Nat west website - a warning?
Discussion
I've not put this in computers as it obviously could have implications to people who don't give a monkeys / wouldn't have a clue if there hard drive is spinning or their ram is ramming.
Just had a call from a mate who's gone to log in to his Nat West account, only there was a subtle difference to his log in procedure - the site was asking him for ALL his account details, full password etc etc etc. Suspicious, he tried using a different PC, which gave the normal log in procedure, just a few details asked and parts of the password. A call to Nat West confirms that the site being visited via the first PC can't be the real one.
Just waiting for a screen shot to have a look at but after talking through with him on the phone I haven't yet identified any visual difference between the real one and the fake one - both appear to have the same URL, nothing instantly recognisable to distinguish it as a phishing site.
So, a possible word of warning to those who bank with Nat West, and also a request for thoughts on tracing how this computer is linking through the correct URL to a scam site?
Just had a call from a mate who's gone to log in to his Nat West account, only there was a subtle difference to his log in procedure - the site was asking him for ALL his account details, full password etc etc etc. Suspicious, he tried using a different PC, which gave the normal log in procedure, just a few details asked and parts of the password. A call to Nat West confirms that the site being visited via the first PC can't be the real one.
Just waiting for a screen shot to have a look at but after talking through with him on the phone I haven't yet identified any visual difference between the real one and the fake one - both appear to have the same URL, nothing instantly recognisable to distinguish it as a phishing site.
So, a possible word of warning to those who bank with Nat West, and also a request for thoughts on tracing how this computer is linking through the correct URL to a scam site?
carmonk said:
You know it's the real NatWest site when it takes 5 minutes to move between pages...
Must be a malicious programme on his PC or following a phishing link, no other possibilities.
Well apart from a hosts file hijack, probably. If he's non tecchie get him to try to ping www.natwest.com from a command prompt (it won't actually ping) and note the IP address it returns on both machines. The legit one is 155.136.80.213 Must be a malicious programme on his PC or following a phishing link, no other possibilities.
I would hazard a guess at it being
http://www.theregister.co.uk/2008/10/31/sinowal_tr...
It runs a HTML injection in to the browser and asks for extra information such as ATM Pin, Social security number, mothers maiden name Etc.
http://www.theregister.co.uk/2008/10/31/sinowal_tr...
It runs a HTML injection in to the browser and asks for extra information such as ATM Pin, Social security number, mothers maiden name Etc.
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guaranteeThe situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guaranteeThe situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guaranteeThe situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
Davi said:
To the average technophobe they aren't exactly the most obvious of things to check either.
They may not be obvious but that is what they are there for. IMHO, if you can't be bothered to learn about the technology that you are using, i.e. basic stuff like checking that a site belongs to who it claims to belong to by looking at the certificate then perhaps you'd better stick to the high street.Furthermore, I have little sympathy for people that blindly dismiss warnings from their browser about SSL certificate problems without understanding what they are doing. The warnings are there for a reason; they are to protect you from things like site SSL certs not matching the request and therefore quite possibly not belonging to whom it claims.
There are many things that we can do to protect ourselves. Sadly, unlike the OP's mate, too many people just blindly type their details into any old form that is presented to them.
Strangely Brown said:
Stigmundfreud said:
Strangely Brown said:
Errr... this is what SSL certificates are for. Check the SSL cert presented by the fake site, if there is one, and you'll see that it's not the right one.
The situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
awww bless its good to think you still believe that but it is always a good starting point ONLY it is still no guaranteeThe situation does sound like a man in the middle attack where a trojan has modified the hosts file so requests to the correct FQDN get directed to the incorrect website.
If you are in any doubt at all, ALWAYS check the ssl certificate.
Strangely Brown said:
Davi said:
To the average technophobe they aren't exactly the most obvious of things to check either.
They may not be obvious but that is what they are there for. IMHO, if you can't be bothered to learn about the technology that you are using, i.e. basic stuff like checking that a site belongs to who it claims to belong to by looking at the certificate then perhaps you'd better stick to the high street.Furthermore, I have little sympathy for people that blindly dismiss warnings from their browser about SSL certificate problems without understanding what they are doing. The warnings are there for a reason; they are to protect you from things like site SSL certs not matching the request and therefore quite possibly not belonging to whom it claims.
There are many things that we can do to protect ourselves. Sadly, unlike the OP's mate, too many people just blindly type their details into any old form that is presented to them.
hondafanatic said:
Strangely Brown said:
OK, Mr. Condecending, please enlighten us as to how the attacker would forge an SSL certificate for Nat West and get it signed by Verisign, Thawte or any of the other major certificate issuers?
You don't need to forge one. Go Daddy.Please explain. This is clearly a gap in my understanding and I'd like to know.
Gassing Station | The Pie & Piston Archive | Top of Page | What's New | My Stuff



