Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #243294 > unrolled thread
| Started by | rhkramer@gmail.com |
|---|---|
| First post | 2021-12-20 16:40 +0100 |
| Last post | 2021-12-21 18:40 +0100 |
| Articles | 20 on this page of 41 — 22 participants |
Back to article view | Back to linux.debian.user
Identity Theft rhkramer@gmail.com - 2021-12-20 16:40 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 17:00 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 17:20 +0100
Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 19:10 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 19:40 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 19:50 +0100
Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 20:00 +0100
Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 20:10 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:00 +0100
Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-21 06:00 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 17:00 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:50 +0100
Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 19:50 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 20:10 +0100
Re: Identity Theft Brian <ad44@cityscape.co.uk> - 2021-12-20 20:30 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:10 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
Re: Identity Theft local10 <local10@tutanota.com> - 2021-12-21 09:20 +0100
Re: Identity Theft Kenneth Parker <sea7kenp@gmail.com> - 2021-12-21 13:50 +0100
Re: Identity Theft Eike Lantzsch ZP6CGE <zp6cge@gmx.net> - 2021-12-21 14:30 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 15:20 +0100
Re: Identity Theft Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-12-21 16:30 +0100
Re: Identity Theft Dan Ritter <dsr@randomstring.org> - 2021-12-21 16:40 +0100
Re: Identity Theft The Wanderer <wanderer@fastmail.fm> - 2021-12-21 16:40 +0100
Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 19:20 +0100
Re: Identity Theft Celejar <celejar@gmail.com> - 2021-12-21 22:40 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
Re: Identity Theft Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 18:10 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-26 14:40 +0100
Re: Identity Theft Hans <hans.ullrich@loop.de> - 2021-12-27 20:10 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
Re: vulnerability classifications (was: Re: Identity Theft) Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:50 +0100
Re: Identity Theft Richmond <richmond@criptext.com> - 2021-12-21 16:50 +0100
Re: Identity Theft harryweaver@tutanota.com - 2021-12-21 21:20 +0100
Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 23:30 +0100
Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 23:50 +0100
Re: Identity Theft Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-12-22 00:40 +0100
Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-22 16:00 +0100
Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
| From | "tv.debian@googlemail.com" <tv.debian@googlemail.com> |
|---|---|
| Date | 2021-12-21 14:40 +0100 |
| Message-ID | <DwNwZ-eW-1@gated-at.bofh.it> |
| In reply to | #243321 |
Le 21/12/2021 à 14:24, Eike Lantzsch ZP6CGE a écrit : > On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote: >> On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote: >>> Dec 21, 2021, 02:13 by jeremy@ardley.org: >>>> You can mitigate XSS by having a single browser that is used >>>> solely to> >>> access high value sites. e.g. if you routinely run Firefox, have a >>> copy of Vivaldi that you use to access your banks - one at a time. >>> >>> >>> >>> Installing NoScript also may help as it has an option to sanitize >>> cross-site suspicious requests. NoScript also speeds up the browser >>> by disabling all the tracking and spying scripts many sites load >>> nowadays. Just make sure to disable all the garbage it has enabled >>> by default after the installation. >> >> +1 on NoScript. I particularly like the White List capabilities, >> where you can allow Scripts by Website, and even only one time. I >> only know it to work with Firefox, at this time. >> >> Kenneth Parker > > Is this > > *No-Script Suite Lite by AdblockLite[1]* > (this one has a whitelist feature) or > *NoScript Security Suite by Giorgio Maone[2]* > (has a whitelist feature too) or other? > > I'm using Privicy Badger among other means > like limiting and redirecting DNS requests. But that does not avoid JS. > > Cheers > Eike > > -------- > [1] https://addons.mozilla.org/en-US/firefox/user/11285580/ > [2] https://addons.mozilla.org/en-US/firefox/user/143/ > It is the second one, "Noscript" in one word [1]. Several look-alike have spawn over the years. I also use Umatrix [2], but it is more complex. For Firefox: [1] https://addons.mozilla.org/fr/firefox/addon/noscript/ [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/ At least one of those is packaged in Debian.
[toc] | [prev] | [next] | [standalone]
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Date | 2021-12-21 15:20 +0100 |
| Message-ID | <DwO9H-GY-3@gated-at.bofh.it> |
| In reply to | #243322 |
On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote: > Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?: > It is the second one, "Noscript" in one word [1]. Several look-alike have > spawn over the years. I also use Umatrix [2], but it is more complex. > > For Firefox: > [1] https://addons.mozilla.org/fr/firefox/addon/noscript/ > [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/ > > At least one of those is packaged in Debian. > Will umatrix still work in firefox 91? Certainly didn't work for me in android v92.
[toc] | [prev] | [next] | [standalone]
| From | Markus Schönhaber <debian-user@list-post.mks-mail.de> |
|---|---|
| Date | 2021-12-21 16:30 +0100 |
| Message-ID | <DwPfs-1i5-3@gated-at.bofh.it> |
| In reply to | #243325 |
21.12.21, 15:10 +0100, Tim Woodall: > Will umatrix still work in firefox 91? Yes. -- Regards mks
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2021-12-21 16:40 +0100 |
| Message-ID | <DwPp8-1l3-7@gated-at.bofh.it> |
| In reply to | #243325 |
Tim Woodall wrote: > On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote: > > > Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?: > > It is the second one, "Noscript" in one word [1]. Several look-alike > > have spawn over the years. I also use Umatrix [2], but it is more > > complex. > > > > For Firefox: > > [1] https://addons.mozilla.org/fr/firefox/addon/noscript/ > > [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/ > > > > At least one of those is packaged in Debian. > > > > Will umatrix still work in firefox 91? > > Certainly didn't work for me in android v92. Yes, it does. Android's Firefox is a completely different codebase, and there is support for only a small number of addons there. That said, the primary developer of uMatrix has stopped working on it, and recommends that people switch to uBlock Origin instead. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | The Wanderer <wanderer@fastmail.fm> |
|---|---|
| Date | 2021-12-21 16:40 +0100 |
| Message-ID | <DwPp7-1l3-5@gated-at.bofh.it> |
| In reply to | #243325 |
[Multipart message — attachments visible in raw view] — view raw
On 2021-12-21 at 09:10, Tim Woodall wrote: > On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote: > >> Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?: >> >> It is the second one, "Noscript" in one word [1]. Several >> look-alike have spawn over the years. I also use Umatrix [2], but >> it is more complex. >> >> For Firefox: >> [1] https://addons.mozilla.org/fr/firefox/addon/noscript/ >> [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/ >> >> At least one of those is packaged in Debian. > > Will umatrix still work in firefox 91? > > Certainly didn't work for me in android v92. Is uMatrix on the whitelist of extensions that are allowed on the mobile version of Firefox? Some good number of releases ago, Mozilla completely redid the mobile version of Firefox, and in the process dropped support for most of the extension base - as in, they restricted the allowed extensions to only those in a defined list, and started that list out with a grand total of *nine* items. (See [1] for some at-the-time commentary on this.) I understand that in the time since then they've gradually expanded the list of allowed extensions, but at nothing like a rapid pace, and with no sign that they even intend to ever let the broad scope of extensions be installable (much less usable) for mobile-device Firefox again. It's always possible that uMatrix is one of the whitelisted extensions, but I wouldn't be even slightly surprised if it weren't. [1] https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/ -- The Wanderer The reasonable man adapts himself to the world; the unreasonable one persists in trying to adapt the world to himself. Therefore all progress depends on the unreasonable man. -- George Bernard Shaw
[toc] | [prev] | [next] | [standalone]
| From | Tim Woodall <debianuser@woodall.me.uk> |
|---|---|
| Date | 2021-12-21 19:20 +0100 |
| Message-ID | <DwRTY-32z-5@gated-at.bofh.it> |
| In reply to | #243329 |
On Tue, 21 Dec 2021, The Wanderer wrote: > On 2021-12-21 at 09:10, Tim Woodall wrote: > >> >> Will umatrix still work in firefox 91? >> >> Certainly didn't work for me in android v92. > > Is uMatrix on the whitelist of extensions that are allowed on the mobile > version of Firefox? > > Some good number of releases ago, Mozilla completely redid the mobile > version of Firefox, and in the process dropped support for most of the > extension base - as in, they restricted the allowed extensions to only > those in a defined list, and started that list out with a grand total of > *nine* items. (See [1] for some at-the-time commentary on this.) > > I understand that in the time since then they've gradually expanded the > list of allowed extensions, but at nothing like a rapid pace, and with > no sign that they even intend to ever let the broad scope of extensions > be installable (much less usable) for mobile-device Firefox again. > > It's always possible that uMatrix is one of the whitelisted extensions, > but I wouldn't be even slightly surprised if it weren't. > > [1] > https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/ > Interesting read. Thanks. I've just installed the kiwi browser which does allow extensions. I found it while googling how to install extensions on vivaldi android (which it seems you cannot)
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2021-12-21 22:40 +0100 |
| Message-ID | <DwV1v-4Pa-3@gated-at.bofh.it> |
| In reply to | #243329 |
On Tue, 21 Dec 2021 10:34:49 -0500 The Wanderer <wanderer@fastmail.fm> wrote: > On 2021-12-21 at 09:10, Tim Woodall wrote: > > > On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote: > > > >> Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?: > >> > >> It is the second one, "Noscript" in one word [1]. Several > >> look-alike have spawn over the years. I also use Umatrix [2], but > >> it is more complex. > >> > >> For Firefox: > >> [1] https://addons.mozilla.org/fr/firefox/addon/noscript/ > >> [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/ > >> > >> At least one of those is packaged in Debian. > > > > Will umatrix still work in firefox 91? > > > > Certainly didn't work for me in android v92. > > Is uMatrix on the whitelist of extensions that are allowed on the mobile > version of Firefox? > > Some good number of releases ago, Mozilla completely redid the mobile > version of Firefox, and in the process dropped support for most of the > extension base - as in, they restricted the allowed extensions to only > those in a defined list, and started that list out with a grand total of > *nine* items. (See [1] for some at-the-time commentary on this.) > > I understand that in the time since then they've gradually expanded the > list of allowed extensions, but at nothing like a rapid pace, and with > no sign that they even intend to ever let the broad scope of extensions > be installable (much less usable) for mobile-device Firefox again. > > It's always possible that uMatrix is one of the whitelisted extensions, > but I wouldn't be even slightly surprised if it weren't. > > [1] > https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/ 1) The author of uBlock and uMatrix, Raymond Hill, has abandoned the latter: https://github.com/uBlockOrigin/uMatrix-issues/issues/291#issuecomment-694988696 https://www.ghacks.net/2020/09/20/umatrix-development-has-ended/ 2) Android uBlock is indeed on the official list of Firefox Recommended Extensions: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/ https://addons.mozilla.org/en-US/firefox/collections/4757633/7dfae8669acc4312a65e8ba5553036/ Celejar
[toc] | [prev] | [next] | [standalone]
| From | "tv.debian@googlemail.com" <tv.debian@googlemail.com> |
|---|---|
| Date | 2021-12-21 14:40 +0100 |
| Message-ID | <DwNwZ-eW-3@gated-at.bofh.it> |
| In reply to | #243321 |
Le 21/12/2021 à 14:24, Eike Lantzsch ZP6CGE a écrit : > On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote: >> On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote: >>> Dec 21, 2021, 02:13 by jeremy@ardley.org: >>>> You can mitigate XSS by having a single browser that is used >>>> solely to> >>> access high value sites. e.g. if you routinely run Firefox, have a >>> copy of Vivaldi that you use to access your banks - one at a time. >>> >>> >>> >>> Installing NoScript also may help as it has an option to sanitize >>> cross-site suspicious requests. NoScript also speeds up the browser >>> by disabling all the tracking and spying scripts many sites load >>> nowadays. Just make sure to disable all the garbage it has enabled >>> by default after the installation. >> >> +1 on NoScript. I particularly like the White List capabilities, >> where you can allow Scripts by Website, and even only one time. I >> only know it to work with Firefox, at this time. >> >> Kenneth Parker > > Is this > > *No-Script Suite Lite by AdblockLite[1]* > (this one has a whitelist feature) or > *NoScript Security Suite by Giorgio Maone[2]* > (has a whitelist feature too) or other? > > I'm using Privicy Badger among other means > like limiting and redirecting DNS requests. But that does not avoid JS. > > Cheers > Eike > > -------- > [1] https://addons.mozilla.org/en-US/firefox/user/11285580/ > [2] https://addons.mozilla.org/en-US/firefox/user/143/ > To follow up on myself, shamelessly ;-) , noscript and umatrix are packaged in Debian (depending on your version), and both protect from cross site scripting. Packages are "webext-umatrix" and "webext-noscript".
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-21 18:40 +0100 |
| Message-ID | <DwRhh-2yP-33@gated-at.bofh.it> |
| In reply to | #243311 |
On Monday, December 20, 2021 09:13:07 PM Jeremy Ardley wrote: > On 21/12/21 10:09 am, Jeremy Ardley wrote:s. > > > There is a type of attack called cross-site scripting (XSS). It's > > mostly been eliminated by latest version browsers, but there are > > always zero-day vulnerabilities. > > > > The effect is that if you are vulnerable and have two tabs open, one > > to the legitimate site, and one to a bad guy site, the bad guy can > > alter your trusted site and for instance change a valid link into > > something malicious, or change a displayed phone number. > > > > More at https://owasp.org/www-community/attacks/xss/ > > You can mitigate XSS by having a single browser that is used solely to > access high value sites. e.g. if you routinely run Firefox, have a copy > of Vivaldi that you use to access your banks - one at a time. I have an almost up-to-date copy of Firefox that I use for my high value sites, and that is the copy of Firefox that I used at the time.
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2021-12-25 18:10 +0100 |
| Message-ID | <DyiIp-6fM-1@gated-at.bofh.it> |
| In reply to | #243311 |
[Multipart message — attachments visible in raw view] — view raw
On Ma, 21 dec 21, 10:13:07, Jeremy Ardley wrote: > On 21/12/21 10:09 am, Jeremy Ardley wrote:s. > > There is a type of attack called cross-site scripting (XSS). It's mostly > > been eliminated by latest version browsers, but there are always > > zero-day vulnerabilities. > > > > The effect is that if you are vulnerable and have two tabs open, one to > > the legitimate site, and one to a bad guy site, the bad guy can alter > > your trusted site and for instance change a valid link into something > > malicious, or change a displayed phone number. > > > > More at https://owasp.org/www-community/attacks/xss/ > > > > You can mitigate XSS by having a single browser that is used solely to > access high value sites. e.g. if you routinely run Firefox, have a copy of > Vivaldi that you use to access your banks - one at a time. Hopefully Multi-Account Containers helps with this as well, point 4. in the "What you can do with Multi-Account Containers" seems to imply it. https://support.mozilla.org/en-US/kb/containers Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2021-12-26 14:40 +0100 |
| Message-ID | <DyBUK-10V-7@gated-at.bofh.it> |
| In reply to | #243450 |
Intentionally top posting: Just in an effort to keep my warning on target, I (and I think the consensus of others on this list) is that the problem that occurred was not an XSS attack). Remember that the incident was that I dialed a known good number of a financial institution 3 times, 2 times I got the financial institution, one time I got a scammer. (And further, the Google Voice logs show that I dialed the same number all three times.) On Saturday, December 25, 2021 12:03:00 PM Andrei POPESCU wrote: > On Ma, 21 dec 21, 10:13:07, Jeremy Ardley wrote: > > On 21/12/21 10:09 am, Jeremy Ardley wrote:s. > > > > > There is a type of attack called cross-site scripting (XSS). It's > > > mostly been eliminated by latest version browsers, but there are > > > always zero-day vulnerabilities. > > > > > > The effect is that if you are vulnerable and have two tabs open, one to > > > the legitimate site, and one to a bad guy site, the bad guy can alter > > > your trusted site and for instance change a valid link into something > > > malicious, or change a displayed phone number. > > > > > > More at https://owasp.org/www-community/attacks/xss/ > > > > You can mitigate XSS by having a single browser that is used solely to > > access high value sites. e.g. if you routinely run Firefox, have a copy > > of Vivaldi that you use to access your banks - one at a time. > > Hopefully Multi-Account Containers helps with this as well, point 4. in > the "What you can do with Multi-Account Containers" seems to imply it. > > https://support.mozilla.org/en-US/kb/containers
[toc] | [prev] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2021-12-27 20:10 +0100 |
| Message-ID | <Dz3xE-1dc-17@gated-at.bofh.it> |
| In reply to | #243459 |
Am Sonntag, 26. Dezember 2021, 14:38:04 CET schrieb rhkramer@gmail.com: Hi there, I think, the more important is not, how the attacker got into the phone connection, the more important IMHO is that he said: "They asked me a lot of questions, very personbal questions about me and my family and so on." This should be the most important thing to all people, to give away the only necessary informations thea need and they already should have: name, address, maybe birthdate, sometimes mail-address (for the last one keep a "spammail- address available). If they ask for more, be alarmed and ask, why they need that special information(s). In doubt, disconnect and call again later. There is a big chance, you get another person on the phone, whom you can ask, if he or she knows your last voicepartner. Remember: Alaways, and really always(!) give as few informations away as possible! All datas are like arrows: If one is shot, you never know, who finds it and what he does with it. Copies it, collects it and misuse it, when ever there is an opportunity. So, again: The most important statement was: They asked me a lot of personal questions and wanted to know many peronal data! Keep alarmed! Best Hans > Intentionally top posting: > > Just in an effort to keep my warning on target, I (and I think the consensus > of others on this list) is that the problem that occurred was not an XSS > attack). > > Remember that the incident was that I dialed a known good number of a > financial institution 3 times, 2 times I got the financial institution, one > time I got a scammer. > > (And further, the Google Voice logs show that I dialed the same number all > three times.) >
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-12-21 03:20 +0100 |
| Message-ID | <DwCUV-24G-1@gated-at.bofh.it> |
| In reply to | #243310 |
[Multipart message — attachments visible in raw view] — view raw
On 21/12/21 9:59 am, rhkramer@gmail.com wrote: > On Monday, December 20, 2021 02:28:13 PM Brian wrote: >> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: >>> My identity has been stolen, and although it has nothing to do with >> [...] >> >> May we know the URL of the financial website you contacted and the >> help number you phoned. > The website is troweprice.com, and the phone number is 855/654-5324. > > It looks like I didn't record the actual URL that I was on, but I don't think > you could see that exact page in any case as it was an https page and one that > showed my account numbers and balances. > There is a type of attack called cross-site scripting (XSS). It's mostly been eliminated by latest version browsers, but there are always zero-day vulnerabilities. The effect is that if you are vulnerable and have two tabs open, one to the legitimate site, and one to a bad guy site, the bad guy can alter your trusted site and for instance change a valid link into something malicious, or change a displayed phone number. More at https://owasp.org/www-community/attacks/xss/ -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-12-21 03:50 +0100 |
| Subject | Re: vulnerability classifications (was: Re: Identity Theft) |
| Message-ID | <DwDnX-2e7-3@gated-at.bofh.it> |
| In reply to | #243312 |
[Multipart message — attachments visible in raw view] — view raw
On 21/12/21 10:18 am, Nicole wrote: > >> More at https://owasp.org/www-community/attacks/xss/ > just out of curiousity: I understand XSS are like code injections into > the HTML through user controlled input or attacker controlled input, e.g. > the password field or the message you send someone. what you describe my > amateurish brain however references as XS(-Leak?) vulnerability - is > this a mix-up on your end or a misunderstanding of how words are used on > my end? The overview in the link above describes it. Basically the script can do many things including altering the content of a page More at https://owasp.org/www-community/Types_of_Cross-Site_Scripting -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Richmond <richmond@criptext.com> |
|---|---|
| Date | 2021-12-21 16:50 +0100 |
| Message-ID | <DwPyN-1o9-3@gated-at.bofh.it> |
| In reply to | #243312 |
Jeremy Ardley <jeremy@ardley.org> writes: > On 21/12/21 9:59 am, rhkramer@gmail.com wrote: >> On Monday, December 20, 2021 02:28:13 PM Brian wrote: >>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: >>>> My identity has been stolen, and although it has nothing to do with >>> [...] >>> >>> May we know the URL of the financial website you contacted and the >>> help number you phoned. >> The website is troweprice.com, and the phone number is 855/654-5324. >> >> It looks like I didn't record the actual URL that I was on, but I don't think >> you could see that exact page in any case as it was an https page and one that >> showed my account numbers and balances. >> > > There is a type of attack called cross-site scripting (XSS). It's > mostly been eliminated by latest version browsers, but there are > always zero-day vulnerabilities. > > The effect is that if you are vulnerable and have two tabs open, one > to the legitimate site, and one to a bad guy site, the bad guy can > alter your trusted site and for instance change a valid link into > something malicious, or change a displayed phone number. > > More at https://owasp.org/www-community/attacks/xss/ That doesn't explain how the phone log showed the correct number had been dialled. I suppose it is possible a call was in progress or came in at the exact moment that the number was dialled. But then how did the number get logged as a call?
[toc] | [prev] | [next] | [standalone]
| From | harryweaver@tutanota.com |
|---|---|
| Date | 2021-12-21 21:20 +0100 |
| Message-ID | <DwTM5-49V-1@gated-at.bofh.it> |
| In reply to | #243330 |
-- Sent with Tutanota, the secure & ad-free mailbox. 22 Dec 2021, 01:20 by richmond@criptext.com: > Jeremy Ardley <jeremy@ardley.org> writes: > >> On 21/12/21 9:59 am, rhkramer@gmail.com wrote: >> >>> On Monday, December 20, 2021 02:28:13 PM Brian wrote: >>> >>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: >>>> >>>>> My identity has been stolen, and although it has nothing to do with >>>>> >>>> [...] >>>> >>>> May we know the URL of the financial website you contacted and the >>>> help number you phoned. >>>> >>> The website is troweprice.com, and the phone number is 855/654-5324. >>> >>> It looks like I didn't record the actual URL that I was on, but I don't think >>> you could see that exact page in any case as it was an https page and one that >>> showed my account numbers and balances. >>> >> >> There is a type of attack called cross-site scripting (XSS). It's >> mostly been eliminated by latest version browsers, but there are >> always zero-day vulnerabilities. >> >> The effect is that if you are vulnerable and have two tabs open, one >> to the legitimate site, and one to a bad guy site, the bad guy can >> alter your trusted site and for instance change a valid link into >> something malicious, or change a displayed phone number. >> >> More at https://owasp.org/www-community/attacks/xss/ >> > > That doesn't explain how the phone log showed the correct number had > been dialled. I suppose it is possible a call was in progress or came in > at the exact moment that the number was dialled. But then how did the > number get logged as a call? > A MiM attack can happen with phones every bit as with computers. Cheers! Harry
[toc] | [prev] | [next] | [standalone]
| From | "tv.debian@googlemail.com" <tv.debian@googlemail.com> |
|---|---|
| Date | 2021-12-21 23:30 +0100 |
| Message-ID | <DwVNT-5k4-1@gated-at.bofh.it> |
| In reply to | #243330 |
Le 21/12/2021 à 16:20, Richmond a écrit : > Jeremy Ardley <jeremy@ardley.org> writes: > >> On 21/12/21 9:59 am, rhkramer@gmail.com wrote: >>> On Monday, December 20, 2021 02:28:13 PM Brian wrote: >>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: >>>>> My identity has been stolen, and although it has nothing to do with >>>> [...] >>>> >>>> May we know the URL of the financial website you contacted and the >>>> help number you phoned. >>> The website is troweprice.com, and the phone number is 855/654-5324. >>> >>> It looks like I didn't record the actual URL that I was on, but I don't think >>> you could see that exact page in any case as it was an https page and one that >>> showed my account numbers and balances. >>> >> >> There is a type of attack called cross-site scripting (XSS). It's >> mostly been eliminated by latest version browsers, but there are >> always zero-day vulnerabilities. >> >> The effect is that if you are vulnerable and have two tabs open, one >> to the legitimate site, and one to a bad guy site, the bad guy can >> alter your trusted site and for instance change a valid link into >> something malicious, or change a displayed phone number. >> >> More at https://owasp.org/www-community/attacks/xss/ > > That doesn't explain how the phone log showed the correct number had > been dialled. I suppose it is possible a call was in progress or came in > at the exact moment that the number was dialled. But then how did the > number get logged as a call? > One possiblity is that the target (recipient of the call) company internal communication network was compromised. That happens quite often, not as much as mail servers but it is still not unknown.
[toc] | [prev] | [next] | [standalone]
| From | Jeremy Ardley <jeremy@ardley.org> |
|---|---|
| Date | 2021-12-21 23:50 +0100 |
| Message-ID | <DwW7f-5q5-1@gated-at.bofh.it> |
| In reply to | #243344 |
[Multipart message — attachments visible in raw view] — view raw
On 22/12/21 6:23 am, tv.debian@googlemail.com wrote: > > One possiblity is that the target (recipient of the call) company > internal communication network was compromised. That happens quite > often, not as much as mail servers but it is still not unknown. > This is completely hypothetical, but with COVID work from home is very common and that includes inbound call centre operators. A compromise of an operator's computer, and/or getting VOIP phone credentials to the call centre PBX is quite possible. -- Jeremy
[toc] | [prev] | [next] | [standalone]
| From | Polyna-Maude Racicot-Summerside <debian@polynamaude.com> |
|---|---|
| Date | 2021-12-22 00:40 +0100 |
| Message-ID | <DwWTE-5Ve-11@gated-at.bofh.it> |
| In reply to | #243344 |
[Multipart message — attachments visible in raw view] — view raw
On 2021-12-21 5:23 p.m., tv.debian@googlemail.com wrote: > Le 21/12/2021 à 16:20, Richmond a écrit : >> Jeremy Ardley <jeremy@ardley.org> writes: >> >>> On 21/12/21 9:59 am, rhkramer@gmail.com wrote: >>>> On Monday, December 20, 2021 02:28:13 PM Brian wrote: >>>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: >>>>>> My identity has been stolen, and although it has nothing to do with >>>>> [...] >>>>> >>>>> May we know the URL of the financial website you contacted and the >>>>> help number you phoned. >>>> The website is troweprice.com, and the phone number is 855/654-5324. >>>> >>>> It looks like I didn't record the actual URL that I was on, but I >>>> don't think >>>> you could see that exact page in any case as it was an https page >>>> and one that >>>> showed my account numbers and balances. >>>> >>> >>> There is a type of attack called cross-site scripting (XSS). It's >>> mostly been eliminated by latest version browsers, but there are >>> always zero-day vulnerabilities. >>> >>> The effect is that if you are vulnerable and have two tabs open, one >>> to the legitimate site, and one to a bad guy site, the bad guy can >>> alter your trusted site and for instance change a valid link into >>> something malicious, or change a displayed phone number. >>> >>> More at https://owasp.org/www-community/attacks/xss/ >> >> That doesn't explain how the phone log showed the correct number had >> been dialled. I suppose it is possible a call was in progress or came in >> at the exact moment that the number was dialled. But then how did the >> number get logged as a call? >> > > One possiblity is that the target (recipient of the call) company > internal communication network was compromised. That happens quite > often, not as much as mail servers but it is still not unknown. > This was a pretty popular form of hacking from the 1980 up to mid 2000. As soon there was some automatic exchange, people found ways to act them and more programmable they were, the more hacked happened. Call redirection is not unknown of and not because there's new way of hacking that the old one stop being used. -- Polyna-Maude R.-Summerside -Be smart, Be wise, Support opensource development
[toc] | [prev] | [next] | [standalone]
| From | Philippe LeCavalier <support@plecavalier.com> |
|---|---|
| Date | 2021-12-22 16:00 +0100 |
| Message-ID | <DxbfX-6ex-1@gated-at.bofh.it> |
| In reply to | #243344 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 21, 2021, 17:23 tv.debian@googlemail.com < tv.debian@googlemail.com> wrote: > Le 21/12/2021 à 16:20, Richmond a écrit : > > Jeremy Ardley <jeremy@ardley.org> writes: > > > >> On 21/12/21 9:59 am, rhkramer@gmail.com wrote: > >>> On Monday, December 20, 2021 02:28:13 PM Brian wrote: > >>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote: > >>>>> My identity has been stolen, and although it has nothing to do with > >>>> [...] > >>>> > >>>> May we know the URL of the financial website you contacted and the > >>>> help number you phoned. > >>> The website is troweprice.com, and the phone number is 855/654-5324. > >>> > >>> It looks like I didn't record the actual URL that I was on, but I > don't think > >>> you could see that exact page in any case as it was an https page and > one that > >>> showed my account numbers and balances. > >>> > >> > >> There is a type of attack called cross-site scripting (XSS). It's > >> mostly been eliminated by latest version browsers, but there are > >> always zero-day vulnerabilities. > >> > >> The effect is that if you are vulnerable and have two tabs open, one > >> to the legitimate site, and one to a bad guy site, the bad guy can > >> alter your trusted site and for instance change a valid link into > >> something malicious, or change a displayed phone number. > >> > >> More at https://owasp.org/www-community/attacks/xss/ > > > > That doesn't explain how the phone log showed the correct number had > > been dialled. I suppose it is possible a call was in progress or came in > > at the exact moment that the number was dialled. But then how did the > > number get logged as a call? > > > > One possiblity is that the target (recipient of the call) company > internal communication network was compromised. That happens quite > often, not as much as mail servers but it is still not unknown. > > My money is on this^. They're probably hosting some services (phones but > not necessarily) on premise and has been compromised. Another probable > scenario imo is they're forwarding to cell phones due to pandemic/WFH and > every now and then you're landing on a spoofed sim card.
[toc] | [prev] | [next] | [standalone]
Page 2 of 3 — ← Prev page 1 [2] 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web