Cyber security ඉස්කොල වල 9 වසරෙ ඉන්දන් පොඩ්ඩ පොඩ්ඩ ඉගැන්නුවා නම් හරි ප්රෙව්සම් වෙන විදි ගැන, ඊට පස්සෙ උන්ගෙ අම්මලා තාත්තාලා ආච්චි සීයාලා ට කියලා දෙන්න බැරියෑ
Oken wena bank credit card payment ekak karanna puluwan da? Ba..iOS ද උඹ කියන්නෙ? Android එකේ නම් කිසිම අවුලක් නෑ.
Google eke welawakata phishing sites "Sponsored" enawa eka click wela yanne
anith widiha Ukrain un dennek kalin alluwe TV pennuwe Samapath eka widihata fb eke Sponsored ads dala ,
ko allapu un dennata labuna danduwama mokadda??????????? Thama naduwa yanawada ?
ohoma neme AliExpress Sponsored ekatath google ad awith search result eke case wela thibba wena rata wala godak ,
oya serama gana dana ganna thiyenneth Meta,Google deka
e nisa un haraha , Meta,google sponsored ad haraha duwana scam gana danuwath karana posts trend wenawa aduyi .
Jeewitheta lankawe kisima app ekak danne na..
මොකාද බං website ගාණෙ ලගුල්ලන්ඩ යන්නෙ app එක තියෙද්දි? හුත්ත තමා
meka mchn oya danagatthe kohomada? Meka wennanm ba. Commercial Bank eka kiyanne PCI DSS certified bank ekak. Ekedi check wenawa mewa,Esoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.
Google eke welawakata phishing sites "Sponsored" enawa eka click wela yanne
anith widiha Ukrain un dennek kalin alluwe TV pennuwe Samapath eka widihata fb eke Sponsored ads dala ,
ko allapu un dennata labuna danduwama mokadda??????????? Thama naduwa yanawada ?
ohoma neme AliExpress Sponsored ekatath google ad awith search result eke case wela thibba wena rata wala godak ,
oya serama gana dana ganna thiyenneth Meta,Google deka
e nisa un haraha , Meta,google sponsored ad haraha duwana scam gana danuwath karana posts trend wenawa aduyi .
Esoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.
meka kohomada mchn verify karagatthe? check kranna widiyak tiyenawada?මේක ඇත්ත සීන් එකක්
Plain text තියාගන්නවා මදිවට බැංකු වැඩකරන උන්ට බලන්න ඇක්සස් තියනවා
මේක සිරා, මම කලින් එළකිරි එකේම දාලා තියෙනවා. මම auto generated password එකක් දැම්මා characters 20ක් විතර තියෙන. මුන්ගේ උපරිම 12ක් හරි 16ක් හරි ගන්නේ. හරිනම් error message එකක් පෙන්නන ඕනේ. මුන් එක error එකක් පෙන්නනේ නැතුවම characters 16කට අඩු කරලා save කරලා. මම characters 20 ම දාලා බලනවා, password එක වැරදියි කියනවා. customer support කතා කලාම password එකේ මුල characters ටික support හිටපු බුවා කිව්වාEsoft එකේ cyber security diploma කරපු එකෙක්ද කොහෙද ඔකේ system එක කරලා තියෙන්නේ. මන් කලිනුත් thread එකක් දැම්ම පක්කු account එක හදපු දවසේ ඉදන් use කරන passwords text form එකෙන් තියාගෙන ඉන්නවා කියල. ඕකේ සල්ලි විතරක් නෙමෙයි එකම password එක use කරලා තියෙන අනිත් accounts වලටත් ෂොට් එක හම්බවෙනවා.
https://www.combank.lk/digitalbanking/
methanama domain 3k thiyenwa
combank.lk ekai
combankdigital.com ekai
commercialbk.com ekai
subdomain hadanna danne nadda mnda mun.
So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?com bank uses .com domain so it is very easy to do a homoglyph attack.
attacker get a look alike domain and clone the actual combank online website, even a cautious person could fall for this type of attack.
attacker get the username and password and as soon as a user try to login, the the attcker gets credentials and the he tries them in the actual site, then the user gets the otp and enters it on the fake site, then attacker get the otp and enters it on the actual site.
since com bank uses a .com domain, this is so easy to pull off.
attacker has to do this real time, but it is technically possible to automate the whole thing.
Either way the above attack works. Because the user’s session is always with the fake site and attacker’s session is with the com bank site. Fake site is just to transfer data to the attacker.So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?
oka aluth deyak neme awurudu ganak parana prashanayak google results & gmail eke udama ena sponsored ad patalenawa athhta results or emails wage enne. owa nisa una scams gana articles posts dakala athi,ලංකාවෙ cybercrime prosecute කරන්න knowledge/skills නෑ බන්. ඒවා කතා කරලා වැඩක් නෑ. ඔහොම industry එක දියුනුවෙන්න තරම් කාලයක් ලංකාවෙ මිනිස්සු තියන් ඉන්න බෑ.
ඔහොම sponsored එනවා කියන්නෙ පට්ට අවුල්නෙ බන්.
unta ona naha unge mistakes gana search eke udata ewannasession based unath ,So you saying that the OTP isn't session based but is just time based. So if the attacker can get the OTP and use it within the valid time period the malicious transaction will go through?
issara combank online google karama mulata awe australia wage rataka same name thiyena bank ekaka site ekak.com bank uses .com domain so it is very easy to do a homoglyph attack.
attacker get a look alike domain and clone the actual combank online website, even a cautious person could fall for this type of attack.
attacker get the username and password and as soon as a user try to login, the the attcker gets credentials and the he tries them in the actual site, then the user gets the otp and enters it on the fake site, then attacker get the otp and enters it on the actual site.
since com bank uses a .com domain, this is so easy to pull off.
attacker has to do this real time, but it is technically possible to automate the whole thing.
oka aluth deyak neme awurudu ganak parana prashanayak google results & gmail eke udama ena sponsored ad patalenawa athhta results or emails wage enne. owa nisa una scams gana articles posts dakala athi,
eth ewa search karala hoyanna lesi naha
search eka handle karanne scam ad dana ungen salli gaththa google ekenmaunta ona naha unge mistakes gana search eke udata ewanna
session based unath ,
phishing site eke unge server eke real site ekata sign in wenawa athi victim enter karana credentials & otp walin,
victim ta pennawa real site eken details aragena,
victim phishing site eke logout dunnma , log out una wage penawa, adala normal logout unama ena page ekath watenawa athi.
aththata logout wenne naha.
issara combank online google karama mulata awe australia wage rataka same name thiyena bank ekaka site ekak.
danuth unge .lk site eken digital bank select karala giyath .com sites dekakata yanna thiyenne
e yanan sites dekath online banking kiyana ekata wenama ekak digital bank kiyana ekata wenama ekak,
dekama mathaka hitina widihe ewath neme ona kenekta waradenna puluwan lesiyenma.
bank kiyana eka bk widihata short karala sammana denna ona url eka mokadda kiyana eka decide karapu unta
Either way the above attack works. Because the user’s session is always with the fake site and attacker’s session is with the com bank site. Fake site is just to transfer data to the attacker.
There is no session between the user and actual website.
oka thamayi godak phishing sites wada karana widiha.User goes to the fake site --> Enters username/password --> This triggers the attacker to login to the real site with these credentials and initiates a transaction which sends OTP to customer --> Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.
So the above is the most probably mode of attack right?
Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.