Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 38 guests and 1 member online
 
Advertisement

You are here: Home arrow Resourcesarrow News from the Outside Worldarrow [Article] Fake parking tickets direct to malicious Web site
EH-Net
May 21, 2013, 04:23:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: [Article] Fake parking tickets direct to malicious Web site  (Read 5173 times)
0 Members and 1 Guest are viewing this topic.
Fathercat
Newbie
*
Offline Offline

Posts: 24


View Profile
« on: February 04, 2009, 03:53:03 PM »

Found this on CNet

In a scary online-offline Internet scam, hybrid cars in North Dakota have been tagged with fake parking citations that include a Web address hosting malicious software that drops a Trojan onto the computer.

The yellow tickets found on the cars in Grand Forks, North Dakota, read "PARKING VIOLATION This vehicle is in violation of standard parking regulations. To view pictures with information about your parking preferences, go to" and gave a Web site, according to a blog posting on the SANS Internet Storm Center site.

The site referenced shows photos of cars in parking lots in that town and prompts the visitor to download a toolbar to see purported photos of the ticketed car. Downloading the executable installs a Trojan and displays a fake security alert when the system is rebooted. The fake alert prompts the computer user to install a fake anti-virus scanner, SANS said.

"The initial program installed itself as a browser helper object (BHO) for Internet Explorer that downloaded a component from childhe.com and attempted to trick the victim into installing a fake anti-virus scanner from bestantispyware securityscan.com and protectionsoft warecheck.com," wrote SANS analyst Lenny Zeltser.


Without photos of the ticket...talking with my co-workers here.  Asked if you gotten a ticket with the option to go online and pay versus showing up at the courthouse...Would you?

I know that whole toolbar thing was just funny.  But given a link to pay for a ticket... I probably would go check it out. 
Logged


CISSP
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 4165


Editor-In-Chief


View Profile WWW
« Reply #1 on: February 04, 2009, 03:58:46 PM »

Brilliant social engineering tactic to push a client-side attack.

Don
Logged

CISSP, MCSE, CSTA, Security+ SME
xXxKrisxXx
Hero Member
*****
Offline Offline

Posts: 512



View Profile
« Reply #2 on: February 04, 2009, 03:59:07 PM »

Good read and Fathercat, with all these articles I've been reading lately about BHOs & Client-Side attacks, it's a definite I won't be using Internet Explorer any time soon.
Logged

eCPPT, GCIH, OSCP, OSWP
Fathercat
Newbie
*
Offline Offline

Posts: 24


View Profile
« Reply #3 on: February 04, 2009, 05:22:05 PM »

Can always be more paranoid and go back to a text only web browser :-)
Logged


CISSP
jason
Hero Member
*****
Offline Offline

Posts: 1012



View Profile WWW
« Reply #4 on: February 11, 2009, 08:50:35 PM »

Ahh that's a sneaky one.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.051 seconds with 23 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Advertisement

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.