<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Andreas Baumhof &#187; phishing</title>
	<atom:link href="http://www.tidos-group.com/blog/tag/phishing/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tidos-group.com/blog</link>
	<description>malware research, IT Security and life in general :-)</description>
	<lastBuildDate>Mon, 16 Nov 2020 18:25:55 +0000</lastBuildDate>
	<language>en-US</language>
		<sy:updatePeriod>hourly</sy:updatePeriod>
		<sy:updateFrequency>1</sy:updateFrequency>
	<generator>https://wordpress.org/?v=3.9.40</generator>
	<item>
		<title>Protection vs Censorship</title>
		<link>http://www.tidos-group.com/blog/2013/09/27/protection-vs-censorship/</link>
		<comments>http://www.tidos-group.com/blog/2013/09/27/protection-vs-censorship/#comments</comments>
		<pubDate>Fri, 27 Sep 2013 17:26:04 +0000</pubDate>
		<dc:creator><![CDATA[abaumhof]]></dc:creator>
				<category><![CDATA[Curiosities]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://www.tidos-group.com/blog/?p=502</guid>
		<description><![CDATA[The title might sound a bit harsh, but with all these &#8220;good&#8221; people trying to protect you, where is the line between protection and censorship? Byron Acohido (@byronacohido) just posted this tweet I personally hate these short URLs, but I thought this sounds interesting. The reason I hate these short URLs is that you don&#8217;t [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>The title might sound a bit harsh, but with all these &#8220;good&#8221; people trying to protect you, where is the line between protection and censorship?</p>
<p>Byron Acohido (@byronacohido) just posted this tweet</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/tweet.png"><img class="aligncenter size-medium wp-image-504" alt="tweet" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/tweet-300x41.png" width="300" height="41" /></a>I personally hate these short URLs, but I thought this sounds interesting. The reason I hate these short URLs is that you don&#8217;t know where they take you (this one takes you from bit.ly/1eUu9e2 to t.co/yzm89jFvxS <img src="http://www.tidos-group.com/blog/wp-includes/images/smilies/icon_wink.gif" alt=";-)" class="wp-smiley" />  In this case it leads you to this:</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/pic1.png"><img class="aligncenter size-medium wp-image-505" alt="pic1" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/pic1-300x158.png" width="300" height="158" /></a>Wow&#8230; That&#8217;s what I preach almost daily&#8230; Watch out what you click on!!! And now I have to be saved by twitter??? Let&#8217;s have a look what this page really is all about:</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/pic2.png"><img class="aligncenter size-medium wp-image-506" alt="pic2" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/pic2-300x158.png" width="300" height="158" /></a>I can confirm that this is neither a &#8220;web forgery&#8221; or a &#8220;phishing site&#8221;. It&#8217;s also not a &#8220;site that downloads malicious software onto your computer&#8221;, nor is it a &#8220;spam site that requests personal information&#8221;. There is no iframe, not even javascript on this page. Only a couple of external references (e.g. youtube)..</p>
<p>Now I don&#8217;t care too much about whether TouchID has been hacked yet, but this almost crosses the line for me where twitter&#8217;s security team has been a bit too &#8220;motivated&#8221; to block content that is definitely not malicious.</p>
<p>What&#8217;s next? What other pages will be blocked in the name of security?</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tidos-group.com/blog/2013/09/27/protection-vs-censorship/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Search Engine Poisoning (malicious ad)</title>
		<link>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/</link>
		<comments>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/#comments</comments>
		<pubDate>Thu, 19 Sep 2013 06:44:08 +0000</pubDate>
		<dc:creator><![CDATA[abaumhof]]></dc:creator>
				<category><![CDATA[bitcoin]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://www.tidos-group.com/blog/?p=487</guid>
		<description><![CDATA[A very valid question that comes up all the time is &#8220;how do people get infected with malware&#8221; or &#8220;how do people lost personal information?&#8221; and there are so many ways that people are blown away by some of the examples I show them. Today I came across one nice one again&#8230; Malicious Ad&#8217;s or [&#8230;]]]></description>
				<content:encoded><![CDATA[<p>A very valid question that comes up all the time is &#8220;how do people get infected with malware&#8221; or &#8220;how do people lost personal information?&#8221; and there are so many ways that people are blown away by some of the examples I show them.</p>
<p>Today I came across one nice one again&#8230; Malicious Ad&#8217;s or Search Engine Poisoning&#8230; I used coinbase for some bitcoin activities and I wanted to transfer some bitcoins. So I typed in &#8220;bitcoin&#8221; into google and this is what came up <a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase1.png"><img class="aligncenter size-full wp-image-485" alt="coinbase1" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase1.png" width="800" height="745" /></a></p>
<p>So far so good and everything looks great. I now just click on the first link as this is an ad where someone pays Google money and Google not being evil, must mean that this is good, right? wrong.</p>
<p>All visual signs suggest that this is legitimate and the URL goes to google.com, but that should be ok as well, right? A look at the source reveals that this goes to google before it goes to one URL shortener to another URL shortener and then to the final destination!)</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase5.png"><img class="aligncenter size-large wp-image-497" alt="coinbase5" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase5-1024x545.png" width="625" height="332" /></a></p>
<p>&nbsp;</p>
<p>after the first URL shortener, we&#8217;ll see this!<a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase2.png"><img class="aligncenter size-large wp-image-491" alt="coinbase2" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase2-1024x404.png" width="625" height="246" /></a></p>
<p>oops&#8230;</p>
<p>Luckily it was already known that this site is up to no good, as this server did hold a number of &#8220;nice&#8221; phishing pages designed to steal your bitcoin wallet information. With the current price of over 120 USD for one bit coin, that could be a very lucrative business</p>
<p>Some examples are:</p>
<p><a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase3.png"><img class="aligncenter size-large wp-image-492" alt="coinbase3" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase3-1024x615.png" width="625" height="375" /></a> <a href="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase4.png"><img class="aligncenter size-large wp-image-493" alt="coinbase4" src="http://www.tidos-group.com/blog/wp-content/uploads/2013/09/coinbase4-1024x615.png" width="625" height="375" /></a></p>
<p>&nbsp;</p>
<p>Approximately 1h after notifying google, the malicious ad was gone, but please make sure you double-check where you click on.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.tidos-group.com/blog/2013/09/19/search-engine-poisoning-malicious-ad/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
