Fraud foray fools phishing filter

A new phishing technique allows attackers to bypass the fraud warnings issued by browsers such as Firefox and Chrome.


A new phishing technique allows attackers to bypass the fraud warnings issued by browsers such as Firefox and Chrome.

This move involves attaching an HTML document instead of sending a link, according to security firm M86Security. It remains unclear how many users have become victims so far.

Email recipients opening the HTML document in their browsers see a bogus PayPal form with the usual request to enter their access data due to alleged security issues. As the form processes locally on the user’s computer, the phishing filter doesn’t issue a warning because it only filters external URLs. A click on the “Submit” button then transmits the entered data to a PHP script on a (hacked) server using a POST request. The browser doesn’t warn about this either, according to M86Security.

While browsers should at least warn users when sending the data, M86Security stated two potential reasons why they won’t: As users don’t see the URL they access via POST requests, they can’t report it, and consequently the URL is missing in the browser filter’s blacklist. Most users can’t make anything of the HTML source code attached to the email, M86Security said.

Secondly, URLs which lead to a PHP script are very difficult to classify as phishing sites, M86Security said. It is hard to identify a phishing site without the accompanying HTML code which could, for instance, reveal whether a site pretends to be a banking site. This has apparently caused phishing campaigns to remain undetected.

M86Security didn’t state whether its assessment only refers to the filter lists maintained for Chrome, Firefox and other browsers, or whether it also includes those of the AV vendors, who maintain separate lists for their own filter products.

No comments
Consulting-Specifying Engineer's Product of the Year (POY) contest is the premier award for new products in the HVAC, fire, electrical, and...
Consulting-Specifying Engineer magazine is dedicated to encouraging and recognizing the most talented young individuals...
The MEP Giants program lists the top mechanical, electrical, plumbing, and fire protection engineering firms in the United States.
Commissioning lighting control systems; 2016 Commissioning Giants; Design high-efficiency hot water systems for hospitals; Evaluating condensation and condensate
Solving HVAC challenges; Thermal comfort criteria; Liquid-immersion cooling; Specifying VRF systems; 2016 Product of the Year winners
MEP Giants; MEP Annual Report; Mergers and acquisitions; Passive, active fire protection; LED retrofits; HVAC energy efficiency
Driving motor efficiency; Preventing Arc Flash in mission critical facilities; Integrating alternative power and existing electrical systems
Putting COPS into context; Designing medium-voltage electrical systems; Planning and designing resilient, efficient data centers; The nine steps of designing generator fuel systems
Designing generator systems; Using online commissioning tools; Selective coordination best practices
As brand protection manager for Eaton’s Electrical Sector, Tom Grace oversees counterfeit awareness...
Amara Rozgus is chief editor and content manager of Consulting-Specifier Engineer magazine.
IEEE power industry experts bring their combined experience in the electrical power industry...
Michael Heinsdorf, P.E., LEED AP, CDT is an Engineering Specification Writer at ARCOM MasterSpec.
click me