials with a third party), they might usually think of banking. But with the popularity of online games, they can still be a target even if they protect their banking information. A typical reason for phishing in games is to steal in-game money and items.</p>
<p>A phish might promise something free; since the phisher doesn't have to deliver, they could promise anything. In this example, the phisher promises two free Steam games:</p>
<p><a title="PWS:HTML/Phish.BF" href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/steam.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/steam-thumb.png" /></a></p>
<p>The phishing email is detected as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BF">PWS:HTML/Phish.BF</a>.</p>
<p>A phish might tell the user that their account has been suspended, or threatened with suspension, and that they can save it by verifying their information. In these examples, a phishing website tells the user that they have done something against the terms of service of Zynga Poker:</p>
<p><a title="PWS:HTML/Phish.BC" href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/zynga1.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/zynga1-thumb.png" /></a></p>
<p>(Detected as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BC">PWS:HTML/Phish.BC</a>.)</p>
<p><a title="PWS:HTML/Phish.BE" href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/zynga2.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/zynga2-thumb.png" /></a></p>
<p>(Detected as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BE">PWS:HTML/Phish.BE</a>.)</p>
<p>A phish may also try to plausibly look like the&nbsp;actual login page, and hope that users treat it like it is authentic and enter their information. In this example, a phishing website tries to look just like the login for&nbsp;RuneScape:</p>
<p><a title="PWS:HTML/Phish.BB" href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape3.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape3-thumb.png" /></a></p>
<p>(Detected as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BB">PWS:HTML/Phish.BB</a> or <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BD">.BD</a>.)</p>
<p>In fact, RuneScape phishing is so popular that sites have sprung up to offer ready-made phishing sites. Here is a landing page for such a site:</p>
<p><a href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape1.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape1-thumb.png" /></a></p>
<p>And the main forum:</p>
<p><a href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape2.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/runscape2-thumb.png" /></a></p>
<p>The phisher enters some information to set up an account, and then can start spreading the URL to his phishing page. After victims have entered their information, the stolen credentials are stored, and the phisher can log into his phishing account to view the credentials they have collected.</p>
<p><strong>Protecting yourself</strong><br />The phisher typically uses in-game messaging to target their audience and spread the link to the phishing site. Typically this will bypass content-filtering mechanisms like antispam. Users should only log into their game accounts through their game program, or navigating to the game's website themselves.</p>
<p>PS: Here's one more example, an instant message that I received in recent days. It was sent by someone I already had in my contact list, so likely he fell for the bait and now the phishers are sending out more phishing messages from his account. This is a screenshot of Trillian, which&nbsp;connects to the Yahoo Instant Messenger Network:</p>
<p><img src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/yahoo2.png" /></p>
<p>If the link is clicked, it leads to the following website, which is detected as <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=PWS%3aHTML%2fPhish.BA">PWS:HTML/Phish.BA</a>:</p>
<p><a title="PWS:HTML/Phish.BA" href="http://www.microsoft.com/security/portal/blog-images/Phishing_games/yahoo1.png"><img alt="" src="http://www.microsoft.com/security/portal/blog-images/Phishing_games/yahoo1-thumb.png" /></a></p>
<p>This resembles the actual Yahoo! login page however, closer inspection reveals that the webpage is not in yahoo.com but rather in config-verify.info.</p>
<p>-- MMPC</p>
</div><div style="clear:both;"></div><img src="http://blogs.technet.com/aggbug.aspx?PostID=3504768" width="1" height="1">
Source: Phishing: not just for banks

Tags: