Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #243294 > unrolled thread

Identity Theft

Started byrhkramer@gmail.com
First post2021-12-20 16:40 +0100
Last post2021-12-21 18:40 +0100
Articles 20 on this page of 41 — 22 participants

Back to article view | Back to linux.debian.user


Contents

  Identity Theft rhkramer@gmail.com - 2021-12-20 16:40 +0100
    Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 17:00 +0100
    Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 17:20 +0100
      Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 19:10 +0100
        Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-20 19:40 +0100
          Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 19:50 +0100
            Re: Identity Theft Nicholas Geovanis <nickgeovanis@gmail.com> - 2021-12-20 20:00 +0100
          Re: Identity Theft "Jeremy Nicoll" <jn.ml.dbn.25@letterboxes.org> - 2021-12-20 20:10 +0100
            Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:00 +0100
              Re: Identity Theft John Hasler <john@sugarbit.com> - 2021-12-21 06:00 +0100
              Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 17:00 +0100
                Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:50 +0100
                  Re: Identity Theft Curt <curty@free.fr> - 2021-12-21 19:50 +0100
                    Re: Identity Theft rhkramer@gmail.com - 2021-12-21 20:10 +0100
    Re: Identity Theft Brian <ad44@cityscape.co.uk> - 2021-12-20 20:30 +0100
      Re: Identity Theft rhkramer@gmail.com - 2021-12-21 03:10 +0100
        Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
          Re: Identity Theft local10 <local10@tutanota.com> - 2021-12-21 09:20 +0100
            Re: Identity Theft Kenneth Parker <sea7kenp@gmail.com> - 2021-12-21 13:50 +0100
              Re: Identity Theft Eike Lantzsch ZP6CGE <zp6cge@gmx.net> - 2021-12-21 14:30 +0100
                Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
                  Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 15:20 +0100
                    Re: Identity Theft Markus Schönhaber <debian-user@list-post.mks-mail.de> - 2021-12-21 16:30 +0100
                    Re: Identity Theft Dan Ritter <dsr@randomstring.org> - 2021-12-21 16:40 +0100
                    Re: Identity Theft The Wanderer <wanderer@fastmail.fm> - 2021-12-21 16:40 +0100
                      Re: Identity Theft Tim Woodall <debianuser@woodall.me.uk> - 2021-12-21 19:20 +0100
                      Re: Identity Theft Celejar <celejar@gmail.com> - 2021-12-21 22:40 +0100
                Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 14:40 +0100
          Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100
          Re: Identity Theft Andrei POPESCU <andreimpopescu@gmail.com> - 2021-12-25 18:10 +0100
            Re: Identity Theft rhkramer@gmail.com - 2021-12-26 14:40 +0100
              Re: Identity Theft Hans <hans.ullrich@loop.de> - 2021-12-27 20:10 +0100
        Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:20 +0100
          Re: vulnerability classifications (was: Re: Identity Theft) Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 03:50 +0100
          Re: Identity Theft Richmond <richmond@criptext.com> - 2021-12-21 16:50 +0100
            Re: Identity Theft harryweaver@tutanota.com - 2021-12-21 21:20 +0100
            Re: Identity Theft "tv.debian@googlemail.com" <tv.debian@googlemail.com> - 2021-12-21 23:30 +0100
              Re: Identity Theft Jeremy Ardley <jeremy@ardley.org> - 2021-12-21 23:50 +0100
              Re: Identity Theft Polyna-Maude Racicot-Summerside <debian@polynamaude.com> - 2021-12-22 00:40 +0100
              Re: Identity Theft Philippe LeCavalier <support@plecavalier.com> - 2021-12-22 16:00 +0100
          Re: Identity Theft rhkramer@gmail.com - 2021-12-21 18:40 +0100

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#243322

From"tv.debian@googlemail.com" <tv.debian@googlemail.com>
Date2021-12-21 14:40 +0100
Message-ID<DwNwZ-eW-1@gated-at.bofh.it>
In reply to#243321
Le 21/12/2021 à 14:24, Eike Lantzsch ZP6CGE a écrit :
> On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote:
>> On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote:
>>> Dec 21, 2021, 02:13 by jeremy@ardley.org:
>>>> You can mitigate XSS by having a single browser that is used
>>>> solely to>
>>> access high value sites. e.g. if you routinely run Firefox, have a
>>> copy of Vivaldi that you use to access your banks - one at a time.
>>>
>>>
>>>
>>> Installing NoScript also may help as it has an option to sanitize
>>> cross-site suspicious requests. NoScript also speeds up the browser
>>> by disabling all the tracking and spying scripts many sites load
>>> nowadays. Just make sure to disable all the garbage it has enabled
>>> by default after the installation.
>>
>> +1 on NoScript.  I particularly like the White List capabilities,
>> where you can allow Scripts by Website, and even only one time.  I
>> only know it to work with Firefox, at this time.
>>
>> Kenneth Parker
> 
> Is this
> 
> *No-Script Suite Lite by AdblockLite[1]*
> (this one has a whitelist feature) or
> *NoScript Security Suite by Giorgio Maone[2]*
> (has a whitelist feature too) or other?
> 
> I'm using Privicy Badger among other means
> like limiting and redirecting DNS requests. But that does not avoid JS.
> 
> Cheers
> Eike
> 
> --------
> [1] https://addons.mozilla.org/en-US/firefox/user/11285580/
> [2] https://addons.mozilla.org/en-US/firefox/user/143/
> 

It is the second one, "Noscript" in one word [1]. Several look-alike 
have spawn over the years. I also use Umatrix [2], but it is more complex.

For Firefox:
[1] https://addons.mozilla.org/fr/firefox/addon/noscript/
[2] https://addons.mozilla.org/fr/firefox/addon/umatrix/

At least one of those is packaged in Debian.

[toc] | [prev] | [next] | [standalone]


#243325

FromTim Woodall <debianuser@woodall.me.uk>
Date2021-12-21 15:20 +0100
Message-ID<DwO9H-GY-3@gated-at.bofh.it>
In reply to#243322
On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote:

> Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?:
> It is the second one, "Noscript" in one word [1]. Several look-alike have 
> spawn over the years. I also use Umatrix [2], but it is more complex.
>
> For Firefox:
> [1] https://addons.mozilla.org/fr/firefox/addon/noscript/
> [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/
>
> At least one of those is packaged in Debian.
>

Will umatrix still work in firefox 91?

Certainly didn't work for me in android v92.

[toc] | [prev] | [next] | [standalone]


#243327

FromMarkus Schönhaber <debian-user@list-post.mks-mail.de>
Date2021-12-21 16:30 +0100
Message-ID<DwPfs-1i5-3@gated-at.bofh.it>
In reply to#243325
21.12.21, 15:10 +0100, Tim Woodall:

> Will umatrix still work in firefox 91?

Yes.

-- 
Regards
   mks

[toc] | [prev] | [next] | [standalone]


#243328

FromDan Ritter <dsr@randomstring.org>
Date2021-12-21 16:40 +0100
Message-ID<DwPp8-1l3-7@gated-at.bofh.it>
In reply to#243325
Tim Woodall wrote: 
> On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote:
> 
> > Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?:
> > It is the second one, "Noscript" in one word [1]. Several look-alike
> > have spawn over the years. I also use Umatrix [2], but it is more
> > complex.
> > 
> > For Firefox:
> > [1] https://addons.mozilla.org/fr/firefox/addon/noscript/
> > [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/
> > 
> > At least one of those is packaged in Debian.
> > 
> 
> Will umatrix still work in firefox 91?
> 
> Certainly didn't work for me in android v92.

Yes, it does. Android's Firefox is a completely different
codebase, and there is support for only a small number of addons
there.

That said, the primary developer of uMatrix has stopped working
on it, and recommends that people switch to uBlock Origin
instead.

-dsr-

[toc] | [prev] | [next] | [standalone]


#243329

FromThe Wanderer <wanderer@fastmail.fm>
Date2021-12-21 16:40 +0100
Message-ID<DwPp7-1l3-5@gated-at.bofh.it>
In reply to#243325

[Multipart message — attachments visible in raw view] — view raw

On 2021-12-21 at 09:10, Tim Woodall wrote:

> On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote:
> 
>> Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?:
>> 
>> It is the second one, "Noscript" in one word [1]. Several
>> look-alike have spawn over the years. I also use Umatrix [2], but
>> it is more complex.
>>
>> For Firefox:
>> [1] https://addons.mozilla.org/fr/firefox/addon/noscript/
>> [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/
>>
>> At least one of those is packaged in Debian.
> 
> Will umatrix still work in firefox 91?
> 
> Certainly didn't work for me in android v92.

Is uMatrix on the whitelist of extensions that are allowed on the mobile
version of Firefox?

Some good number of releases ago, Mozilla completely redid the mobile
version of Firefox, and in the process dropped support for most of the
extension base - as in, they restricted the allowed extensions to only
those in a defined list, and started that list out with a grand total of
*nine* items. (See [1] for some at-the-time commentary on this.)

I understand that in the time since then they've gradually expanded the
list of allowed extensions, but at nothing like a rapid pace, and with
no sign that they even intend to ever let the broad scope of extensions
be installable (much less usable) for mobile-device Firefox again.

It's always possible that uMatrix is one of the whitelisted extensions,
but I wouldn't be even slightly surprised if it weren't.

[1]
https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/

-- 
   The Wanderer

The reasonable man adapts himself to the world; the unreasonable one
persists in trying to adapt the world to himself. Therefore all
progress depends on the unreasonable man.         -- George Bernard Shaw

[toc] | [prev] | [next] | [standalone]


#243335

FromTim Woodall <debianuser@woodall.me.uk>
Date2021-12-21 19:20 +0100
Message-ID<DwRTY-32z-5@gated-at.bofh.it>
In reply to#243329
On Tue, 21 Dec 2021, The Wanderer wrote:

> On 2021-12-21 at 09:10, Tim Woodall wrote:
>
>>
>> Will umatrix still work in firefox 91?
>>
>> Certainly didn't work for me in android v92.
>
> Is uMatrix on the whitelist of extensions that are allowed on the mobile
> version of Firefox?
>
> Some good number of releases ago, Mozilla completely redid the mobile
> version of Firefox, and in the process dropped support for most of the
> extension base - as in, they restricted the allowed extensions to only
> those in a defined list, and started that list out with a grand total of
> *nine* items. (See [1] for some at-the-time commentary on this.)
>
> I understand that in the time since then they've gradually expanded the
> list of allowed extensions, but at nothing like a rapid pace, and with
> no sign that they even intend to ever let the broad scope of extensions
> be installable (much less usable) for mobile-device Firefox again.
>
> It's always possible that uMatrix is one of the whitelisted extensions,
> but I wouldn't be even slightly surprised if it weren't.
>
> [1]
> https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/
>

Interesting read. Thanks.

I've just installed the kiwi browser which does allow extensions. I
found it while googling how to install extensions on vivaldi android
(which it seems you cannot)

[toc] | [prev] | [next] | [standalone]


#243343

FromCelejar <celejar@gmail.com>
Date2021-12-21 22:40 +0100
Message-ID<DwV1v-4Pa-3@gated-at.bofh.it>
In reply to#243329
On Tue, 21 Dec 2021 10:34:49 -0500
The Wanderer <wanderer@fastmail.fm> wrote:

> On 2021-12-21 at 09:10, Tim Woodall wrote:
> 
> > On Tue, 21 Dec 2021, tv.debian@googlemail.com wrote:
> > 
> >> Le 21/12/2021 ? 14:24, Eike Lantzsch ZP6CGE a ?crit?:
> >> 
> >> It is the second one, "Noscript" in one word [1]. Several
> >> look-alike have spawn over the years. I also use Umatrix [2], but
> >> it is more complex.
> >>
> >> For Firefox:
> >> [1] https://addons.mozilla.org/fr/firefox/addon/noscript/
> >> [2] https://addons.mozilla.org/fr/firefox/addon/umatrix/
> >>
> >> At least one of those is packaged in Debian.
> > 
> > Will umatrix still work in firefox 91?
> > 
> > Certainly didn't work for me in android v92.
> 
> Is uMatrix on the whitelist of extensions that are allowed on the mobile
> version of Firefox?
> 
> Some good number of releases ago, Mozilla completely redid the mobile
> version of Firefox, and in the process dropped support for most of the
> extension base - as in, they restricted the allowed extensions to only
> those in a defined list, and started that list out with a grand total of
> *nine* items. (See [1] for some at-the-time commentary on this.)
> 
> I understand that in the time since then they've gradually expanded the
> list of allowed extensions, but at nothing like a rapid pace, and with
> no sign that they even intend to ever let the broad scope of extensions
> be installable (much less usable) for mobile-device Firefox again.
> 
> It's always possible that uMatrix is one of the whitelisted extensions,
> but I wouldn't be even slightly surprised if it weren't.
> 
> [1]
> https://palant.info/2020/08/31/a-grim-outlook-on-the-future-of-browser-add-ons/

1) The author of uBlock and uMatrix, Raymond Hill, has abandoned the
latter:

https://github.com/uBlockOrigin/uMatrix-issues/issues/291#issuecomment-694988696
https://www.ghacks.net/2020/09/20/umatrix-development-has-ended/

2) Android uBlock is indeed on the official list of Firefox Recommended
Extensions:

https://addons.mozilla.org/en-US/firefox/addon/ublock-origin/
https://addons.mozilla.org/en-US/firefox/collections/4757633/7dfae8669acc4312a65e8ba5553036/

Celejar

[toc] | [prev] | [next] | [standalone]


#243323

From"tv.debian@googlemail.com" <tv.debian@googlemail.com>
Date2021-12-21 14:40 +0100
Message-ID<DwNwZ-eW-3@gated-at.bofh.it>
In reply to#243321
Le 21/12/2021 à 14:24, Eike Lantzsch ZP6CGE a écrit :
> On Dienstag, 21. Dezember 2021 09:43:42 -03 Kenneth Parker wrote:
>> On Tue, Dec 21, 2021, 3:15 AM local10 <local10@tutanota.com> wrote:
>>> Dec 21, 2021, 02:13 by jeremy@ardley.org:
>>>> You can mitigate XSS by having a single browser that is used
>>>> solely to>
>>> access high value sites. e.g. if you routinely run Firefox, have a
>>> copy of Vivaldi that you use to access your banks - one at a time.
>>>
>>>
>>>
>>> Installing NoScript also may help as it has an option to sanitize
>>> cross-site suspicious requests. NoScript also speeds up the browser
>>> by disabling all the tracking and spying scripts many sites load
>>> nowadays. Just make sure to disable all the garbage it has enabled
>>> by default after the installation.
>>
>> +1 on NoScript.  I particularly like the White List capabilities,
>> where you can allow Scripts by Website, and even only one time.  I
>> only know it to work with Firefox, at this time.
>>
>> Kenneth Parker
> 
> Is this
> 
> *No-Script Suite Lite by AdblockLite[1]*
> (this one has a whitelist feature) or
> *NoScript Security Suite by Giorgio Maone[2]*
> (has a whitelist feature too) or other?
> 
> I'm using Privicy Badger among other means
> like limiting and redirecting DNS requests. But that does not avoid JS.
> 
> Cheers
> Eike
> 
> --------
> [1] https://addons.mozilla.org/en-US/firefox/user/11285580/
> [2] https://addons.mozilla.org/en-US/firefox/user/143/
> 

To follow up on myself, shamelessly ;-) , noscript and umatrix are 
packaged in Debian (depending on your version), and both protect from 
cross site scripting. Packages are "webext-umatrix" and "webext-noscript".

[toc] | [prev] | [next] | [standalone]


#243333

Fromrhkramer@gmail.com
Date2021-12-21 18:40 +0100
Message-ID<DwRhh-2yP-33@gated-at.bofh.it>
In reply to#243311
On Monday, December 20, 2021 09:13:07 PM Jeremy Ardley wrote:
> On 21/12/21 10:09 am, Jeremy Ardley wrote:s.
> 
> > There is a type of attack called cross-site scripting (XSS). It's
> > mostly been eliminated by latest version browsers, but there are
> > always zero-day vulnerabilities.
> > 
> > The effect is that if you are vulnerable and have two tabs open, one
> > to the legitimate site, and one to a bad guy site, the bad guy can
> > alter your trusted site and for instance change a valid link into
> > something malicious, or change a displayed phone number.
> > 
> > More at https://owasp.org/www-community/attacks/xss/
> 
> You can mitigate XSS by having a single browser that is used solely to
> access high value sites. e.g. if you routinely run Firefox, have a copy
> of Vivaldi that you use to access your banks - one at a time.

I have an almost up-to-date copy of Firefox that I use for my high value 
sites, and that is the copy of Firefox that I used at the time.

[toc] | [prev] | [next] | [standalone]


#243450

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2021-12-25 18:10 +0100
Message-ID<DyiIp-6fM-1@gated-at.bofh.it>
In reply to#243311

[Multipart message — attachments visible in raw view] — view raw

On Ma, 21 dec 21, 10:13:07, Jeremy Ardley wrote:
> On 21/12/21 10:09 am, Jeremy Ardley wrote:s.
> > There is a type of attack called cross-site scripting (XSS). It's mostly
> > been eliminated by latest version browsers, but there are always
> > zero-day vulnerabilities.
> > 
> > The effect is that if you are vulnerable and have two tabs open, one to
> > the legitimate site, and one to a bad guy site, the bad guy can alter
> > your trusted site and for instance change a valid link into something
> > malicious, or change a displayed phone number.
> > 
> > More at https://owasp.org/www-community/attacks/xss/
> > 
> 
> You can mitigate XSS by having a single browser that is used solely to
> access high value sites. e.g. if you routinely run Firefox, have a copy of
> Vivaldi that you use to access your banks - one at a time.

Hopefully Multi-Account Containers helps with this as well, point 4. in 
the "What you can do with Multi-Account Containers" seems to imply it.

https://support.mozilla.org/en-US/kb/containers


Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#243459

Fromrhkramer@gmail.com
Date2021-12-26 14:40 +0100
Message-ID<DyBUK-10V-7@gated-at.bofh.it>
In reply to#243450
Intentionally top posting:

Just in an effort to keep my warning on target, I (and I think the consensus of 
others on this list) is that the problem that occurred was not an XSS attack).

Remember that the incident was that I dialed a known good number of a financial 
institution 3 times, 2 times I got the financial institution, one time I got a 
scammer.

(And further, the Google Voice logs show that I dialed the same number all 
three times.)

On Saturday, December 25, 2021 12:03:00 PM Andrei POPESCU wrote:
> On Ma, 21 dec 21, 10:13:07, Jeremy Ardley wrote:
> > On 21/12/21 10:09 am, Jeremy Ardley wrote:s.
> > 
> > > There is a type of attack called cross-site scripting (XSS). It's
> > > mostly been eliminated by latest version browsers, but there are
> > > always zero-day vulnerabilities.
> > > 
> > > The effect is that if you are vulnerable and have two tabs open, one to
> > > the legitimate site, and one to a bad guy site, the bad guy can alter
> > > your trusted site and for instance change a valid link into something
> > > malicious, or change a displayed phone number.
> > > 
> > > More at https://owasp.org/www-community/attacks/xss/
> > 
> > You can mitigate XSS by having a single browser that is used solely to
> > access high value sites. e.g. if you routinely run Firefox, have a copy
> > of Vivaldi that you use to access your banks - one at a time.
> 
> Hopefully Multi-Account Containers helps with this as well, point 4. in
> the "What you can do with Multi-Account Containers" seems to imply it.
> 
> https://support.mozilla.org/en-US/kb/containers

[toc] | [prev] | [next] | [standalone]


#243479

FromHans <hans.ullrich@loop.de>
Date2021-12-27 20:10 +0100
Message-ID<Dz3xE-1dc-17@gated-at.bofh.it>
In reply to#243459
Am Sonntag, 26. Dezember 2021, 14:38:04 CET schrieb rhkramer@gmail.com:
Hi there,

I think, the more important is not, how the attacker got into the phone 
connection, the more important IMHO is that he said: "They asked me a lot of 
questions, very personbal questions about me and my family and so on."

This should be the most important thing to all people, to give away the only 
necessary informations thea need and they already should have: name, address, 
maybe birthdate, sometimes mail-address (for the last one keep a "spammail-
address available). 

If they ask for more, be alarmed and ask, why they need that special 
information(s). In doubt, disconnect and call again later. There is a big 
chance, you get another person on the phone, whom you can ask, if he or she 
knows your last voicepartner.

Remember: Alaways, and really always(!) give as few informations away as 
possible! All datas are like arrows: If one is shot, you never know, who finds 
it and what he does with it. Copies it, collects it and misuse it, when ever 
there is an opportunity.

So, again: The most important statement was: They asked me a lot of personal 
questions and wanted to know many peronal data!

Keep alarmed!

Best 

Hans


 
> Intentionally top posting:
> 
> Just in an effort to keep my warning on target, I (and I think the consensus
> of others on this list) is that the problem that occurred was not an XSS
> attack).
> 
> Remember that the incident was that I dialed a known good number of a
> financial institution 3 times, 2 times I got the financial institution, one
> time I got a scammer.
> 
> (And further, the Google Voice logs show that I dialed the same number all
> three times.)
> 

[toc] | [prev] | [next] | [standalone]


#243312

FromJeremy Ardley <jeremy@ardley.org>
Date2021-12-21 03:20 +0100
Message-ID<DwCUV-24G-1@gated-at.bofh.it>
In reply to#243310

[Multipart message — attachments visible in raw view] — view raw

On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
>>> My identity has been stolen, and although it has nothing to do with
>> [...]
>>
>> May we know the URL of the financial website you contacted and the
>> help number you phoned.
> The website is troweprice.com, and the phone number is 855/654-5324.
>
> It looks like I didn't record the actual URL that I was on, but I don't think
> you could see that exact page in any case as it was an https page and one that
> showed my account numbers and balances.
>

There is a type of attack called cross-site scripting (XSS). It's mostly 
been eliminated by latest version browsers, but there are always 
zero-day vulnerabilities.

The effect is that if you are vulnerable and have two tabs open, one to 
the legitimate site, and one to a bad guy site, the bad guy can alter 
your trusted site and for instance change a valid link into something 
malicious, or change a displayed phone number.

More at https://owasp.org/www-community/attacks/xss/

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#243313 — Re: vulnerability classifications (was: Re: Identity Theft)

FromJeremy Ardley <jeremy@ardley.org>
Date2021-12-21 03:50 +0100
SubjectRe: vulnerability classifications (was: Re: Identity Theft)
Message-ID<DwDnX-2e7-3@gated-at.bofh.it>
In reply to#243312

[Multipart message — attachments visible in raw view] — view raw

On 21/12/21 10:18 am, Nicole wrote:
>
>> More at https://owasp.org/www-community/attacks/xss/
> just out of curiousity: I understand XSS are like code injections into
> the HTML through user controlled input or attacker controlled input, e.g.
> the password field or the message you send someone. what you describe my
> amateurish brain however references as XS(-Leak?) vulnerability - is
> this a mix-up on your end or a misunderstanding of how words are used on
> my end?

The overview in the link above describes it. Basically the script can do 
many things including altering the content of a page

More at

https://owasp.org/www-community/Types_of_Cross-Site_Scripting

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#243330

FromRichmond <richmond@criptext.com>
Date2021-12-21 16:50 +0100
Message-ID<DwPyN-1o9-3@gated-at.bofh.it>
In reply to#243312
Jeremy Ardley <jeremy@ardley.org> writes:

> On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
>> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
>>>> My identity has been stolen, and although it has nothing to do with
>>> [...]
>>>
>>> May we know the URL of the financial website you contacted and the
>>> help number you phoned.
>> The website is troweprice.com, and the phone number is 855/654-5324.
>>
>> It looks like I didn't record the actual URL that I was on, but I don't think
>> you could see that exact page in any case as it was an https page and one that
>> showed my account numbers and balances.
>>
>
> There is a type of attack called cross-site scripting (XSS). It's
> mostly been eliminated by latest version browsers, but there are
> always zero-day vulnerabilities.
>
> The effect is that if you are vulnerable and have two tabs open, one
> to the legitimate site, and one to a bad guy site, the bad guy can
> alter your trusted site and for instance change a valid link into
> something malicious, or change a displayed phone number.
>
> More at https://owasp.org/www-community/attacks/xss/

That doesn't explain how the phone log showed the correct number had
been dialled. I suppose it is possible a call was in progress or came in
at the exact moment that the number was dialled. But then how did the
number get logged as a call?

[toc] | [prev] | [next] | [standalone]


#243342

Fromharryweaver@tutanota.com
Date2021-12-21 21:20 +0100
Message-ID<DwTM5-49V-1@gated-at.bofh.it>
In reply to#243330

-- 
 Sent with Tutanota, the secure & ad-free mailbox. 



22 Dec 2021, 01:20 by richmond@criptext.com:

> Jeremy Ardley <jeremy@ardley.org> writes:
>
>> On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
>>
>>> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
>>>
>>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
>>>>
>>>>> My identity has been stolen, and although it has nothing to do with
>>>>>
>>>> [...]
>>>>
>>>> May we know the URL of the financial website you contacted and the
>>>> help number you phoned.
>>>>
>>> The website is troweprice.com, and the phone number is 855/654-5324.
>>>
>>> It looks like I didn't record the actual URL that I was on, but I don't think
>>> you could see that exact page in any case as it was an https page and one that
>>> showed my account numbers and balances.
>>>
>>
>> There is a type of attack called cross-site scripting (XSS). It's
>> mostly been eliminated by latest version browsers, but there are
>> always zero-day vulnerabilities.
>>
>> The effect is that if you are vulnerable and have two tabs open, one
>> to the legitimate site, and one to a bad guy site, the bad guy can
>> alter your trusted site and for instance change a valid link into
>> something malicious, or change a displayed phone number.
>>
>> More at https://owasp.org/www-community/attacks/xss/
>>
>
> That doesn't explain how the phone log showed the correct number had
> been dialled. I suppose it is possible a call was in progress or came in
> at the exact moment that the number was dialled. But then how did the
> number get logged as a call?
>
A MiM attack can happen with phones every bit as with computers.
Cheers!

Harry

[toc] | [prev] | [next] | [standalone]


#243344

From"tv.debian@googlemail.com" <tv.debian@googlemail.com>
Date2021-12-21 23:30 +0100
Message-ID<DwVNT-5k4-1@gated-at.bofh.it>
In reply to#243330
Le 21/12/2021 à 16:20, Richmond a écrit :
> Jeremy Ardley <jeremy@ardley.org> writes:
> 
>> On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
>>> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
>>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
>>>>> My identity has been stolen, and although it has nothing to do with
>>>> [...]
>>>>
>>>> May we know the URL of the financial website you contacted and the
>>>> help number you phoned.
>>> The website is troweprice.com, and the phone number is 855/654-5324.
>>>
>>> It looks like I didn't record the actual URL that I was on, but I don't think
>>> you could see that exact page in any case as it was an https page and one that
>>> showed my account numbers and balances.
>>>
>>
>> There is a type of attack called cross-site scripting (XSS). It's
>> mostly been eliminated by latest version browsers, but there are
>> always zero-day vulnerabilities.
>>
>> The effect is that if you are vulnerable and have two tabs open, one
>> to the legitimate site, and one to a bad guy site, the bad guy can
>> alter your trusted site and for instance change a valid link into
>> something malicious, or change a displayed phone number.
>>
>> More at https://owasp.org/www-community/attacks/xss/
> 
> That doesn't explain how the phone log showed the correct number had
> been dialled. I suppose it is possible a call was in progress or came in
> at the exact moment that the number was dialled. But then how did the
> number get logged as a call?
> 

One possiblity is that the target (recipient of the call) company 
internal communication network was compromised. That happens quite 
often, not as much as mail servers but it is still not unknown.

[toc] | [prev] | [next] | [standalone]


#243345

FromJeremy Ardley <jeremy@ardley.org>
Date2021-12-21 23:50 +0100
Message-ID<DwW7f-5q5-1@gated-at.bofh.it>
In reply to#243344

[Multipart message — attachments visible in raw view] — view raw

On 22/12/21 6:23 am, tv.debian@googlemail.com wrote:
>
> One possiblity is that the target (recipient of the call) company 
> internal communication network was compromised. That happens quite 
> often, not as much as mail servers but it is still not unknown.
>
This is completely hypothetical, but with COVID work from home is very 
common and that includes inbound call centre operators. A compromise of 
an operator's computer, and/or getting VOIP phone credentials to the 
call centre PBX is quite possible.

-- 
Jeremy

[toc] | [prev] | [next] | [standalone]


#243346

FromPolyna-Maude Racicot-Summerside <debian@polynamaude.com>
Date2021-12-22 00:40 +0100
Message-ID<DwWTE-5Ve-11@gated-at.bofh.it>
In reply to#243344

[Multipart message — attachments visible in raw view] — view raw

On 2021-12-21 5:23 p.m., tv.debian@googlemail.com wrote:
> Le 21/12/2021 à 16:20, Richmond a écrit :
>> Jeremy Ardley <jeremy@ardley.org> writes:
>>
>>> On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
>>>> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
>>>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
>>>>>> My identity has been stolen, and although it has nothing to do with
>>>>> [...]
>>>>>
>>>>> May we know the URL of the financial website you contacted and the
>>>>> help number you phoned.
>>>> The website is troweprice.com, and the phone number is 855/654-5324.
>>>>
>>>> It looks like I didn't record the actual URL that I was on, but I
>>>> don't think
>>>> you could see that exact page in any case as it was an https page
>>>> and one that
>>>> showed my account numbers and balances.
>>>>
>>>
>>> There is a type of attack called cross-site scripting (XSS). It's
>>> mostly been eliminated by latest version browsers, but there are
>>> always zero-day vulnerabilities.
>>>
>>> The effect is that if you are vulnerable and have two tabs open, one
>>> to the legitimate site, and one to a bad guy site, the bad guy can
>>> alter your trusted site and for instance change a valid link into
>>> something malicious, or change a displayed phone number.
>>>
>>> More at https://owasp.org/www-community/attacks/xss/
>>
>> That doesn't explain how the phone log showed the correct number had
>> been dialled. I suppose it is possible a call was in progress or came in
>> at the exact moment that the number was dialled. But then how did the
>> number get logged as a call?
>>
> 
> One possiblity is that the target (recipient of the call) company
> internal communication network was compromised. That happens quite
> often, not as much as mail servers but it is still not unknown.
> 
This was a pretty popular form of hacking from the 1980 up to mid 2000.
As soon there was some automatic exchange, people found ways to act them
and more programmable they were, the more hacked happened. Call
redirection is not unknown of and not because there's new way of hacking
that the old one stop being used.


-- 
Polyna-Maude R.-Summerside
-Be smart, Be wise, Support opensource development

[toc] | [prev] | [next] | [standalone]


#243357

FromPhilippe LeCavalier <support@plecavalier.com>
Date2021-12-22 16:00 +0100
Message-ID<DxbfX-6ex-1@gated-at.bofh.it>
In reply to#243344

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 21, 2021, 17:23 tv.debian@googlemail.com <
tv.debian@googlemail.com> wrote:

> Le 21/12/2021 à 16:20, Richmond a écrit :
> > Jeremy Ardley <jeremy@ardley.org> writes:
> >
> >> On 21/12/21 9:59 am, rhkramer@gmail.com wrote:
> >>> On Monday, December 20, 2021 02:28:13 PM Brian wrote:
> >>>> On Mon 20 Dec 2021 at 10:32:31 -0500, rhkramer@gmail.com wrote:
> >>>>> My identity has been stolen, and although it has nothing to do with
> >>>> [...]
> >>>>
> >>>> May we know the URL of the financial website you contacted and the
> >>>> help number you phoned.
> >>> The website is troweprice.com, and the phone number is 855/654-5324.
> >>>
> >>> It looks like I didn't record the actual URL that I was on, but I
> don't think
> >>> you could see that exact page in any case as it was an https page and
> one that
> >>> showed my account numbers and balances.
> >>>
> >>
> >> There is a type of attack called cross-site scripting (XSS). It's
> >> mostly been eliminated by latest version browsers, but there are
> >> always zero-day vulnerabilities.
> >>
> >> The effect is that if you are vulnerable and have two tabs open, one
> >> to the legitimate site, and one to a bad guy site, the bad guy can
> >> alter your trusted site and for instance change a valid link into
> >> something malicious, or change a displayed phone number.
> >>
> >> More at https://owasp.org/www-community/attacks/xss/
> >
> > That doesn't explain how the phone log showed the correct number had
> > been dialled. I suppose it is possible a call was in progress or came in
> > at the exact moment that the number was dialled. But then how did the
> > number get logged as a call?
> >
>
> One possiblity is that the target (recipient of the call) company
> internal communication network was compromised. That happens quite
> often, not as much as mail servers but it is still not unknown.
>
> My money is on this^. They're probably hosting some services (phones but
> not necessarily) on premise and has been compromised. Another probable
> scenario imo is they're forwarding to cell phones due to pandemic/WFH and
> every now and then you're landing on a spoofed sim card.

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web