Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > 2+2 Communities > Other Other Topics
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #11  
Old 02-23-2006, 10:34 PM
yasher yasher is offline
Senior Member
 
Join Date: Jun 2005
Location: its a classic
Posts: 1,713
Default Re: How do phishers do this?

Warik, JoA:

This is what has me so confused.

If you click the link, at the top of the page there's a link about scams. If you click the scams link, you can find a screenshot of the ORIGINAL page at chaseonline.chase.com, which is really really weird.

The website blames a "trojan horse virus," for displaying that page, but that's BS; that page is obviously THERE...

So what gives?

Confused,
yasher
Reply With Quote
  #12  
Old 02-23-2006, 10:35 PM
Warik Warik is offline
Senior Member
 
Join Date: Dec 2003
Location: Florida
Posts: 2,840
Default Re: How do phishers do this?

[ QUOTE ]
You think its hard for the phishers to do this: <a href="Chase.com" target="_blank">Home of Chase Banks</a>

[/ QUOTE ]

Dude, he looked at the link's properties to compare the actual URL to the displayed URL. They match. This was in the first post.
Reply With Quote
  #13  
Old 02-23-2006, 10:36 PM
yasher yasher is offline
Senior Member
 
Join Date: Jun 2005
Location: its a classic
Posts: 1,713
Default Re: How do phishers do this?

guids,

You're missing the point. It actually directs you to a website at chaseonline.chase.com. Click the link. What you did is not what they did.

Get it?

yasher
Reply With Quote
  #14  
Old 02-23-2006, 10:36 PM
Sponger. Sponger. is offline
Senior Member
 
Join Date: May 2004
Location: San Diego
Posts: 19,136
Default Re: How do phishers do this?

Yeah for some reason I totally fell for this at wells fargo about 8 months ago. I filled out a bunch of stuff and then 5 seconds after I hit enter I realized what a retard I was and called up wells and had them change everything for me. yay.
Reply With Quote
  #15  
Old 02-23-2006, 10:37 PM
guids guids is offline
Senior Member
 
Join Date: Oct 2005
Posts: 12,908
Default Re: How do phishers do this?

[ QUOTE ]
[ QUOTE ]
if i own www.chase.com, you can set up chaseonline.chase.com and not be infringing on my [censored]?

or are these websites just one-shot things, taken down as fast as they get put up?

[/ QUOTE ]

You can't. The only one who can make chaseonline.chase.com or banana.chase.com is chase.com. You CANNOT register a domain with a "dot" in it.

[/ QUOTE ]

ya, this is right, i forgot abotu the dots. you could register chaseonlinesite.com if its not taken...
Reply With Quote
  #16  
Old 02-23-2006, 10:41 PM
guids guids is offline
Senior Member
 
Join Date: Oct 2005
Posts: 12,908
Default Re: How do phishers do this?

The more i look into this, the more I think that the phishsers are just complete morons, and didnt know the phishing trick.
Reply With Quote
  #17  
Old 02-23-2006, 10:42 PM
Warik Warik is offline
Senior Member
 
Join Date: Dec 2003
Location: Florida
Posts: 2,840
Default Re: How do phishers do this?

[ QUOTE ]
If you click the link, at the top of the page there's a link about scams. If you click the scams link, you can find a screenshot of the ORIGINAL page at chaseonline.chase.com, which is really really weird.

[/ QUOTE ]

Wrong. That's not a screenshot of the original page. There are quite a number of differences. Look closely.

That, and another couple of important things:

1) The e-mail does not demand that he enter any information or risk suspension of his account (Chase warns that phishing e-mails usually say "if you don't fill out this info then we will close your account!"

2) The website is a legitimate SECURED SERVER page. Double click on the gold lock icon in the status bar and look at the security certificate. It's a security certificate issued by VeriSign to JPMorgan Chase. VeriSign does not issue these things to phishers... and you cannot fake it.

The e-mail is legit.
Reply With Quote
  #18  
Old 02-23-2006, 10:42 PM
StevieG StevieG is offline
Senior Member
 
Join Date: Jan 2003
Location: b-more
Posts: 3,558
Default Re: How do phishers do this?

That link does looks completely legit.

It could be a man in the middle attack, where they have you compromised somewhere between your browser and the real site, so that to you it looks like you are making that request, but the network serves up the phisher's site instead. This is a danger with wireless in particular, since it is easy to impersonate a known, insecure network.

There was also an attack last year that used Unicode characters that looked like other characters to make domain names that were different from real ones, but to the reader looked the same. Up to date browsers should be protected from this, but Firefox was vulnerable as late as last year. I looked at this link byte by byte, though, and it looks fine that way, too.
Reply With Quote
  #19  
Old 02-23-2006, 10:42 PM
yasher yasher is offline
Senior Member
 
Join Date: Jun 2005
Location: its a classic
Posts: 1,713
Default Re: How do phishers do this?



guids,

the more i look at it, the more i think its the exact opposite, and they're actually really, really good.

OP,

do you have an account with Chase?

yasher
Reply With Quote
  #20  
Old 02-23-2006, 10:44 PM
jman220 jman220 is offline
Senior Member
 
Join Date: May 2005
Posts: 7,160
Default Re: How do phishers do this?

[ QUOTE ]
if i own www.chase.com, you can set up chaseonline.chase.com and not be infringing on my [censored]?

or are these websites just one-shot things, taken down as fast as they get put up?

[/ QUOTE ]

Considering the fact that they are using these websites to commit wire fraud and identity theft, I don't think they're too worried about trademark infringement on top of that.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 10:30 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.