Exploring Historical & Emerging Phishing Techniques

International Journal of Network Security & Its Applications (IJNSA), Vol.5, No.4, July 2013
DOI : 10.5121/ijnsa.2013.5402 23

Marc A. Rader1 and Syed (Shawon) M. Rahman2, *
1CapellaUniversity, Minneapolis, MN, USA and Associate Faculty, Cochise CollegeAZ, USA
Mrader3@CapellaUniversity.edu
Associate Professor of Computer Science at the University of Hawaii-Hilo, Hawaii,
USA and Part-time Faculty at Capella University, Minneapolis, USA
*SRahman@hawaii.edu
ABSTRACT
Organizations invest heavily in technical controls for their Information Assurance (IA) infrastructure.
These technical controls mitigate and reduce the risk of damage caused by outsider attacks. Most
organizations rely on training to mitigate and reduce risk of non-technical attacks such as social
engineering. Organizations lump IA training into small modules that personnel typically rush through
because the training programs lack enough depth and creativity to keep a trainee engaged. The key to
retaining knowledge is making the information memorable. This paper describes common and emerging
attack vectors and how to lower and mitigate the associated risks.
KEY WORDS
Security Risks, Phishing, Social Engineering, Cross Site Scripting, Emerging Attack Vectors, DNS poising.
1. INTRODUCTION
Phishing is a social engineering technique that is used to bypass technical controls implemented
to mitigate security risks in information systems. People are the weakest link in any security
program. Phishing capitalizes on this weakness and exploits human nature in order to gain access
to a system or to defraud a person of their assets.

Adrian Lamo

img-article-shenon-adrian-lamo_075825934724-300x199

Inverview taken on: 1/12/01

What are your current AIM screen names? Line Trace
What is your e-mail address? adrian@adrian.org
Do you have a web site? inside-aol.com, terrorists.net, securid.org
What is your real name? Adrian Lamo. . if you want to be technical, its the Doctor Reverend Adrian A. Lamo, Ph.D . . Doctor of Divinity and minister through the Universal Life Church, the grandma of all diploma mills everywhere. . .i don’t take those seriously, and don’t expect anyone else to, but i put them on my resume and my business cards to make a point of my disdain for the certification and educational process.
Where do you live? i move around alot .. i like to travel, and have lived on both coasts, and spent a couple years in south america. . i’m in transit right now. . but am based out of San Francisco.
How old are you? 19
What are your hobbies? i like to break and explore. breaking things is integral to the progression of technology. . people accuse me of being directionless, but i think its important to drop dynamite into the pond sometimes, to see what floats up. in my copious free time, i like to explore abandoned buildings and sewer systems, as well as exploring occupied buildings – its amazing how many security guards will escort you up to the roof of a skyscraper if you only ask, or won’t even stop you if you look like you know where you’re going. . urban exploration is definitely a big passtime. one of the reasons i like to travel, too., i used to be involved in local activism and whatnot. . worked with the city government, stuff like that. . i’m massively disinterested in politics now though.
How would you describe your physical appearance? scrawny geek ; )
What do you hope to do as a profession? same as i do now. . short term, interesting contracts for worthwhile places. i’ve been working since i was 16, and have run through a pretty big variety of jobs and contracts. . most of them designed to be short term .. i did a 3 month security audit for a fortune 500 company once, that was probably the most interesting. . but i’ve worked for everything from nonprofits to law firms to private investigation firms. . i set up a Netzero account for one of kevin mitnick’s former attorneys at one of them, of all the ironic things. . thats the sort of thing i want to keep doing. i don’t want to be stuck behind the same desk all my life, working at the same place until i have too much invested in what i’m doing to be able to do anything to risk it.
How long have you been on AOL? used the service briefly when i was younger, when it was known as Quantum Link, and i was playing around with my commodore 64. . but i didn’t start to really use it til the mid-90’s. . i used AOL 1.6 for DOS/GeoWorks for the longest time, and actively resisted going over to the Windows version until they started disabling features one by one. .they eventually sunsetted it altogether in June of 1999. So. .something like 7 or 8 years now.
How much time do you think you spend online each day? it varies. . .depending on where i am and what i’m doing. sometimes, if i’m interested in something, i’ll spend days online nonstop. . sometimes i’ll spend days without touching a computer. on a really average day, anywhere between 4 and 12 hours ;x
What programming languages are you familiar with? i don’t really program. the only languages i’ve worked with are x86 assembler and OPL for the EPOC16 palmtop OS.
What do you spend most of your time online doing? breaking and exploring -=)
Who are your good friends online? They know who they are.

Glue³.bas

— ——• Glue³.bas by méèh •—— — 'This is My Seventh Module 'The biggest bas ever made....1306 Subs and Functions '--If you make any programs with this please 'email them to me i would like to see them-- '--AND, If You Have Any Ideas For My Next Bas 'Or Suggestions, and Comments, or Errors Email Me-- '!-#* If you have a web site please post.....

**>> FEDERATION GREETER'S GUIDE 96.09.30 TOS SECTION

HOW TO DEAL WITH TOS PROBLEMS

It's a sad fact that part of your job is to act as a Fed Cop and stop people
from offending against TOS or the Federation Policy. Greeters are the first
line of action when someone starts misbehaving, and, except in very serious
cases or when you are very busy, generally Hosts won't intervene until you
ask them to bump or lock someone.

Please do not be afraid to pass a problem player to a Host to deal with. If
you give someone a TOS warning, and they ignore it, there's usually not much
point giving them another warning - they need to be bumped out of the game as
a wake-up call, or locked out completely.
Netcat 1.10

Netcat 1.10=========== Netcat is a simple Unix utility which reads and writes dataacross network connections, using TCP or UDP protocol.It is designed to be a reliable "back-end" tool that canbe used directly or easily driven by other programs andscripts. At the same time, it is a feature-rich networkdebugging and exploration tool, since it can create almostany kind of connection you would need and has severalinteresting.....

 

[Disclaimer]

 

–==LEET LINK AdvancedAccess Absolute Edition==–

This is FREE Software!

Author: c4rn3vil/NeophytesnVisualBasiX/Chris

Completed: September 24th – 2004

 

:—This MIGHT* work for DIALUP USERS – one of my buddies’ is using dialup and it worked for him, but however for the longterm extension …This DOES NOT work for DIALUP users!’

 

This is now fully equiped/ (coded internal with mstcp/ip+winsock/lan, data flows)

It runs now with a EVEN More sufficient encryption.

I’ve added a MP3 Player, [Tight]

I also Plugged in a ‘POPUP Blocker’ You’ll atleast need to have the screen open, ‘POPUP BLOCKER’ atleast.

You may minimize the pop up blocker. to leave the hastle of it getting infront of you.

This is the last Version of the LEET LINKS I’m doing!

I hope you enjoy this fine release by c4rn3vil/neophytesnvisualbasix/Chris.

 

 

 

Note: known error is that when you attempt to load proxies and you do not load them, it’ll call an arguement and program will fail, just reoping the program and do load the proxies, that’s what this program is for!


BBBBB HH tt LL
BB B HH TTTT LL
BB B HH tt LL
BB BB UU UU SSS CCCCC HHHHHH TT RR RR OOOO MM MM MMM MM MM MMM EEE LL
BB B UU UU SS CC HH HH tt RR R OO OO MMM MMM MM MMM MMM MM E E LL
BB B UU UU SS CC HH HH TT RRR OO OO MM MM MM MM MM MM EEE LL
BBBBB UUUU SSS CCCCC HH HH TT RR OOOO MM MM MM MM MM MM EEEE LL

 

111 222
1 11 2 2
11 2
11* 22222

 

Buschtrommel 1.2
Written by Natok

 

Dieses Programm dient nicht zu Aufklärungszwecken da sich sowieso keiner
dran hält und es sowieso keinen interessiert bis es zu einer Masseninfektion
sprich Seuche kommt. Wer dieses Programm benutzt zu illegalen Zwecken muss
mit den entsprechen Konsequenzen wie rechtliche Verfolgung rechnen.

Mark Zuckerberg AOL Programmer?

Hi, my name is…Slim Shady. No, really, my name is Slim Shady. Just kidding, my name is Mark (for those of you that don’t know me) and I live in a small town near the massive city of New York. I am currently 15 years old and I just finished freshman year in high school. I have remodeled this website in an attempt that perhaps some search engine will recognize it. I am trying to promote my new AOL Program, The Vader Fader, which you can download elsewhere on this site. It is a decent fader. If you have any comments about this website, the java applets on it, or the Vader Fader which I am trying to promote, please contact me. My E-Mail address is at the bottom of this page.

 

E-Mail: Themarke51@aol.com