lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <200406110103.i5B1356p012010@web185.megawebservers.com>
From: 1 at malware.com (http-equiv@...ite.com)
Subject: FOUND: COELACANTH: Phreak Phishing Expedition


>From the original discover, 'bitlance winter' one big fat 
coelacanth:

<a href="http://www.malware.com%2F redir=www.e-gold.com">test</a>

"i guess that this issue is not e-gold's BUG,
IE6 and Opera7.51 is vulnerable.

Some server's DNS allow magic number subdomainname.
the server allow ,
www.site.tld
wwwww.site.tld
wwwwwwwwwwww.site.tld
www   www.site.tld
wwwURLEncodecharcterswww.site.tld
when the server allows URLEncodecharacters 
evil attackers can fake victim users who use Opera and IE .

the attacker will make their DNS
*.evilsite.tld IN A 333.333.333.333

using this DNS,
victim's IE can shows victim
http://w.evilsite.tld
http://wwwwwwwwwwwwwwwwwww.evilsite.tld

and then,
attacker makes an evil link as 
http://www.microsoft.com [malicious falke char$]  evilsite.tld

and then, attacker set tricks
Bugtraq: Stupid Phishing Tricks (you find it)

victim user will input his userID and password.

I guess many server's DNS allow 
*.evilsite.tld IN A 333.333.333.333
because they use magicnumber SSL cert.
Attacker can use this method."

 
-- 
http://www.malware.com














Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ