PDA

View Full Version : Password Sniffing Busted


Admin
8th April 2006, 05:49 PM
Subject: Network Security Update: Password Sniffing Busted
Following is the screenshot of a fake Yahoo Login screen fabricated by a hacker who sent me the file to steal my password:

http://www.bhavsarsamaj.com/forum/uploads/dhayfule/2006-03-29_095732_yahoo.gif


When I opened the file it struck to my mind that it seemed to be a malicious page, so opened it in front page, to view the form properties, what I saw really shocked me.

http://www.bhavsarsamaj.com/forum/uploads/dhayfule/2006-03-29_100053_yahooformtarget.gif

I found a non Yahoo ID in Action (now those who are'nt aware of HTML just simply understand that action is the target location where the values entered in the form would be transfered for processing) field. That path lead to a malicious script that mails data to an id found in the hidden fields as seen below:

http://www.bhavsarsamaj.com/forum/uploads/dhayfule/2006-03-29_100533_tovalue.gif

As seen in the above screenshot the above values predict the victim and the hacker. The action that would have been taken place is as follows:
1) First my password would have been grabbed from the text box and been sent to the link seen above for processing.
2) The subject line would contain "Password Received"
3) The victim's Email/Messenger id is provided here is dhayfule@yahoo.com (http://us.f503.mail.yahoo.com/ym/Compose?To=dhayfule@yahoo.com)
4)Then the page gets redirected to a "Page Not Found" Error
5)But in background the mail is sent to the hacker's id, which is here provided as angel4shashi@yahoo.com (http://us.f503.mail.yahoo.com/ym/Compose?To=angel4shashi@yahoo.com)

This is how users are fooled and complain that their ids are hacked.

Things to remember:
1) Never ever accept files through Messenger, it reveals ur IP Address to the opposir person.
2) Before entering passwords in the forms received in mail or through URLs, view the source for the information provided above i.e. "Action" and hidden fields.
3) Never disclose your password, to any one.
4) Never surf pronographic or any other sites that may contain illicit materials, since they are a good source for password sniffers.
5) Frequently change your passwords.

Take care while you are online. Since this is just Yahoo, hackers can try hands on your NetBanking, PayPal, EBay and other such accounts!!!

Also educate your corncerned ones with this information.

Finally, never ever try this trick on others!!!!!

Edit : Posted By Pravin Dhayfule on Bhavsarsamaj.com

GodFather
9th April 2006, 12:06 AM
Good find, making it a sticky...for other ppls benefit.:thumbup:

Eshtyle Raja
9th April 2006, 12:20 AM
Did a good search....thanks buddy :getdrunk:

greatalok
9th April 2006, 01:10 AM
good info, thanks

God_Of_Death
11th April 2006, 08:51 PM
I happen to know the site which provides these Pages for IP spoofing... u just have to pay some fee of 1$ n then they'll the exact replica of the page to the person who's password u want to hack.....

if im correct the URL of the site is www.spoof.com, allthough im sure abt the URl but it worked in the similar manner as ADMIN dude has explicated.....

Thanks for the additional info admin bhai:toast:

dhayfule
29th August 2007, 08:35 PM
Hey Admin,
I really wonder from where did you obtain this article written by me, since I had posted it on a Private forum managed by me its www.bhavsarsamaj.com/forum and for evidence you can right click on the images and check the properties you can find the URL of my community portal http://www.bhavsarsamaj.com/forum/uploads/dhayfule/2006-03-29_100053_yahooformtarget.gif

Infact I had Copyrights note in this article. You could have atleast specified Pravin Dhayfule as the Author.

By the way great to see that my article is appreciated by many.
As for me am Pravin Dhayfule - CEO of www.bhavsarsamaj.com from where this article has been fetched.

Bye
Regards

Admin
29th August 2007, 08:45 PM
I suppose i got a forward which i posted here...

I have edited the post with your credentials... :)

dhayfule
29th August 2007, 08:52 PM
Thanks a lot for the immediate response :)
Btw I couldnt get your name.

JUNGLEE RAJA
30th August 2007, 01:31 PM
dhyafulay Saab, thanks for the usefull information, and thanks admin for posting it


:thumbup: