Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Networking: Is that bank's URL legitimate?
Washington Times & UPI ^ | May 1, 2006 | Gene Koprowski

Posted on 05/01/2006 2:17:31 PM PDT by 2Jim_Brown

CHICAGO, May 1 (UPI) -- Computer-security professionals at the weekend were working on what is being described as a just-emerging IT problem -- the kind which, if the pros are correct, potentially could imperil all e-commerce across the globe. Hackers have apparently compromised the computer server of a Russian bank and set up a fake subsite to "phish" for credit-card information and other personal financial details, experts tell UPI's Networking.

This is a new kind of phishing scam, as computer criminals usually set up sites that simply look and feel similar to the site they are attacking. But in this instance, the phishers replicated the Moscow-based KS Bank site itself, www.ks-bank.ru, and not just an image of it, and created a page that used its exact URL, a subsite of that URL, www.ks-bank.ru/.x/hvfcu. This new tactic raises a horrid specter for online banking consumers -- the grinding fear of whether one's e-commerce site is what it purports to be or is actually a criminal enterprise. By Gene Koprowski

http://www.upi.com/Hi-Tech/view.php?StoryID=20060501-100818-3626r

(Excerpt) Read more at washingtontimes.com ...


TOPICS: Business/Economy; Culture/Society; News/Current Events
KEYWORDS: bankcards; banks; hackers; identitytheft; internet; phishing
A new kind of phishing scam emerged - hackers compromising the computer server of a Russian bank.
1 posted on 05/01/2006 2:17:35 PM PDT by 2Jim_Brown
[ Post Reply | Private Reply | View Replies]

To: 2Jim_Brown

Well, do not deal with Russian banks, then - it pays to deal only with those you know and trust.


2 posted on 05/01/2006 2:21:13 PM PDT by GSlob
[ Post Reply | Private Reply | To 1 | View Replies]

To: 2Jim_Brown

The Russians are so poor at technology
they can't even get their "Live" scoring
system operating correctly in the JandS
Tennis Tourney this week in Moscow!


3 posted on 05/01/2006 2:24:48 PM PDT by Grendel9 (u ()
[ Post Reply | Private Reply | To 1 | View Replies]

To: GSlob
Yeah, but what about when YOUR bank deals with the commie bank? Think your info stays here?

My girlfriend works for Chase. You wouldn't believe the amount of our information that goes overseas due to outsourcing of one kind or another. Even the IRS sends stuff abroad.

4 posted on 05/01/2006 2:26:56 PM PDT by Slump Tester ( What if I'm pregnant Teddy? Errr-ahh Calm down Mary Jo, we'll cross that bridge when we come to it)
[ Post Reply | Private Reply | To 2 | View Replies]

To: 2Jim_Brown
criminals usually set up sites that simply look and feel similar to the site they are attacking.

That is a fairly common scenario. Try to never click on a link that arrives by email as they can easily be disquised to take you to a site other than what you expect.
5 posted on 05/01/2006 2:27:21 PM PDT by P-40 (http://www.590klbj.com/forum/index.php?referrerid=1854)
[ Post Reply | Private Reply | To 1 | View Replies]

To: 2Jim_Brown

Are they saying what I think? When I get such email, the "properties" of the URL point to the bogus site, and is completely different from the URL that's displayed (usually chase.com or citibank.com).

Is this post saying that even if you put in the "right" URL you still can go to a fake site? Doesn't SSL or VeriSign prevent it?


6 posted on 05/01/2006 2:28:23 PM PDT by rudy45
[ Post Reply | Private Reply | To 1 | View Replies]

To: rudy45
"www.ks-bank.ru, and not just an image of it, and created a page that used its exact URL, a subsite of that URL, www.ks-bank.ru/.x/hvfcu."

Notice the difference in the urls. The/.x/... doesn't belong to the bank. It's a different IP.

7 posted on 05/01/2006 2:34:04 PM PDT by spunkets
[ Post Reply | Private Reply | To 6 | View Replies]

To: 2Jim_Brown

Except for the enhanced technology, this is just a variation on a very old con game, do a Google search on "The Bank of Sark", and read about some real con men who made this kind of scam work long before the Internet existed.


8 posted on 05/01/2006 2:45:10 PM PDT by mkjessup (The Shah doesn't look so bad now, eh? But nooo, Jimmah said the Ayatollah was a 'godly' man.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: GSlob

The implication of this is that hackers can do this to any bank, or PayPal, etc. or the companies you pay directly to online.


9 posted on 05/01/2006 3:59:17 PM PDT by ThanhPhero (di hanh huong den La Vang)
[ Post Reply | Private Reply | To 2 | View Replies]

To: ThanhPhero

I am dealing with very few companies. All of them are US based, thus sueable in the US.


10 posted on 05/01/2006 4:06:44 PM PDT by GSlob
[ Post Reply | Private Reply | To 9 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson