Bitcoin Forum
November 11, 2024, 09:35:01 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: « 1 [2]  All
  Print  
Author Topic: Half of all Phishing Sites Now Have the Padlock Sign  (Read 653 times)
UserU
Hero Member
*****
Online Online

Activity: 2212
Merit: 537


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
February 09, 2019, 10:47:38 AM
 #21

Now that's scary, since I usually eye for the padlocks. But just to pay several bucks extra doesn't cost much when the returns are greater since more people tend to fall for them.

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
Juggy777
Hero Member
*****
Offline Offline

Activity: 2646
Merit: 686


View Profile
February 09, 2019, 01:41:49 PM
 #22

Now that's scary, since I usually eye for the padlocks. But just to pay several bucks extra doesn't cost much when the returns are greater since more people tend to fall for them.


I have never really given much weightage for that padlock sign, as any site can get it via a free ssl. I have made it a habit to either bookmark my regular sites, or type their entire name.com till I find the legitimate one. I also would advise people whenever you visit a new site you’re not sure off, use a dummy email, and a 16 digit password like i do let them go nuts cracking that.
khaled0111
Legendary
*
Offline Offline

Activity: 2702
Merit: 3045


Top Crypto Casino


View Profile WWW
February 09, 2019, 02:11:59 PM
 #23

Scammers tends to target ignorant users.
Any regular user, who haven't good knowledge of Internet security, will consider a website with a green padlock as a legit website.
The green padlock means that the trafic between browser and server is encrypted so no third party can read/modify the data the user sends to the server.

Any phishing website can get a green padlock. SSL certificate costs few bucks.
 

UserU
Hero Member
*****
Online Online

Activity: 2212
Merit: 537


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
February 09, 2019, 03:28:28 PM
 #24


I have never really given much weightage for that padlock sign, as any site can get it via a free ssl. I have made it a habit to either bookmark my regular sites, or type their entire name.com till I find the legitimate one. I also would advise people whenever you visit a new site you’re not sure off, use a dummy email, and a 16 digit password like i do let them go nuts cracking that.

But if they decide not to encrypt the passwords, does the HTTPS do anything? They can be stored in plaintext, right?

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
khaled0111
Legendary
*
Offline Offline

Activity: 2702
Merit: 3045


Top Crypto Casino


View Profile WWW
February 10, 2019, 10:15:20 PM
 #25

But if they decide not to encrypt the passwords, does the HTTPS do anything? They can be stored in plaintext, right?
If they are running a phishing website then they have no interest in encrypting password. Besides, there is no way the user may know whether the password was encrypted or not.
HTTPS only encrypts data before it reaches the server.
When you type your password, basically, your browser will use the certificate it received from the website to encrypt the password and sends it. When it reaches the server, it will be decrypted and the website owner can see it as you typed it.

Erickan
Member
**
Offline Offline

Activity: 266
Merit: 18


View Profile
February 11, 2019, 02:50:50 AM
 #26

I sometimes don't a Google search to get which link to use.

Many people have a habit of searching web addresses with google, this is quite a dangerous thing, google is just a smart search engine, it cannot distinguish phishing sites. So the best way is to save the secure domain name on your search toolbar
UserU
Hero Member
*****
Online Online

Activity: 2212
Merit: 537


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
February 11, 2019, 02:56:00 AM
 #27

Many people have a habit of searching web addresses with google, this is quite a dangerous thing, google is just a smart search engine, it cannot distinguish phishing sites. So the best way is to save the secure domain name on your search toolbar

The reason why Google banned crypto ads, was because they mostly impersonated legit sites and topped them in search results.

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 7550


Playgram - The Telegram Casino


View Profile
February 11, 2019, 03:49:59 PM
 #28

The reason why Google banned crypto ads, was because they mostly impersonated legit sites and topped them in search results.
Not sure if it was mentioned before but it is sometimes very dangerous to trust the first result of a google search if it has the AD logo. Take a look at a random picture I found with the logo.




In the past, I've seen phishing sites of crypto exchanges being advertised this way that would be placed on top following a google search and below it came the official - legitimate site.   

▄▄███████▄▄███████
▄███████████████▄▄▄▄▄
▄████████████████████▀░
▄█████████████████████▄░
▄█████████▀▀████████████▄
██████████████▀▀█████████
████████████████████████
██████████████▄▄█████████
▀█████████▄▄████████████▀
▀█████████████████████▀░
▀████████████████████▄░
▀███████████████▀▀▀▀▀
▀▀███████▀▀███████

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 
Playgram.io
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▄▄▄░░
▀▄







▄▀
▀▀▀░░
▄▄▄███████▄▄▄
▄▄███████████████▄▄
▄███████████████████▄
▄██████████████▀▀█████▄
▄██████████▀▀█████▐████▄
██████▀▀████▄▄▀▀█████████
████▄▄███▄██▀█████▐██████
█████████▀██████████████
▀███████▌▐██████▐██████▀
▀███████▄▄███▄████████▀
▀███████████████████▀
▀▀███████████████▀▀
▀▀▀███████▀▀▀
██████▄▄███████▄▄████████
███▄███████████████▄░░▀█▀
███████████░█████████░░
░█████▀██▄▄░▄▄██▀█████░
█████▄░▄███▄███▄░▄█████
███████████████████████
███████████████████████
██░▄▄▄░██░▄▄▄░██░▄▄▄░██
██░░░░██░░░░██░░░░████
██░░░░██░░░░██░░░░████
██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████
███████████████████████
███████████████████████
 
PLAY NOW

on Telegram
[/
UserU
Hero Member
*****
Online Online

Activity: 2212
Merit: 537


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
February 12, 2019, 01:29:55 AM
Last edit: February 12, 2019, 02:46:34 AM by UserU
 #29

Not sure if it was mentioned before but it is sometimes very dangerous to trust the first result of a google search if it has the AD logo. Take a look at a random picture I found with the logo.




In the past, I've seen phishing sites of crypto exchanges being advertised this way that would be placed on top following a google search and below it came the official - legitimate site.  


Exactly, that's why Google Ads came down hard on such ads after that.

Last time I accidentally accessed a phishing link when I searched for an exchange name on Google. The same ad spot on the first page.

.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
leowonderful
Legendary
*
Offline Offline

Activity: 1624
Merit: 1130


Bitcoin FTW!


View Profile
February 12, 2019, 01:34:23 AM
 #30

I recall there used to be numerous fake Blockchain wallet sites that were advertised via the Google ads and many people used to fall for such sites as the scam site came up first before the actual Blockchain site. Google's indeed banned crypto ads so such phishing sites should no longer be a problem, but it's always a good idea to check the certificate of any site you go on before inputting any actual user information so you're sure that you are using the right site. A few exchanges and other sites even tell you to do this before logging in.
masulum
Legendary
*
Offline Offline

Activity: 2324
Merit: 1604

hmph..


View Profile WWW
October 24, 2019, 12:58:24 AM
Merited by Pmalek (1), wwzsocki (1), DdmrDdmr (1), Bttzed03 (1)
 #31

I want to create a new topic about phishing under HTTPS websites, But, because I found this thread, maybe better if I make a post reply to this thread. Sorry for bumping threads.


Phishing attempts increase 400%, many malicious URLs found on trusted domains

Secure Socket Layer (SSL) is considered as a secure, means to secure user data on a website. However, a hacker is not a beginner, they are always looking for ways to get victims. If a website that uses SSL (HTTPS://) used to be considered secure if accessing it from all devices, now that can't be said to be 100% correct.

Let's look at the data in the article published by helpnetsecurity.com (the reference is at the end of the post), the article data shown:
  • Nearly 24% of malicious programs are found on trusted websites.
  • Nearly 29% of phishing websites use HTTPS to deceive victims.

This is an irony for those of us who often use websites. Especially for novice investors or airdrop / bounty hunters. If we don't pay attention to the URL we open, we can become victims of this cyber crime.

Let's look at the thread created by wwzsocki entitled "What is Punycode and how to protect yourself from Homograph Phishing attacks?". In that thread, there is an example of a phishing website which is a Binance duplication. The website was created using HTTPS on the domain to convince its victims and also trick users by using a similar alphabet.

Another example, from dkbit98, he found a Chainlink duplication website that also uses HTTPS on the domain to convince its users. Despite the fact that the website is a phishing website that utilizes user typo.

Back to the article, the article mentioned that in 2019, phishing websites had increased by 400%. The terrible thing is, the growth of phishing takes place only in 7 months from January - July 2019. The sectors that are targeted for phishing are:
  • 25% are SaaS / Webmail providers
  • 19% are financial institutions
  • 16% social media
  • 14% retail
  • 11% file hosting
  • 8% payment services companies

If you are still using Windows 7 on your computer OS.
  • Between January and June, the number of IPs that host Windows exploits grew 75%
  • Malware samples seen on only one PC are at 95.2%, up from 91.9% in 2018
  • Out of all infected PCs, 64% were home user machines, and 36% were business devices, likely because home users aren’t protected by corporate firewalls and security policies and may not be updated as regularly.
  • Over 75% of malware on Windows system hides in one of three places:
    41% in %temp%, 24% in %appdata% and 11% in %cache%.
  • Businesses can easily set policies to restrict execution of any application from the %temp% and %cache% locations, preventing more than 50% of infections.



Quote

HOLD...
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 7550


Playgram - The Telegram Casino


View Profile
December 19, 2019, 10:20:35 AM
 #32

bumping

▄▄███████▄▄███████
▄███████████████▄▄▄▄▄
▄████████████████████▀░
▄█████████████████████▄░
▄█████████▀▀████████████▄
██████████████▀▀█████████
████████████████████████
██████████████▄▄█████████
▀█████████▄▄████████████▀
▀█████████████████████▀░
▀████████████████████▄░
▀███████████████▀▀▀▀▀
▀▀███████▀▀███████

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 
Playgram.io
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▄▄▄░░
▀▄







▄▀
▀▀▀░░
▄▄▄███████▄▄▄
▄▄███████████████▄▄
▄███████████████████▄
▄██████████████▀▀█████▄
▄██████████▀▀█████▐████▄
██████▀▀████▄▄▀▀█████████
████▄▄███▄██▀█████▐██████
█████████▀██████████████
▀███████▌▐██████▐██████▀
▀███████▄▄███▄████████▀
▀███████████████████▀
▀▀███████████████▀▀
▀▀▀███████▀▀▀
██████▄▄███████▄▄████████
███▄███████████████▄░░▀█▀
███████████░█████████░░
░█████▀██▄▄░▄▄██▀█████░
█████▄░▄███▄███▄░▄█████
███████████████████████
███████████████████████
██░▄▄▄░██░▄▄▄░██░▄▄▄░██
██░░░░██░░░░██░░░░████
██░░░░██░░░░██░░░░████
██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████
███████████████████████
███████████████████████
 
PLAY NOW

on Telegram
[/
gabrielkrieger
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile WWW
December 19, 2019, 10:24:55 AM
 #33

Time to get rid of this padlock sign once and for all. Just display an explicit warning to the user when SSL is not used...
DdmrDdmr
Legendary
*
Offline Offline

Activity: 2492
Merit: 11049


There are lies, damned lies and statistics. MTwain


View Profile WWW
December 19, 2019, 10:45:45 AM
 #34

PhishLabs, the data source behind the link in the OP,  has an update report, and now places the mark at 68% for phishing sites using SSL (see https://info.phishlabs.com/blog/apwg-two-thirds-phishing-sites-ssl-https). Although their data for some Quarters decreases in percentage, it’s fair to assume that SSL certificates is a non-trustworthy indicator on its own, and that the assumption needs to clearly be demystified.
UserU
Hero Member
*****
Online Online

Activity: 2212
Merit: 537


FREE passive income eBook @ tinyurl.com/PIA10


View Profile WWW
December 19, 2019, 10:55:20 AM
 #35

Time to get rid of this padlock sign once and for all. Just display an explicit warning to the user when SSL is not used...

Most browsers have already displayed such warnings when accessing an insecure site.


.
.500 CASINO.██

  ▄

.
THE HOTTEST CRYPTO
CASINO & SPORTSBOOK
         ▄▄▄███████████
 ▄▄▄████████████████

▐████████████████████
 ██████████████████
 ▐██████████████████
 ▐█████████████████
  ██████████████████
  ██████▀█████▀█████
  ▐████████████████
  ▐██████████████
   █████████████████
   ▐██████████████████
    ▀██████▀▀▀▀▀▀   ▀▀▀█

▄▄▄██████████▄▄▄
████████▀██▀▀██▄▄
 █
█████████████████▄
 █
████████████████████
  █
██▄████▄███████▄███
  █
████████████████████
  █
███▀████▀███████▀███
 █
████████████████████
 █
█████████████████▀
█████████▄██▄▄██▀▀
 ▀▀▀██████████▀▀▀

ORIGINALS

SLOTS

LIVE GAMES

SPORTSBOOK



.
██..PLAY NOW..
gabrielkrieger
Newbie
*
Offline Offline

Activity: 3
Merit: 0


View Profile WWW
December 24, 2019, 02:13:34 PM
 #36


Most browsers have already displayed such warnings when accessing an insecure site.

https://i.ibb.co/wN8J1BK/non.jpg

It's not so much that it's an insecure site on itself, rather the TCP connection between you and the site is not encrypted, which is bad for security.
Pmalek (OP)
Legendary
*
Offline Offline

Activity: 2940
Merit: 7550


Playgram - The Telegram Casino


View Profile
December 25, 2019, 09:04:36 AM
 #37

TCP connection between you and the site is not encrypted, which is bad for security.
Exactly. Anyone sniffing around can intercept the data you are sending over insecure networks. That doesn't mean that HTTP can't or shouldn't be used at all. It just shouldn't be used in connection with private data, passwords, logins, pins etc.

▄▄███████▄▄███████
▄███████████████▄▄▄▄▄
▄████████████████████▀░
▄█████████████████████▄░
▄█████████▀▀████████████▄
██████████████▀▀█████████
████████████████████████
██████████████▄▄█████████
▀█████████▄▄████████████▀
▀█████████████████████▀░
▀████████████████████▄░
▀███████████████▀▀▀▀▀
▀▀███████▀▀███████

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 
Playgram.io
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▄▄▄░░
▀▄







▄▀
▀▀▀░░
▄▄▄███████▄▄▄
▄▄███████████████▄▄
▄███████████████████▄
▄██████████████▀▀█████▄
▄██████████▀▀█████▐████▄
██████▀▀████▄▄▀▀█████████
████▄▄███▄██▀█████▐██████
█████████▀██████████████
▀███████▌▐██████▐██████▀
▀███████▄▄███▄████████▀
▀███████████████████▀
▀▀███████████████▀▀
▀▀▀███████▀▀▀
██████▄▄███████▄▄████████
███▄███████████████▄░░▀█▀
███████████░█████████░░
░█████▀██▄▄░▄▄██▀█████░
█████▄░▄███▄███▄░▄█████
███████████████████████
███████████████████████
██░▄▄▄░██░▄▄▄░██░▄▄▄░██
██░░░░██░░░░██░░░░████
██░░░░██░░░░██░░░░████
██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████
███████████████████████
███████████████████████
 
PLAY NOW

on Telegram
[/
robelneo
Legendary
*
Offline Offline

Activity: 3416
Merit: 1226



View Profile WWW
December 25, 2019, 02:59:47 PM
 #38

So many or almost all of these HYIP's are hosted in a secured SSL, because any website operator can buy a comodo to encrypt it and makes the site legit, but it doesn't guaranty the site is legit, it's not even a factor I looked when looking in a project, the plan, the people behind it are some of the things that you need to look but never the site's encryption.

..cryptomus..   
  
.
lllllllllllllllllll CRYPTO
PAYMENT GATEWAY
▄█▀▀██▄░░░▄█████▄░░░▄▀████▄
██░▀▄██░░░██▄░▄██░░░██▄▀▀▀█
██░▀▄██░░░███▄███░░░███░░▄█
▀▀▀▀▀░░░░░▀▀▀▀▀░░░░░▀▀▀▀▀
▄▄▄▄▄░░░░░▄▄▄▄▄░░░░░▄▄▄▄▄
███▀▄██░░░██▀░▀██░░░██▀▀▀▀█
██▀▄███░░░██░░░██░░░█▄███░█
▀█▄▄▄█▀░░░▀██▄██▀░░░▀█▄▄▄█▀

▄█████▄░░░▄█▀▀██▄░░░▄█████▄
█▀░█░▀█░░░█░▀░▀▀█░░░██▄░▄██
█▄█▄█▄█░░░███░▀▄█░░░███▄███
▀▀▀▀▀░░░░░▀▀▀▀▀░░░░░▀▀▀▀▀
ACCEPT
CRYPTO
PAYMENTS
..GET STARTED..
Pages: « 1 [2]  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!