3 ms·
It was probably a compromised site. Spinning up your own domain/vps has the drawback of it being a new site not trusted or classified by most corporate firewall
by badrabbit 6y ago
It was probably a compromised site. Spinning up your own domain/vps has the drawback of it being a new site not trusted or classified by most corporate firewalls and proxies (if setup right).
You'd be surprised how easy it is to scan+pwn some wordpress site left in default config or vulnerable to the latest joomla exploit. They then upload a $20 phishing kit and start spamming. If you look at the directories' root in the path you sometimes get lucky enough to get the zip/tar file they forgot to remove (includes their email, to which stolen creds are sent, you probably spammed the crap out of their mailbox too). A few times I've even found unsecured webshells they left behind (just booted them out, got emails of people who fell for it and did the standard rfc-whatever notification)
One thing I wanted to try was to include tracker URLs when stuffing them with fake usernames like 'bob@bob.com https://bobscompany.com/login.php?trackerid=1345556' https://bobscompany.com/login.php?trackerid=1345556' or make it a 1x1 pixel image link so when they see the fake creds I will know their IP