4 ms·
My bank returns an icon I chose after I enter my username, I think that would have helped me recognize something was wrong.
by emondi 10y ago
My bank returns an icon I chose after I enter my username, I think that would have helped me recognize something was wrong.
- elsombrero 10y agoHijacking dns means that when you connected to the bank's website you would connect to their servers first and then they could have just proxied your connection to the real servers, that image->username check wouldn't have saved you from it since the bank's servers still operated normally
- tyingq 10y agoNginx, in proxy mode, even has a nice sub_filter where you can rewrite the response body. Pick a tag that generally occurs once, like </head>, and replace it with arbitary text. Like maybe "</head><script src="whatever"></script>". That would be perfect...no need to recreate the target site's look and feel. Just whatever js you need to scrape the credentials.
- gcb0 10y agoand now the bank just have to block Google's cloud ip range.
- tyingq 10y agoThe idea is the bank may not notice, since the site would be functional and serving customers. Certainly, there's ways to see this is going on, but you could, for example, round robin the DNS and only attack a percentage of traffic.
- bhtp 10y agoAlthough, if the bank realized what was happening, they could shutdown their servers immediately instead of needing to regain control of their DNS.
- pfg 10y agoThe bank's servers were unlikely to be involved at all. If the compromise happened at the registrar level - as the article indicates - the attackers could use their own DNS and web servers.