Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Security

Web Fraud 2.0 — Point-and-Click Cracking Tools 92

An anonymous reader writes "The Washington Post's Security Fix blog is running a fascinating series that peers inside some of the Web-based services cyber crooks are using to ply their trade: from masking their identity, to defeating CAPTCHAs, to creating counterfeit documents and validating stolen credit and debit cards. Everyone familiar with this space hears about these kinds of tools and services all the time in the abstract, but the Post blog includes screen shots and background details on the popularity of the services and how each one is helping to bring cyber crime that much closer to the realm of even the most newbie scam artists." Many of these tools require a working knowledge of Russian. Wouldn't surprise me to learn that Chinese-language tools exist too.
This discussion has been archived. No new comments can be posted.

Web Fraud 2.0 — Point-and-Click Cracking Tools

Comments Filter:
  • by Enlarged to Show Tex ( 911413 ) on Tuesday August 26, 2008 @02:28PM (#24754323)
    All this really means is that script kiddies can now do identity theft as easily as they can perform DDoS attacks...
  • by Animats ( 122034 ) on Tuesday August 26, 2008 @02:31PM (#24754359) Homepage

    If you want made-in-USA tools for this, try searching Google for "craigslist auto posting tool" [google.com]. Google offers seven paid ads for spamming tools and crackers. ("The worlds Best Selling Craigslist software. Works with new CAPTCHA!") Three of them (including one that advertises "Only Automated Solution for the new captcha. Nobody else is automated.") are available through Google Checkout.

    This has been going on for months, despite press coverage. I'm beginning to wonder if Google is deliberately promoting tools to kill Craigslist.

  • by garcia ( 6573 ) on Tuesday August 26, 2008 @02:43PM (#24754509)

    I'm beginning to wonder if Google is deliberately promoting tools to kill Craigslist.

    They're deliberately promoting advertisements that make them money. If you notice, if you search for something like AdSense and you'll find links to such treasures as Google Massacre [googlescalper.com]. Whatever pays the bills I guess.

  • Re:Holy Stereotypes! (Score:2, Interesting)

    by Anonymous Coward on Tuesday August 26, 2008 @02:47PM (#24754569)

    Register of *known* Spammers. I'd expect the much better/less bribe-able police services in the US would encourage Spammers there to stay much deeper underground...

  • Re:Holy Stereotypes! (Score:3, Interesting)

    by palegray.net ( 1195047 ) <philip DOT paradis AT palegray DOT net> on Tuesday August 26, 2008 @03:13PM (#24754959) Homepage Journal
    This data looks good until you consider the fact that a major profit center for certain Chinese nationals is the practice of compromising huge numbers of servers hosted outside China, for the purpose of sending SPAM that won't be stopped by GeoIP restrictions.

    Who's making assumptions now?
  • by Jherek Carnelian ( 831679 ) on Tuesday August 26, 2008 @03:19PM (#24755029)

    This has been going on for months, despite press coverage. I'm beginning to wonder if Google is deliberately promoting tools to kill Craigslist.

    If I were Craigslist, I would rather see those tools easily available instead of pushed underground. Because it makes it easier to identify them and thus to create countermeasures.

    For example, instead of just shutting down the exploits and their distrubtion, I would study the tools and see if they have a recognizable 'fingerprint' when used. Then I would make the craigslist software look for such 'fingerprints' and treat the postings differently - for example instead of just blocking the post, I would set the threshold for other user's tagging it as spam to be very low, or even set a timer to delete the post after an hour or two.

    The end result being that the most common and easily available tools would be compromised in non-obvious ways, reducing the rate of escalation in the "arms race" of cracker/anti-cracker tools and simultaneously making abuse less effective for most (ab)users.

  • Re:stereotype day (Score:5, Interesting)

    by Zontar_Thing_From_Ve ( 949321 ) on Tuesday August 26, 2008 @03:41PM (#24755307)
    You forget the main reason the tools and the crime exists in Russia:
    - a weak, corrupt legal system.

    Russians (and quite a few people in the other states of the ex-USSR) have a weird sense of entitlement that causes them to believe that it's perfectly acceptable to steal from the rich. They suffered under communism for so long that it's quite all right to get some payback by stealing from the West now.

    Since Russian law really doesn't care about crimes that are committed outside of Russia against non-Russians and anyway you can just bribe a judge to get whatever ruling you want, there really is no stopping these people. Well, I can think of ways to stop them, but let's just say that I don't think the USA or the EU has the stomach for what it would take. The weak legal system argument probably applies to China too.
  • by smooth wombat ( 796938 ) on Tuesday August 26, 2008 @03:59PM (#24755593) Journal

    I would study the tools and see if they have a recognizable 'fingerprint' when used.

    Forget the tools, it's much easier to identify the fake ads because they use the same phrases over and over. To wit:

    • a body that will make you melt
    • I haven't had much luck on Craigslist

    to name just two I can remember. All CL has to do is to scan their postings every hour, identify ads which use these phrases and delete them. Sure, the postings still get put up but they get taken down just as easily.

  • by gujo-odori ( 473191 ) on Tuesday August 26, 2008 @04:58PM (#24756395)

    Your comment just proves how clueless you are about the spam situation in China.

    China is, and has been for several years, a bastion of "bulletproof" hosting. Since you're so clueless about spam, I probably have to explain bulletproof hosting. Bulletproof hosting is a contract with a hosting provider and/or ISP with IP space to burn that doesn't care what you do with that hosting/IP space so long as you pay your bills.

    China is also a haven of phishing sites, largely for the same reason and courtesy of a few rogue registrars operating in China.

    There's nothing racist about criticizing China for its conduct. What next? You'll be telling us it's racist to criticize Nigeria for being the source of most of the world's 419 spam?

    Silly me. I hadn't heard that scammers, spammers, and those who give them shelter constituted a race.

If you want to put yourself on the map, publish your own map.

Working...