Phishing Kits Now Act as MITM
Thanks to Mark for sending this over, but there is a new phishing kit that acts as a man in the middle. According to the article the phishing kit simply acts as a PHP proxy to forward any requests directly through the proxy. That way it can detect anything you are typing or defeat any systems like sitekey that require that you see the image in question.
I can’t exactly say this is a major leap forward, because I’ve seen phishing sites that have similar levels of sophistication in automatic detection of whether the username/password was correct by checking in real time. However, this does represent a new variant that could render a lot of the more snake oil security products virtually useless. The one major disadvantage with this system is that it has to reside on a host and if the same IP is used over and over and over, that could set off a lot of alarms. Interesting nonetheless.



January 12th, 2007 at 12:58 pm
To make it less suspicious the proxy could just run all traffic through Tor…
January 15th, 2007 at 8:41 am
Could someone include a screenshot of this? I can’t find it and I’d like to know what it looks like.
~Thx.
January 19th, 2007 at 5:36 pm
more info: http://www.pcworld.com/article/id,128524-c,cybercrime/article.html