Exploring Historical & Emerging Phishing Techniques

International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23

Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.

Adrian Lamo and FBI Cyber Squad computer scientist Russell Handorf

10/18/12 Update: 2006 posting at forum - where Russell Handorf still contributes using his "grey hat hacker" handle "satanklawz" - suggests he has been working for FBI three years earlier than his resume claims; Adrian Lamo admits being "friends" with Handorf but still won't answer any real questions; Chet Uber offers to have Lamo "interview" me - Neal Rauhauser, who claims he has nothing to.....
Netcat 1.10

Netcat 1.10=========== Netcat is a simple Unix utility which reads and writes dataacross network connections, using TCP or UDP protocol.It is designed to be a reliable "back-end" tool that canbe used directly or easily driven by other programs andscripts. At the same time, it is a feature-rich networkdebugging and exploration tool, since it can create almostany kind of connection you would need and has severalinteresting.....

Using a combination of trade tricks and clever programming, hackers have thoroughly compromised security at America Online, potentially exposing the personal information of AOL's 35 million users. The most recent exploit, launched last week, gave a hacker full access to Merlin, AOL's latest customer database application. As a security measure, Merlin runs only on AOL's internal network, but savvy hackers have found a way to.....
You Might Be from AOL if…

YOU MIGHT BE FROM AOL IF.... (a compiled list) ... If you ever once hid your phone bill from your parents. ... Someone says "I got TOS'd," and you know they don't mean their salad. ... If you knew Solarwinds had nothing to do with sun or weather patterns. ... You've seen some pretty disturbing sets of genitals.(and helped spread em) ... If you hated.....
About
JustinakaPaste.com is dedicated to my childhood from 1998-2005 - everything related to the AOL/AIM scene.  From AOL/AIM Progs, Exploits, Security Breaches, Hacks, Screen Names (leets, 2chars, 3chars, INTs, overheads, hosts, restricteds, indents), AOLers, AIMers, Employee Sections, AOL/AIM Articles & Tutorials, SecurID, Merlin, <M><, <><, Keyword Defacements, Old AOL Site Archives, Fallen AOL h4ckers (RIP), AOL Chat Logs, Macro Art, AOL Scam Sites, AOL Progs from.....
Hackers’ Excellent Adventures by William Bastone

HACKERS' EXCELLENT ADVENTURESBY WILLIAM BASTONEHow Underage Pranksters Ended Up in the Middle of an FBI Cybercrime Investigation With his baby face and doughy body, 17-year-old Joshua Gilson does not look like your typical FBI quarry. In fact, huddled over his Toshiba laptop, with rock music blaring from his bedroom stereo and Jerry Springer flickering on the TV, the Sheepshead Bay resident looks like any other teenager, albeit one.....
Digital5k.com

aol progz… a digital throw back to AOL, 1995.

one of the main reasons that i decided to recreate my digital5k.com website was the constant memories of the AOL progz days.  i won’t lie, there are redundant reminders of my AOL/visual basic (vb)/C++ childhood.  it was a great time in life and the internet, if you ask me.  let’s start off by how it all caught my attention and obsession… ascii art – which doomed my future and solidified my career in computers, programming, development and marketing.

2014-10-25 10_14_23-aol progz… a digital throw back to AOL, 1995.

yep, ascii art was the one little element that attack my attention span and made me say ‘whoa, that’s pretty cool’.  better known in those days as scrollers or macros.  a macro is simple font characters put together to form a type of pre-digital art.  i’ll never forget the first time i signed into AOL and say that beautiful scroll ascii art by ao-hell.

AOHellSplashScreen (1)

i was in 6th grade.  who knows how old i was, i don’t feel like doing the math.  i had just moved to the hell hole known as _____ from Houston, Texas.  i had no friends.  i knew nobody.  i just wanted to go home.  since Texas schools let out a few weeks earlier, i had some time to kill.  a very dangerous thing for a teenager.  what is a borderline anti social teen to do in a city with no friends?  go on the internet with the elite speed of 56 bits per second.

for those of us who remember, AOL was very… fucked.  the horrible chatrooms, stupid interface, laggy system and overall confusing nature, yet – it’s all we had.  the internet was a different place back in 1995.  images of a woman’s breasts were downloaded one pixel line at a time.  often stopping right above the nipple or right below the belly button.  there were no scams, very little spam, limited advertising and an innocence that can never be restored.  the internet was the preacher’s virgin daughter that was just getting ready to leave home, go off to college and get fucked, hard.

it took 3-4 attempts to connect to AOL back then, i would go on to later know the swift backdoor, alternate numbers and general brute force attacks that would prioritize my place in dial up line.  once you gained a stable connection, it was a release of endorphins that no drug has been able to reignite in my brain.  it was instant freedom.  no reality, no physical or gravitational limits, nobody to answer to.  it was an open digital playground with visual basic as monkey bars and the rush of adrenaline for swings.  it was a beautiful feeling for a child at the age of 12 with no real world experience.

finally,  you’re logged into AOL and you’re at the horrible start screen.  let’s go to a chatroom and see what’s popping.  ASL?  remember that?  jesus christ, why do i?  i must have been in a basketball related chatroom when i saw the very thing that would literally go on to change my life.  for the best.  a fucking scrolling advertisement for an aol prog known as ao-hell in an ascii format.

when i saw the 2 line scroll in a basketball chatroom i was first intrigued and then a bit shocked.  my initial thought was, what the hell is this?  i had no idea what it was, but i knew i needed it.  i needed to own it.  i needed to download it.  i needed to run this application.  just by the name, i knew it was something i would appreciate.
aol25_940x700-300x211

i started to IM the person who had ran this ao-hell prog.  the username?  that, too i will never forget – da chronic.

after 10-20 ignored IM’s i finally got an email.  a bit confused, i checked out the email.  it was blank.  cocksucker.  but wait, there’s an attachment?  aohell32.exe?  this must be the prog i’ve seen advertised.  without caution, i download and run it… and with that, my career choice is altered in a very dramatic way.

wait, a tool that i can use to flood emails? scroll and flood chatrooms?  boot people offline and cause all kinds of general hell and annoyances?  this is what i want.  this is what i need – this is what i want to make.  however, before i even thought about how/what it took to make one, i needed to study them all.  i cannot honestly tell you how many hours i spent in my bedroom over the next 2 years downloading, running, studying and then networking with the AOL progs and their programmers.  a few huge ones stick out for some reason for me;gothic nightmares, fate zero, millennium, pepsi, havok, ao-hell and the prophecy trilogy by unab0mber.

Star Tool AOL 2.5/3.0 16 bit

Date 1996Founded Unknown, Hexed and Released by Mad MiserySubmitted By O0OSource AOL-Files.com/FDO-Files.com Archive This was a huge discovery for PC AOLers. Up until this point PCers were unable to do the things Mac hax0rs were able to with their version of the Star Tool, called Utilities. The Star tool for 16 bit AOL clients came with a limited Atomic Debugger and an invoker for f1 tokens. Within weeks of.....
NY teen hacks AOL, infects systems

A New York teenager broke into AOL networks and databases containing customer information and infected servers with a malicious program to transfer confidential data to his computer, AOL and the Manhattan District Attorney's Office allege. In a complaint filed in Criminal Court of the City of New York, the DA's office alleges that between December 24, 2006 and April 7, 2007, 17-year old Mike Nieves.....
U.S. Teen Hacks AOL, Infects Systems | PCWorld

A New York teenager broke into AOL LLC networks and databases containing customer information and infected servers with a malicious program to transfer confidential data to his computer, AOL and the Manhattan District Attorney's Office allege. In a complaint filed in Criminal Court of the City of New York, the DA's office alleges that, between December 24, 2006 and April 7, 2007, 17-year old Mike.....