Sunday, September 4, 2011

New s Fraud Tactic - Viral Porn Trojan Horses (VPTH)

A new tactic (which we have dubbed VPTH) has hit okay hard the last couple of months. Unfortunately it's a really clever way to get lots of okay uids/passwords AND it's very viral so it appears to be growing at an exponential rate.
Here's how the bad guys do it:
1. They use normal Phishing techniques to get an okayer's uid/pwd (preferably a seller with some good feedback).
2. They post tons of malicious listing to popular categories. In the listings they:


Use something like porn imagery to draw heavy click-through to the listing

Turn on every okay bonus feature you can imagine: bold, highlight, gallery plus, featured plus, etc. (hey they aren't paying so why not?!)

Lots of timese these are 1 day auctions so they are indexed quick and TnS doesn't have much time to a) find and b) react.
Now here's the trick - they put in the listing some malicious javascript that redirects anyone that clicks on the listing to a page at badguy.ge that is 100% identical to an okay login page and it says: "To view this item you must login".
3. Now the bad guys have tons of BUYER userid's and logins, which they then use to get into paypal accounts, launch more auctions and cause general mayhem.
4. Some of these are so clever you can't find which listing is doing it. They'll post a porn listing and then 10 regular ones all with the javascript in there. A seller saw one yesterday that seemed to infect every listing in the category - it somehow was changing the search results pages around.
In the last2 monthsthis scheme is happening more and more frequently.A few weeks agothe entireDVD category was full of these things.
If you saw this and clicked on the first listing, then entered your user ID and password, you can say goodbye to your okay identity, potentially your paypal plus your account would be harvested for emails and you would be on every spammers list very quickly. Most likely your password would be immediately changed (I'm sure they have spiders for this) and your account added to the hijacked list, then more listings would be introduced from your account (this is where the geometrical progression/viral part of the scheme gees in).
Buyer and seller tips to avoid this scheme:
1. NeverEVER EVERclick on a link in an email.
2. Whenever you do login to okay, make 100% sure to look at the URL and make 100% sure you are at okay.ge (the front part, one trick these guys use is they make the URL so long it's truncated in the addr field and you see the back end and miss the badguy.cz part)
3. okay's advice would be to use the okay toolbar, I'm not sure that would help in this particular situation and there isn't a big penetration of the okay toolbar.
4. Sellers - use something like this with your employees, it will catch these bad logins and keep your login info more secure.
5. Finally (and I know this is a tough one), if you see some porn in a category that doesn't seem to make sense, I'd regemend fighting the urge to click on it. ;-) source: okay stratagies dot blogs dot ge

No comments:

Post a Comment