TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Advice wanted – Stumbled across active phishing scam

5 pointsby zefmanalmost 8 years ago
So yesterday I received a suspicious sms message with standard phishing speil asking to follow a link and renew a subscription to well known app.<p>Out of interest I followed the link to see how the attack would work, and before I knew it I had discovered that the attacker had left directory listings enabled on their server!<p>After looking through the PHP used to perform the scam, I could see that the results of the form victims are asked to fill out were being emailed to the attacker, and logged into a text file on the server. I just want to stress this is all publicly available if you know the url, not behind any kind of authentication.<p>After looking at the log file I could see that this scam was very and active and very effective. New entries were being added throughout the day including credit card and bank information. At this point I realised it was probably time to inform the police, and after many many painful hours I finally had a report logged.<p>Its now been 24 hours and I can still see the scam is active and collecting real peoples&#x27; details, the majority of whom are elderly.<p>What should I do? It feels wrong just to sit here and watch these people lose their details while the UK police take their time figuring out what a zipfile is. It would be very easy to disrupt the scam by flooding it with fake data. Good or bad idea?

4 comments

tdeckalmost 8 years ago
Much of this sounds like a standard phish kit. Unfortunately I don&#x27;t think the police can do much. Often you can actually find the perpetrator&#x27;s info, but they&#x27;re in Nigeria where nobody cares.<p>First of all, I&#x27;d report the site to Google Safe Browsing and to PhishTank: <a href="https:&#x2F;&#x2F;safebrowsing.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;?hl=en" rel="nofollow">https:&#x2F;&#x2F;safebrowsing.google.com&#x2F;safebrowsing&#x2F;report_phish&#x2F;?h...</a> <a href="https:&#x2F;&#x2F;www.phishtank.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.phishtank.com&#x2F;</a><p>Once Chrome starts blocking the site, that will stop the bleeding. The contact the host and domain registrar, if possible. If the phish kit is piggybacking on a WordPress site (very common), find the person who owns that site and message them if you can.
评论 #14802693 未加载
nirmalkantalmost 8 years ago
Its a hazardous menace affecting almost all Internet powerful nations of the world. If you are attacked, probably you won&#x27;t be able to do much now and just wait for them to do something for you. I think the cyber cell will take care, it takes time but you&#x27;ll get solution lately. From next time the first and the foremost you should do is to steer clear of spams and e-mails which are from suspicious senders. Read about the Cyber Plague..<a href="http:&#x2F;&#x2F;gotowebsecurity.com&#x2F;cyber-phishing-attack&#x2F;" rel="nofollow">http:&#x2F;&#x2F;gotowebsecurity.com&#x2F;cyber-phishing-attack&#x2F;</a>
detaroalmost 8 years ago
You could try contact their hosting provider? (assuming it is a somewhat legitimate one)
评论 #14799147 未加载
wazanatoralmost 8 years ago
Is there a way you can anonymously alert people who have been scammed?
评论 #14800069 未加载