TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Obfuscated JavaScript, scam emails, and American Express

102 pointsby jonlucaover 6 years ago

6 comments

porluneover 6 years ago
I wonder if scammers are intentionally misspelling subject lines because most security savvy people will just delete those as obvious scams and move on. This would have a two pronged effect:<p>1. it would filter out security savvy individuals from the actual payload, who might report the scam.<p>2. it would map to the least security conscious individuals who would be the most likely to fall for it.
评论 #19072795 未加载
userbinatorover 6 years ago
The next logical step after finding where the data is sent, is to use a script to fill the phisher&#x27;s database with rubbish... there are sites like <a href="https:&#x2F;&#x2F;www.fakenamegenerator.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.fakenamegenerator.com&#x2F;</a> which will help you create fake-yet-plausible identities.<p>I remember many years ago I was sent a keylogger. I reversed it, found it was configured to upload keylogs to an FTP server on a free webhost, and promptly replaced the existing contents of it with as many copies of The Bible as would fit in the few MB of space available.
mindfulplayover 6 years ago
Is it ethical or possible to attack the attacker by spawning a few cloud instances that POST dummy but nearly legit responses to their website? This way they would have to comb through and hopefully verify a lot of crap to find victims&#x27; card numbers?<p>Unless of course they were clever enough to embed some fake cookie to track responses to specific emails...
chinhodadoover 6 years ago
So in the end, what does the obfuscated JS do?
评论 #19072976 未加载
评论 #19072993 未加载
benj111over 6 years ago
And yet, if you turn off JavaScript to protect against this type of thing, you end up breaking most financial websites.<p>(American Express is in fairness the one site that continued working ok as I recall)
me45555over 6 years ago
Very interesting, thanks for the post