Posting Foun

Home Refinance LoanVirtuC Ami hanesan grupu istuda nebe kompostu husi estudantes husi area de istuda Teknik Informatika, Sistim Informasi, Teknik Komputer, Manajemen Informatika no Desain Komunikasi Visual. Iha Loron balun atu mai ami espera katak bele iha tan membros balun nebe nak iha interese hnesan atu join ami nia grupu de istuda nee...

Kontinua Le'e

Materias de Istuda Sei istuda buat hotu kona ba ICT (Information and Communication Technology) nebe starta husi Komputador hanesan ninian main tool to be use, nomos sei uja simulator balun nebe mak iha relasaun ho area de istuda...

Kontinua Le'e

Membros Membros ne'e sei kompostu husi estudantes Timoroan iha Bandung nebe mak istuda iha area ICT nian. Iha tinan oin mai, ba membros nebe mak sei join ho grupu ne'e sei hal'o uluk lai projeitu kiik ida nebe mak kona-ba ICT molok atu join ho grupu nee...

Kontinua Le'e


Tuesday, February 15, 2011

CDT: ISP Level Gmail Phishing

Via @torproject comes a link to a China Digital TImes (a site run at Berkeley) that gives just a brief notice that some users behind the GFW are having their gmail login attempts redirected to hxxp://124.117.227.201/web/gmail/ where they are asked to enter their password. Chinese users reporting this redirect believe that the redirects are being performed by the ISP. Interestingly, 124.117.227.201 is a CNC host in Xinjiang.

At the time of this post the hxxp://124.117.227.201/web/gmail/ site is not operating (from the US or the PRC according to webpulse).

The original info apparently came from ntdtv:
中国ISP騙取gmail密码 被現場抓獲

https://www.ntdtv.com/xtr/b5/2010/08/11/a417907_p.html

https://www.ntdtv.com/xtr/b5/2010/08/11/a417907_p.html

UPDATE: I was looking closely at the screen cap that shows the source and it appears that part of the phishing app is hosted on ndns01.com, which doesn’t presently have an IP address assigned although the DNS record was updated on August 10.


Source: http://www.thedarkvisitor.com

0 comments:

Post a Comment