āļ¸āļ¸ āļ§āˇāļāļāļ§ āļāļŊāˇāļąāˇ āļ§āˇāˇāˇāļ§āˇ āļāļŊ⎠OTP āļāļ resend āļāļģāļąāˇāļą āļāˇāļēāļŊ⎠āļ´āļģāļą OTP āļāļ āļ´āˇāˇāˇāļ āˇāļ ⎠āļāļģāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇāļ¯ āļļāļŊāļąāˇāļą, āļāļ āˇāˇāļŠ āļąāˇ (āļ¯āˇāļąāˇ āˇāļ¯āļŊāļ¯, āļāļŊāˇāļąāˇ āļāļŗāļąāˇāļ¸ āˇāˇāļŠ āļąāˇāļ¯āˇāļ¯ āļ¯āˇāļąāˇāļąāˇ āļąāˇ)oka thamayi godak phishing sites wada karana widiha.
user danne naha hack wela kiyana eka mokak hari suspicious deyak wenakan.
un credentials save kara gannawa otp ahanne nathi site wala nam + cookies - cookies thibbama otp ahana ida aduyi gmail wage ekaka unath kalin log una cookies etc & sitedata thiyena nisa
original site eke otp ahana step ekata dala athi mama combank use karala naha 7 years walin.
kohomath un aniwa original site eke otp ahana thanak saka nohithenna ganna set karagena athi.
samahara bank wala otp ahanne naha lankawe sign in weddi & transaction eka karaddi ahanneth naha ,
eth transactions karanna kalin adala recipient register karanna ona ethanadi otp ekak ahanawa.
pretty much yes.User goes to the fake site --> Enters username/password --> This triggers the attacker to login to the real site with these credentials and initiates a transaction which sends OTP to customer --> Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.
So the above is the most probably mode of attack right?
OW OTP EKA valid wena time eka max thiyagena karanawa athi,āļ¸āļ¸ āļ§āˇāļāļāļ§ āļāļŊāˇāļąāˇ āļ§āˇāˇāˇāļ§āˇ āļāļŊ⎠OTP āļāļ resend āļāļģāļąāˇāļą āļāˇāļēāļŊ⎠āļ´āļģāļą OTP āļāļ āļ´āˇāˇāˇāļ āˇāļ ⎠āļāļģāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇāļ¯ āļļāļŊāļąāˇāļą, āļāļ āˇāˇāļŠ āļąāˇ (āļ¯āˇāļąāˇ āˇāļ¯āļŊāļ¯, āļāļŊāˇāļąāˇ āļāļŗāļąāˇāļ¸ āˇāˇāļŠ āļąāˇāļ¯āˇāļ¯ āļ¯āˇāļąāˇāļąāˇ āļąāˇ)
āļ¸āļ§ āˇāˇāļāˇāļąāˇāļąāˇ āļāļąāˇ login āļāļāļ§ OTP āļāļ āļ¯āˇāļŊ āļāļāˇāļąāˇ OTP āļāļ āļļāˇāļą āˇāˇāļąāˇ āļāļāļ⎠āļāļģāļąāˇāļąāˇ. āļāˇāˇāļ¸ āļāļąāˇāļ¸ āļ āļģāˇāļ§ āˇāˇāļ āˇāˇāļāˇāļąāˇāļ⎠āļāļāˇāļąāˇ āļļāļąāˇ, āˇāļŊāˇāļŊ⎠āļ§āˇāļ āļāˇāļē⎠āļāˇāļēāļŊ⎠message āļāļ āļāˇāļ¸ āļāļ¸āˇ āļģāļāˇāˇāˇāļąāˇāļąāˇ.
I don't think government is responsible for this type of things. This is scamming users and this is a global problem. Only way to fight is to educate people and the bank has to play a bigger role to protect their customers and Implement more security measures on their websites/apps. Most of these problems are because of poor design decisions made by banks. For an example, If the bank uses only .lk webiste then it is hard to do a homoglyph attack, because nic.lk validates this and reject such.OW OTP EKA valid wena time eka max thiyagena karanawa athi,
anith eka samahra welawata bank walin ena sms delay wela enawa , samahara bank wala
āļŊāļāļāˇāˇāˇ āļāļŗāļąāˇ āļ´āˇāļ§ āļģāļ§āļ§ āˇāļŊāˇāļŊ⎠āļēāˇāļąāˇāļą āļļāˇāˇāˇ .
track āļāļģāļąāˇāļą & āļāˇāļŊāˇāļ¸ report āļāļģāˇāļ⎠āļļāˇāļģ⎠āļāļ¸āļāˇāļ⎠āļąāˇāˇāˇ āļ āļŊāˇāļŊāļąāˇāļą āļāļģāļ´āˇ āļāļąāˇ .
card āˇāļŊāļ⎠āļŊāˇāļ¸āˇāļ§āˇ āļāˇāļēāˇāļąāˇāˇ + card payment reverse āļāļģāļąāˇāļą āļ´āˇāˇ āˇāˇāļąāˇ ,
āļ⎠āļāļą āļąāˇāˇāˇ āļ´āˇāļē āļāļĢāļąāˇ call āļāļ⎠line āļāļ⎠āļāˇāļēāˇāļāˇāļą āļāļąāˇāļąāˇ āļļāļēāˇāļ§āˇ āļāļģāļąāˇāļą ez cash āˇāˇāļģ⎠, āļ āļ¯ āˇāˇāļąāļāļąāˇ āļ āļŊāˇāļŊāļŊ āļāˇāļēāˇāļąāˇāļ¯
āļ⎠āļāļģāļąāˇāļą āļāļ¸āļē⎠āļģāļĸāļēāļ⎠āļāļąāˇāļąāˇ . āļģāļĸāļē āļ⎠āļāļģāļąāˇāļą āļāļą āˇāˇāļ¯āˇāˇāļ§ āˇāļ¯āļąāˇāļą āļāļ¸āļē⎠āļ āˇāˇāļģāˇāļ¯āˇ 5 āļāļ§ āļ´āˇāļģāļ⎠225+1 āļ⎠āļēāˇāļąāˇāļąāˇ āļ¯āˇāļąāˇ āļāļąāˇāļą āļāļąāˇāļ⎠āļāļāļē⎠āļāˇāˇāˇāļģ āļāļŗāļ´āˇ āļāļąāˇāļ⎠āļāļāļē⎠āļāļąāˇāļ⎠āļĸāˇāļļ⎠āļāļ āļāļģāļąāˇāļąāˇ āļąāˇāˇāˇ 225+1 āļāˇāļŊāļāļąāˇāļąāˇ āļ§āˇāļ āļ¯āˇāļąāˇ āļāļąāˇāļą & āļ¸āˇ āˇāˇāļąāļāļąāˇ āļāļŗāļ´āˇ
scam wena eka kohmath nawaththanna baha ,I don't think government is responsible for this type of things. This is scamming users and this is a global problem. Only way to fight is to educate people and the bank has to play a bigger role to protect their customers and Implement more security measures on their websites/apps. Most of these problems are because of poor design decisions made by banks. For an example, If the bank uses only .lk webiste then it is hard to do a homoglyph attack, because nic.lk validates this and reject such.
90% of the time bank has to take the responsibility rest of the 10% is regularity bodies such as CBSL.
There is a CBSL guideline for financial apps and websites. It is very comprehensive and covers many areas. But, banks are not adopting it 100% due to various reasons. In some cases, the bankâs Board of Directors decides not to fully follow the CBSL guideline, and the BOD takes the responsibility if a scam occurs as a result of their decision. CBSL and LankaPay also work with third-party cybersecurity companies, so it doesnât matter if CBSL itself does not have all the expertise.scam wena eka kohmath nawaththanna baha ,
eth lankawe adu karanna ona dewal wath karanne naha
mage point eka - government(+cbls) ekata karanna puluwan dewal tikak thiyenawa unge power walin e dewal wath mun karanne naha ,
wadiyenma wena justpay otp scam eka , balen account walata obapu ekak nisa wenne , optout wenna ahuwama bank eken un danneth naha karana widiha.
There is a CBSL guideline for financial apps and websites. It is very comprehensive and covers many areas. But, banks are not adopting it 100% due to various reasons. In some cases, the bankâs Board of Directors decides not to fully follow the CBSL guideline, and the BOD takes the responsibility if a scam occurs as a result of their decision. CBSL and LankaPay also work with third-party cybersecurity companies, so it doesnât matter if CBSL itself does not have all the expertise.
That is why I say that 90% of the responsibility still lies with the banks. If they truly want to fight this, they can do a far better job. However, almost all banks tend to look for the cheapest possible solution to any problem.
Mokadda solution eka?The same goes for JustPay. CBSL and LankaPay have already provided a solution for it, but banks were initially slow to adopt it. I think most banks have now implemented it, which is why JustPay related scams are rare today.
ow eka thamayi mama kiwwethMost of these scams are not run by Sri Lankans, so it does not matter what rules and regulations we have here in Sri Lanka.
Justpay is a payment platform that works across different banks, and the account holding bank has the ability to reject/accept these transaction, so if the bank wants, they can implement opt out feature (enable by default, disable by default etc). Different banks may have different solutions for this, some banks enabled this by default that is the root cause of all the problems.Mokadda solution eka?
saralama solution ekak thiyenawa - opt out wena eka , ehema karanna puluwanda danta???
Justpay is a payment platform that works across different banks, and the account holding bank has the ability to reject/accept these transaction, so if the bank wants, they can implement opt out feature (enable by default, disable by default etc). Different banks may have different solutions for this, some banks enabled this by default that is the root cause of all the problems.
This is like banks implementing an insecure payment gateway and people asking from the government/CBSL why this is happening?
spoof email ekak gmail inbox awada spam warning ekak netiwa? spf,dkim validate wela da? pudumai block une ne kiwwama. puluwan nam email header eke details tika dapan machan.Yako mata giya sathiye awa [email protected] eken account ussana phishing link ekak.. gmail eke inbox deliver una..
pretty much yes.
there are some other practicle tricks to get both login otp and transaction otp from the user.
User goes to the fake site > Enter credentials > triggers the attacker to login with credentials > user gets the otp > submits the otp > attacker gets the otp but the take site take a long time to submit the otp/keep showing the loading screen (this is a deliberate by the attacker) > attacker login with the otp > immediately start a transaction( usually a new transaction otp says this is for a transaction, so most likely the attacker can add his account as a registered account in the portal *more details at the end of the post) > the the fake site says your otp is incorrect and submit the new otp sent (the new otp is the transaction or new account add otp) > user submits it and game over.
other thing is some banking apps does not allow login from two different locations(two login sessions), if an attacker take over an account and keep using it, the real user has no way of login to the account until the attacker logs out. I think banks have disabled multiple login attempts as a security mechanism, but it could work in favor of the attacker.
*more details at the end of the post
about this. Attacker never gets the money in to his own account. Attacker always has few contacts with shops (usually sellers from clarified sites, or facebook market place) they already have account numbers of some shops or sellers, and attacker transfer the money to those clueless sellers, they will send the item to the attacker. or there could be another layer (like a drop-shipping the item to someone else). It is very hard to track down the real attcker.
āļ⎠āļāļģāļąāˇāļą āļāļ¸āļē⎠āļģāļĸāļēāļ⎠āļāļąāˇāļąāˇ . āļģāļĸāļē āļ⎠āļāļģāļąāˇāļą āļāļą āˇāˇāļ¯āˇāˇāļ§ āˇāļ¯āļąāˇāļą āļāļ¸āļē⎠āļ āˇāˇāļģāˇāļ¯āˇ 5 āļāļ§ āļ´āˇāļģāļ⎠225+1 āļ⎠āļēāˇāļąāˇāļąāˇ āļ¯āˇāļąāˇ āļāļąāˇāļą āļāļąāˇāļ⎠āļāļāļē⎠āļāˇāˇāˇāļģ āļāļŗāļ´āˇ āļāļąāˇāļ⎠āļāļāļē⎠āļāļąāˇāļ⎠āļĸāˇāļļ⎠āļāļ āļāļģāļąāˇāļąāˇ āļąāˇāˇāˇ 225+1 āļāˇāļŊāļāļąāˇāļąāˇ āļ§āˇāļ āļ¯āˇāļąāˇ āļāļąāˇāļą & āļ¸āˇ āˇāˇāļąāļāļąāˇ āļāļŗāļ´āˇ
āļ¸āˇ āˇāˇāļŠāˇ āļāļģāļ¯āˇāļ¯āˇ user ⎠āļŠāˇāˇāļēāˇāˇāˇ āļ¯āˇāļāļāˇāļąāˇ āļŊāˇāļ⎠āˇāˇāļąāˇāļąāˇ āļąāˇāˇāˇāļąāˇcombank nam login wenakota otp request karanne neha. anyway, oya kiwwa wage phishing site ekedi loading wenawa kiyala dala OTP ganna eka try karanna puluwan. wede ehema nam oka realtime salli adina wede wennat one.
hebei mataka widihata munge multiple sessions allow karala neha. devices 2kin access karoth parana session eka logout wenawa. netnam keylogger ekak tiyenne one. ehema netnam mun cards walin adinawa wenna one. samahara ecommerec platform wala OTP request karannet nehane.
That's the point! mata amataka una user phishing site ekata log wela inne kiyala.āļ¸āˇ āˇāˇāļŠāˇ āļāļģāļ¯āˇāļ¯āˇ user ⎠āļŠāˇāˇāļēāˇāˇāˇ āļ¯āˇāļāļāˇāļąāˇ āļŊāˇāļ⎠āˇāˇāļąāˇāļąāˇ āļąāˇāˇāˇāļąāˇ
User āļŊāˇāļ⎠āˇāˇāļąāˇāļąāˇ āˇāˇāļ⎠āˇāļēāˇāļ§āˇ āļāļāļ§, scammer/hacker āļāļ¸āļē⎠real site āļāļāļ§ āļŊāˇāļ⎠āˇāˇāļąāˇāļąāˇ. āļāļāļāˇāļ§ āļāļ āļŊāˇāļāˇāļąāˇ āˇāˇāˇāļąāˇ āļāļāļē⎠āļāˇāļēāˇāļąāˇāļąāˇ
āˇāˇāļļāˇāļē⎠āļ¯āˇāļąāˇ āˇāˇāļ¸ āļļāˇāļāļāˇāˇāˇāļ¸ āļŊāˇāļ⎠āļāļąāˇāļ§ āļ´āˇāˇāˇāˇ āļēāˇāˇāļģāˇāļ§ SMS āļāļāļ⎠āļēāļąāˇāˇ, āļāļ⎠āļēāˇāˇāļģ⎠fake site āļāļāļ§ āļŊāˇāļ⎠āˇāˇāļąāˇāļą āˇāļ¯āļą āļąāˇāˇāˇ āļ SMS āļāļāļ⎠ignore āļāļģāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇ.
āļ¸āˇāļ āļģāˇāļēāļŊ⎠āļ§āļēāˇāļ¸āˇ āˇāˇāļąāˇāļą āļāļąāļ⎠āļąāˇāˇāˇ, āˇāˇāļŊ⎠āļ´āˇāļ⎠āļāļ automate āļāļģāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇ āļąāˇ. āļāļāļāˇāļ§ āļāˇāļē⎠āˇāˇāļŊ⎠āļ¸āˇāļą āļēāˇāˇāļģ⎠āļŊāˇāļ⎠āļāļąāļ⎠pre-define āļāļģāļŊ⎠āļāˇāļēāļą automation āļāļ āļģāļąāˇ āˇāˇāļŊ⎠user āļ⎠account āļāļ āˇāˇāˇāˇ āļāļģāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇ.
āˇāˇāˇāˇāļąāˇ āˇāļēāˇāļ§āˇ āļāļāļ§ āļāļąāļ⎠āļļāļąāˇ lets encrypt āˇāļ⎠āļāļāļāˇāļąāˇ ssl āļāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇ āļąāˇ. āļāļ āļąāˇāˇāˇ āļ¸āˇ āˇāļ⎠āļāļāļāļ§ āˇāˇāļŗāļ§āļ¸ āļ¯āļąāˇāļą āļāļāˇāļ⎠āļāļąāļ⎠āļ āˇāˇ āˇāˇāļąāˇāļą āļ´āˇāļŊāˇāˇāļąāˇThat's the point! mata amataka una user phishing site ekata log wela inne kiyala.
mehe nam itin minissu danne neti nisa godak ahu wenne. Ape un SSL neti unath click karala yanawane.
. Website log āˇāˇāļąāˇāļą āˇāˇāļąāˇāˇ āļāˇāļē āļ¸āˇāˇāˇāļ⎠log āļāļąāˇ. āļāļąāˇ āļāļē āˇāˇāļą website āļāļāˇāˇ āļ¯āˇāļąāˇ āļāˇāļŊāļēāļ⎠āļāˇāˇāˇāˇāˇ āļāˇāļēāļą āļąāˇāˇāˇ āļ¯āˇāļ´āˇāļģāļ⎠āˇāˇāļāļģ āļļāļŊāļŊ⎠log āˇāˇāļąāˇāļąāˇ. āļāļ⎠āˇāˇāˇāļģ⎠āļąāˇ āļ¯āˇāļąāˇāļąāļ¸āˇ āļ¸āļ§..