HomeinetDon't trust... your browser either

Don't trust... your browser either

social_engineeringThe issue of trust and “social engineering” is considered the fastest way to breach a system. Below are 2 ways through which user passwords can be stolen.

The first way is simple but will help users understand how exposed their passwords (Facebook and not only) are to anyone's eyes, if they trust their browser.

Yes, yes, I know, you're tired of logging in every time, etc. etc. I feel you! But I prefer to log in "manually" than to have a day come when I won't be able to log in because the password is wrong!

1st way:

Read here: WebBrowserPassView.

As you can see, it is a tool that does something very simple. It helps to reset passwords from all browsers present on the user's system.

Go to a website, enter your password (e.g. Facebook), and let the browser save them (it will ask, and you will accept!).

Now download WebBrowsePassView and run the application (no installation required). If you do indeed let the browser save the details, then WebBrowserPassView will find and display these details! (and the details of any other accounts you have on other websites).

"So what? What about that? No one saw them."

Yes, no one saw them...now!

Similar codes, like the one in the above program, can be embedded in a program that starts running on the computer (through various techniques, phishing attacks, etc.). The program does what was mentioned above and why not… it sends your details to someone specific who rubs their hands with satisfaction… And because this program was “running” in the background, you didn’t notice anything!

Conclusion:

1. Anyone who has access to the user's computer can access their passwords.

2. A malicious attacker who gains access to the user's system can simply and easily obtain all of their passwords (with various scripts containing code similar to that of WebBrowserPassView).

And all this just because… you trust the browser!

2nd way:

The second way is slightly more complex, but the result is the same.

The attack is based on creating a clone of another website, and the attacker makes sure it “runs” on a server (for example, let’s say it’s 111.111.111.111 and we “run” a clone of Facebook on it). The attacker must make sure to direct the victim to the page 111.111.111.111 and convince the user that this page is indeed Facebook. If he succeeds, then as soon as the user attempts to log in, the access details are immediately sent to the attacker. Perhaps this is very difficult for someone to fool, as the address bar (with 111.111.111.111 ) “catches the eye”!

But the attack becomes more complex (hey, don't complain! no pain, no gain!).

On every computer, whether Linux or Windows, there is a file called “hosts”. It is the first file that will be checked by the browser (before even checking DNS Servers), in order to locate the IP address that corresponds to the domain name that the user typed. So the malicious user only needs to have access to the computer for 30 seconds to enter the following in the file:

www.facebook.com 111.111.111.111

Then, when the user opens the browser, he types www.facebook.com, which “reads” 111.111.111.111 and the user is taken to a page that looks like facebook, but it is not facebook! And of course he does not understand anything since the address bar continues to write “www.facebook.com”. He logs in and… you have been hacked!

I hope you are convinced that someone with access to your computer and a little time at their disposal can do a lot.

So, that's why your computer and your eyes!

 

We warmly thank SecTeam member @gkoume01.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS