Here's another reason to avoid proxy servers as McAfee SiteAdvisor has been popping up warnings about potential phishing via these seemingly "harmless" proxy sites.
Maybe phishing is one of the real reasons behind the sudden proliferation of new proxy sites and not just so kids and workers can bypass internet security.
Maybe the real purpose of many of the sites popping up every few minutes is to lure unsuspecting victims into using their passwords and other personal information and collecting them for nefarious purposes.
It's also another possible reason that the proxy hacking/hijacking is being done as a means to purposely direct people to sites they may be members of, by hijacking the page in Google as a means to get you to login via their servers.
Some of the newer proxy sites I've seen attempting to hijack some of my pages lately have a very low profile, such as "http://000a.com/www.mysite.com" and don't even frame the page to give you any indication that you're even using a proxy other than the URL.
Everything is starting to add up to a very serious threat for novice internet users that can't tell they're even being spoofed.
I didn't like proxy sites before and now I think they should just be abolished because the risks are too high for site owners and visitors alike.
When it comes to proxy sites just play it safe and avoid them at all cost.
Thursday, August 23, 2007
Proxy Phishing Warning - Avoid Proxies!
Posted by
IncrediBILL
at
8/23/2007 03:33:00 PM
6
comments
Labels: Phishing
Sunday, November 26, 2006
Anti-Phish Shootout: Firefox 2 vs. MSIE 7
Another phishing email arrived today so I tried it in both Firefox 2 and MSIE 7 as fast as I could get the link pasted into the browsers.
The resulting screenshots below and the score is:
FIREFOX: 1
INTERNET EXPLORER: 0
Posted by
IncrediBILL
at
11/26/2006 01:46:00 PM
5
comments
Labels: Phishing
Saturday, November 18, 2006
Google's Anti-Phish ROCKS!
After reading all of the whiners and complainers going on and on about how anti-phish in browsers was going to give people a false sense of security I decided to put it to the test today when a phishing email landed in my Inbox.
Within minutes of the arrival of the phishing email, I enabled the Google anti-phish in FireFox 2.0 and went to the site linked in the email:http://g-lec.com/data/cont/news/sicherung/einfach_millionaer1/wells/
The very minute the screen loaded Google popped up an alert:
Here's the page without the Google alert covering it:
I'll try the anti-phish a few more times as the opportunity arises, but this first test was impressive. As soon as I get around to installing IE 7 then I'll test their anti-phish as well.
Way to go Google!
You get a nice well deserved pat on the back for this one!
Posted by
IncrediBILL
at
11/18/2006 04:56:00 PM
3
comments
Labels: Phishing
Monday, August 28, 2006
Google Utilized in Phishing Exploits
Maybe the title is a little bit of link bait but it's also accurate as I received a WellsFargo phishing email today with a redirect link through Google.
Some of you may remember how I've complained a time or two about being abused via various Google proxy servers and sure enough they have something else that's vulnerable to being used by abusers.
The link to the phishing site used Google to redirect victims:
http://www.google.com/url?sa=t&ct=res&cd=7How's that for Google's war on anti-phishing?
&url=http%3Awebtracpro.valleyvistamortgage.com/wellsfargo/Update.html
Yes, I know that's a cheap shot but they really need to fix some vulnerabilities over there and maybe after enough cheap shots someone will pay attention, who knows.
Onward with our phishing expedition!
Here's a screenshot of the email sent by the Wells Fargo "Safehaebor Department" which is amusing that they didn't even bother spell checking their phish but most people are illiterate and wouldn't notice such details.


And the form sends the data to some place in The Czech Republic:
http://mailform.cz/The only amazing part is that I notified the people with the compromised server a couple of hours ago and the phish site is still live as I write this, supposedly after their IT dept. was going to handle it ASAP.
So there you have it, another exciting episode of Gone Phishing.
Until next time...
Posted by
IncrediBILL
at
8/28/2006 09:49:00 AM
3
comments
Labels: Phishing
Friday, June 02, 2006
Locating and Blocking Proxy Servers
Since some of my readers want to know how I'm doing it, here's a few tips on how you too can eliminate the anonymous proxies from your site. Probably won't get them all and you might get a few false positives as well but it's better to have some defense against this menace than none at all.
A large number of these proxy servers are on .EDU domains because of all the bleeding heart crap about making information free for all without censorship and being able to surf without fear of retribution. That's a very noble and altruistic motive but you open the doors for competitve spying, scrapers, phishing theives and a lot more so don't take this the wrong way when I don't appreciate what you're doing with our tax and college dollars and send out a big "FUCK YOU" to establishments of higher learning that permit this bullshit. If people in other countries don't like being censored, let them overthrow their fucking government, it's not our problem and my server and copyrighted content shouldn't be vulnerable to attack because of the gaping holes opened up by your bleeding heart asses, but I'm off on a tangent.
The other groups of asshole proxies are the many web-based CGI and PHP proxy servers (like eatmoreblueberries) being used to bypass restricted internet access imposed on corporate, library and school networks. Well I'm sorry but you're supposed to be WORKING or STUDYING so let me give you a big "FUCK YOU" as well. Not only do they download your pages, they strip out YOUR ads and insert their OWN ads, assholes. So for all you slackers using those proxies, zip it up, close the porn sites, go back to work, and get a life you little fuckers as MySpace isn't it.
So, with a bit of ranting aside, back to blocking proxies...
New proxy servers pop up every 5 seconds so my method requires multiple techniques:
- Import lists of known proxies and block them
- Look for proxy environment variables
- Test the IP for typical proxy ports and see if it works
- Check for a port number being appended to your domain done by lame proxies
- Monitor for proxy crawl thru of known services
This step is pretty obvious and can be automated by downloading the lists from a few well known proxy list sites, or if you're lazy you can subscribe to a service or two already doing that.
Probably doesn't hurt to validate these proxies, which can be done automatically, otherwise your list will grow infinitely as they appear and disappear very quicky
2. Proxy Environment Variables
You can check for the following:
HTTP_VIA
HTTP_X_FORWARDED_FOR
HTTP_PROXY_CONNECTION
Yes, those will tell you a proxy made the request but remember that AOL and many others are also a proxy so then it becomes more complicated as you have to evolve a list of known good proxies vs. all the rest and do further processing on those you don't know.
FYI, the really good anonymous proxies don't send that information so you'll never know it's a proxy.
3. Test for Proxy Ports
It will look simple but it's way more complicated to get right.
in PHP you can check to see if you can open port 80 on the incoming IP to see if it's an open proxy like this:
$fp = @fsockopen($theIP, 80, $errno, $errstr, 5);
if ($fp) {
// OPEN PORT
}
But that's very simplistic as most don't use :80, they use port :8080 and other weird #s like :3128, to avoid what the admins are currently blocking.
Not to mention, some proxies are very slow so you want to do exhaustive testing on post-page processing so you don't slow down the user experience on the front end of the page. You only have to do this once per IP, but someone could think your website is down if the process takes to long and worse case you get a positive answer that it's a proxy they've only accessed one page and you block the next page.
Once you detect the proxy add it to your proxy lists built in step 1 above and you'll never have to worry about this one again.
Remember, you may end up blocking IPs from colleges and universities but remember our alma mater, good old FU.
4. Port Numbers Appended to Domain
The dumbest of the dumb append a port number to your domain name which is easy to test in the HTTP_HOST variable. The only exceptions I've have to make to this rule so far is for the poor dumb bastards still using prodigy.net.mx which astonished me that prodigy still existed even as a name on a block of IPs!
5. Proxy Crawl Thru
What some of these dumb fuck proxy operators do is set up a cloaked directory, probably a clone of DMOZ or some shit, and cloak this directory to the search engines.
When you see things like Googlebot, Mediabot, Msnbot, etc. hitting your servers outside of their known range of IP's it means only 1 of 2 possibilities.
- Someone is trying to spoof the user agent to get onto your server
- The crawler is coming thru a proxy port
BTW, before serving up an error message, it's wise to do a reverse DNS lookup to make sure that Googlebot really isn't on a new block of IP's owned by google.com.
Summary
Probably not as simple as you had hoped but a couple of techniques are very straight forward and stop some level of the proxy nonsense without fear of blocking innocents.
Good luck trying this and may all your proxy requests bounce off your server like a rock skipping across a pond.
Posted by
IncrediBILL
at
6/02/2006 11:58:00 AM
2
comments
Labels: Phishing, Proxy Hijacking




