100
Vas
Member
characters
85 Draenei Shaman
83 Night Elf Rogue
80 Night Elf Warrior
85 Draenei Paladin
80 Draenei Death Knight
posted on
05/25/10 07:05:50

New phishing technique and a creepy proof of concept. Article


Inv_misc_questionmark_t100
Deldawalth
Raider
characters
85 Night Elf Warrior
85 Gnome Mage
85 Night Elf Druid
85 Dwarf Hunter
85 Draenei Shaman
85 Night Elf Priest
85 Human Paladin
85 Night Elf Rogue
85 Worgen Warlock
Notatarah (Sen'jin)
80 Night Elf Druid
posted on
05/25/10 11:07:57

Wow, I am anal about how I keep my pc clean but this actually scares me a bit.

The auction house is the only balanced form of PvP in the game.



1
Aven
Administrator
characters
85 Night Elf Hunter
85 Night Elf Druid
85 Dwarf Shaman
65 Worgen Rogue
posted on
05/25/10 11:14:41

I don't know, it assumes that you click on links willy nilly. You still have to open a tab to an infected site or honeypot, and then forget that you opened it. If you spend a lot of time on warez/porn/farting-desktop-widget-of-the-day sites (the kinds of places where stuff like this will live) and you're not already really careful about what you're doing, you're probably already disease ridden.


100
Vas
Member
characters
85 Draenei Shaman
83 Night Elf Rogue
80 Night Elf Warrior
85 Draenei Paladin
80 Draenei Death Knight
posted on
05/25/10 11:54:19

I just read the article. The proof of concept site is blocked at work. They also talk about the possibility of combining it with the :visited w3c specification exploit (proof of concept: Start panic).

It's just interesting. I don't do any "high risk" browsing, as you said, so its still very low risk for me. It just has the potential of making phishing sites harder to detect.

And they said the proof of concept site for the phishing exploit doesn't work at all in Chrome... which is what I use at home (not sure if that is just because it was a Mozilla blogger or not).


1
Aven
Administrator
characters
85 Night Elf Hunter
85 Night Elf Druid
85 Dwarf Shaman
65 Worgen Rogue
posted on
05/25/10 12:28:31

Yea, I guess it's more of an impact if your trust level is high. I still remember the "wild west" of the internet and am still inherently skeptical of any site that I visit.


539
Tink
Member
characters
80 Dwarf Hunter
85 Human Warlock
80 Dwarf Priest
80 Gnome Mage
83 Night Elf Druid
85 Human Paladin
84 Gnome Rogue
80 Night Elf Warrior
85 Draenei Shaman
80 Draenei Death Knight
posted on
05/25/10 13:30:31

[Update: As several readers have correctly pointed out, this attack does in fact work against Chrome, although it doesn't seem to change the favicon in Chrome tabs].

And I'm trolling... :)