0% found this document useful (0 votes)
5 views26 pages

Website Security: Phishing & Attack Types

The document discusses various types of web-based attacks, including phishing, cross-site scripting (XSS), and clickjacking, emphasizing the vulnerabilities of websites to these threats. It outlines methods for protecting against such attacks, such as checking SSL certificates, using CAPTCHAs, and disabling JavaScript. Additionally, it highlights the importance of user awareness and security measures to prevent unauthorized access and data breaches.

Uploaded by

Rahul Khan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
5 views26 pages

Website Security: Phishing & Attack Types

The document discusses various types of web-based attacks, including phishing, cross-site scripting (XSS), and clickjacking, emphasizing the vulnerabilities of websites to these threats. It outlines methods for protecting against such attacks, such as checking SSL certificates, using CAPTCHAs, and disabling JavaScript. Additionally, it highlights the importance of user awareness and security measures to prevent unauthorized access and data breaches.

Uploaded by

Rahul Khan
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

CamScanner

CamScanner
CamScanner
CamScanner
CamScanner
CamScanner
CamScanner
CamScanner
Phishing

CamScanner
CamScanner
CamScanner
CamScanner
Malicious Web Content

[Link] bug
[Link]
[Link] by download

CamScanner
CamScanner
CamScanner
CamScanner
CamScanner
Code With data
● Cross-Site Scripting
● SQL Injection
● Dot-Dot-Slash
● Server-Side Include

4-2
Code With data
Cross-Site Scripting (XSS) (continue):
● A script submitted as comment or in a text area
● If the script is taken as script instead of plain text, the
site is considered as vulnerable.

● This comment could redirect users to [Link]


unless the comment was taken as plain text
4-5
Browser Attack Types
● Dot-Dot-Slash:
● ‘..’ is the directory indicator for “pre-decessor.”
● Using ../ we can go back one folder back from
the current location
● Following URL causes the server to return the
requested file, [Link]
[Link]
&File=../../../../../winnt/system32/[Link]
● Which enables an attacker to modify or delete it

4-9
Email Attacks
● Why Send Spam:
● Spammers make enough money to make the work
worthwhile.
● Why spam emails are sent:
● Advertising
● Pump and Dump
● Advertising
● Malicious Payload
● Links to Malicious Web Sites
● The Price Is Right

4-16
Phishing
● Spear phishing email tempts recipients by seeming to
come from sources the receiver knows and trusts.
● The email message tries to trick the recipient into
disclosing private data or taking another unsafe action.
● Purport to be from reliable companies such as banks
or other financial institutions, popular web site
companies (such as Facebook, Hotmail, or Yahoo), or
consumer products companies
● In spear phishing, the bait looks especially appealing
to the prey.

4-19
1. The Silent Banker man-in-the-browser attack depends on malicious code that is integrated into
the browser. These browser helpers are essentially unlimited in what they can do. Suggest a
design by which such helpers are more rigorously controlled. Does your approach limit the
usefulness of such helpers?
Chapter 4
Answer 1

Answer 2
 As, we all know, attacks on the websites are being most common rather it be
any phishing attack or mass data breach, etc. The websites are the new and
successful targets for the hackers.
 When we talk about cryptography for confirmation we all know that using
cryptography as software or part of daily use is not legal in all countries and
hence, this would not be an appropriate measure in checking the authenticity
of the websites.
 So, here I have some steps broken down for you in case of checking any
website for its authenticity. They are as follows:
o One must always make sure it is secure to exchange information with
the website or not. The first measure is to check the SSL certificate
which can be found in the URL of the website.
o The URL must begin with "HTTPs" instead of "HTTP" which means
that the site is secured and will be using an SSL certificate for handling
all the requests.
4. A CAPTCHA puzzle is one way to enforce that certain actions need to be carried out by a real person.
However, CAPTCHAs are visual, depending not just on a person’s seeing the image but also on a person’s being
able to recognize distorted letters and numbers. Suggest another method usable by those with limited vision.

Answer 4:
Egglue Semantic CAPTCHA generates text CAPTCHA challenges for protecting
websites from automated spam. Unlike conventional CAPTCHA, all challenges
require only basic intuitive abilities to solve. The use of plain texts rather than images
improves accessibility. Visitors are presented with two meaningful sentences as plain
texts, each missing one verb. Visitors are asked to type in the missing verbs so that
the sentences make intuitive sense.

A real good alternate to visual challenged people is an audio captcha. Here the
challenge is to listen to the characters/numbers read out my the machine and type in
the same characters on the screen.
5. Are computer-to-computer authentications subject to the weakness of replay? Why or why not?

Answer 5:
Computer to computer are subject to weakness of replay attack as mostly these type of
authentication uses username and password as the form of authentication. So if a request
was sent to computer from another computer as a form of authentication and it was
authenticated then a malicious user can enter into the system and then create another
replay of the same request and can gain access to the computer.
Answer 8:

Cross Frame Scripting (XFS) Cheat Sheet, Attack Examples & Protection :

Cross-Frame Scripting (XFS), also known as iFrame Injections, are basically


targeted browser-based phishing attacks. These must not be confused with Cross-
Site Scripting (XSS) attacks, which also allow the execution of malicious JavaScript
scripts. XFS works in a similar manner, but enables only the sniffing of user input for
data harvesting.

According to recent research by Singaporean security expert Wang Jing, over 99%
of the [Link] topic links and domains are vulnerable to XFS and XSS attacks.

What is Cross Frame Scripting (XFS) :

Cross Frame Scripting attacks take place when the victim is tricked into accessing a
malicious web page via his browser. The malicious attacker, who has control of this
page, loads a third-party page in the HTML frame. A malicious JavaScript keylogger
then records the victim’s keystrokes and sends them to the attacker’s server.

Answer 9: Forgery is a false-making, or any material-alteration of any document


or writing to pass it off as genuine, whether by addition, erasure, insertion,
obliteration, removal, or otherwise with intent to [Link] is defined as the criminal
act that includes the purposeful defrauding, misleading, deception, and
misrepresentation of a product, service, or item with the intent to deceive. The scope
forgery is a vast one; forgery can include the production of falsified documents,
counterfeited items - products intended to resemble other products, and the
misrepresentation of fraudulent identification.
Answer 10:
Spam senders always have various email addresses because the email providers
learn of their illegal practices and shut down their accounts. However, nothing stops
the spammers from making new accounts either on the same provider (if they are
not IP blocked) or on a new one from the many available on the Internet.
Furthermore, victims are gullible and some are unfortunately not computer-literate,
so they believe the scams are true and genuine.

Changing addresses and domains decreases the effectiveness ofspam filters. Also,
different domains and addresses may be morelikely to work on different users. Mass
spammers generally aren’tconcerned about users responding to their emails, but
rather try toget them to click links, run code, or download programs.

Answer 11:

 A web server is a computer program that manages the client request for web
pages.
 For client request, client sent a URL (Uniform resource locator) request with
it’s IP.
 IP means address of the client machine.
 So the web server take that request all files corresponding URL send back to
client using it’s IP.
 Each client use different we browsers as their search engine.
 Web server is an application software, which is convert the files as client
needed form, such as text, video, animations etc.
 So, web browser detail is important in client server model, because each
browser support this functions differently.
 aUser’s
12. Suggest eachby
technique request
which for a page is
a browser treated
could as and
detect independently, so server
block clickjacking don’t
attacks
know which file send previously.
 Managing this conflict, cookies used to identify the user information and
session.

Answer 12:
One possible answer is for the browser to look for and block the telltale signs
of clickjacking: transparent frames, for instance.

Install plugins for your broswers like NoScript which will disable those scripts in your
browser this will prevent browser opening that doesn't support script.
Comitari Web Protection is a software that protects you from ClickJacking

C-Frame Option is also another mehtod to prevent the clickJacking


Keep your other plugins updated because old versions are vulnerable to Clickjacking
attack.
13. The issue of cross-site scripting is not just that scripts execute, for they do in many sites. The issue is that the
script is included in the URL communicated between sites, and therefore the user or a malicious process can
rewrite the URL before it goes to its intended destination. Suggest a way by which scripts can be communicated
more securely.

Answer 13:
What is cross site scripting?

Cross site scripting (XSS) is where one site manages to run a script on another site,
with the privileges of you, the user.

In many pages, this would be completely harmless. But now imagine that you have
logged into site A, and that site has used a session cookie to store your identity. If
site B manages to make you load a page on site A containing a script they have
injected into it, that script could take the cookie for site A, and send it to site B. The
person running site B can now use your cookie in their own browser, and can now
use site A, making it think they are you.

How can users protect themselves? Or Ways by which scripts can be


communicated more securely?

Most users are not even aware that XSS and XSRF are possible. And they should
not need to be. Users should not be expected to be security experts - if they were, a
Web developer would be out of the job. However, users who wish to protect
themselves can take a few steps to do so.

The basic step is to never open other sites while you are logged into a site. This
means that while you are logged into your bank, shopping site, blog, forum, web
mail, side admin section, etc., never open another site in any window. Do not click
links in emails, or other applications. If you use Internet Explorer (I recommend
against this if you value your security), do not run programs like Word (that includes
opening attachments in email), or generally any other programs that view Web
pages, as many Windows programs use the Internet Explorer engine either directly
or via macros, and may be used as a vector for these attacks.

If the site uses cookies to log you in, make sure you log out when you are finished
using it. If the site does not allow you to log out, or if it uses HTTP authentication,
then restart your browser. If the site uses a cookie based login but not session
cookies, and does not allow you to log out, then you may find that your browser
allows you to delete those cookies manually.

The next step is to disable JavaScript while logged into a site. This may seem like a
drastic measure, but it will protect against virtually all XSS (but not XSRF) attacks.
Unfortunately, many sites will not allow you to use them without JavaScript, so this
step may not be possible. If the site is important enough, such as a bank, but still
does not allow you to disable JavaScript, then I suggest you use a different bank.

You may also want to disable iframes if your browser (such as Opera) allows that.
This step should not be necessary as long as you do not browse other sites at the
same time, but if you do, it makes it a little harder for XSRF attacks to be carried out,
as most (but by no means all) of them use iframes.

All of these measures are extremely limiting, and certainly not something most users
would want to do. So the final step will always be the one that is preferred: Make

You might also like