🔴commercial bank accounts āļ­āˇ’āļē⎙āļą āļ…āļē āļ´āļģāˇ’āˇƒāˇŠāˇƒāļ¸āˇ’āļąāˇŠđŸ”´

SimMaster

Well-known member
  • Dec 16, 2015
    9,867
    13,109
    113
    NTB, Sampath āˇ„āˇœāļ¯āļē⎒ āļšāˇ’āˇƒāˇ’ ⎀āļ¯āļēāļšāˇŠ āļąāˇ‘.
     
    • Haha
    Reactions: wqe123

    tharakaf

    Well-known member
  • Oct 19, 2020
    36,427
    75,143
    113
    oka thamayi godak phishing sites wada karana widiha.
    user danne naha hack wela kiyana eka mokak hari suspicious deyak wenakan.
    un credentials save kara gannawa otp ahanne nathi site wala nam + cookies - cookies thibbama otp ahana ida aduyi gmail wage ekaka unath kalin log una cookies etc & sitedata thiyena nisa



    original site eke otp ahana step ekata dala athi mama combank use karala naha 7 years walin.
    kohomath un aniwa original site eke otp ahana thanak saka nohithenna ganna set karagena athi.

    samahara bank wala otp ahanne naha lankawe sign in weddi & transaction eka karaddi ahanneth naha ,
    eth transactions karanna kalin adala recipient register karanna ona ethanadi otp ekak ahanawa.
    āļ¸āļ¸ āļ§āˇ’āļšāļšāļ§ āļšāļŊ⎒āļąāˇŠ āļ§āˇ™āˇƒāˇŠāļ§āˇŠ āļšāļŊāˇ OTP āļ‘āļš resend āļšāļģāļąāˇŠāļą āļšāˇ’āļēāļŊāˇ āļ´āļģāļą OTP āļ‘āļš āļ´āˇāˇ€āˇ’āļ āˇŠāļ āˇ’ āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠāļ¯ āļļāļŊāļąāˇŠāļą, āļ’āļš āˇ€āˇāļŠ āļąāˇ‘ (āļ¯āˇāļąāˇŠ ⎄āļ¯āļŊāļ¯, āļšāļŊ⎒āļąāˇŠ āļ‰āļŗāļąāˇŠāļ¸ āˇ€āˇāļŠ āļąāˇāļ¯āˇŠāļ¯ āļ¯āˇāļąāˇŠāļąāˇ™ āļąāˇ‘)

    āļ¸āļ§ āˇ„āˇ’āļ­āˇ™āļąāˇŠāļąāˇ™ āļ‹āļąāˇŠ login āļ‘āļšāļ§ OTP āļ‘āļš āļ¯āˇāļŊ āļ’āļšāˇ™āļąāˇŠ OTP āļ‘āļš āļļāˇāļą āˇƒāˇ“āļąāˇŠ āļ‘āļšāļšāˇŠ āļšāļģāļąāˇŠāļąāˇ™. āļ‘⎄⎙āļ¸ āļ‹āļąāˇāļ¸ āļ…āļģ⎖āļ§ āˇƒāˇāļš āˇ„āˇ’āļ­āˇ™āļąāˇ€āļ­āˇŠ āļ‡āļ­āˇ’āļąāˇ™ āļļāļąāˇŠ, ⎃āļŊ⎊āļŊ⎒ āļ§āˇ’āļš āļœāˇ’āļēāˇ āļšāˇ’āļēāļŊāˇ message āļ‘āļš āļ†āˇ€āļ¸ āļ­āļ¸āˇ āļģāļ­āˇŠāˇ€āˇ™āļąāˇŠāļąāˇ™.
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    User goes to the fake site --> Enters username/password --> This triggers the attacker to login to the real site with these credentials and initiates a transaction which sends OTP to customer --> Fake site has a additional login step to enter OTP --> Customer enters the OTP thinking it is to login to the site --> attacker uses the OTP to authorise the transaction on the real site.

    So the above is the most probably mode of attack right?
    pretty much yes.
    there are some other practicle tricks to get both login otp and transaction otp from the user.

    User goes to the fake site > Enter credentials > triggers the attacker to login with credentials > user gets the otp > submits the otp > attacker gets the otp but the take site take a long time to submit the otp/keep showing the loading screen (this is a deliberate by the attacker) > attacker login with the otp > immediately start a transaction( usually a new transaction otp says this is for a transaction, so most likely the attacker can add his account as a registered account in the portal *more details at the end of the post) > the the fake site says your otp is incorrect and submit the new otp sent (the new otp is the transaction or new account add otp) > user submits it and game over.

    other thing is some banking apps does not allow login from two different locations(two login sessions), if an attacker take over an account and keep using it, the real user has no way of login to the account until the attacker logs out. I think banks have disabled multiple login attempts as a security mechanism, but it could work in favor of the attacker.

    *more details at the end of the post
    about this. Attacker never gets the money in to his own account. Attacker always has few contacts with shops (usually sellers from clarified sites, or facebook market place) they already have account numbers of some shops or sellers, and attacker transfer the money to those clueless sellers, they will send the item to the attacker. or there could be another layer (like a drop-shipping the item to someone else). It is very hard to track down the real attcker.
     

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,168
    6,654
    113
    East Blue (Goa Kingdom)
    āļ¸āļ¸ āļ§āˇ’āļšāļšāļ§ āļšāļŊ⎒āļąāˇŠ āļ§āˇ™āˇƒāˇŠāļ§āˇŠ āļšāļŊāˇ OTP āļ‘āļš resend āļšāļģāļąāˇŠāļą āļšāˇ’āļēāļŊāˇ āļ´āļģāļą OTP āļ‘āļš āļ´āˇāˇ€āˇ’āļ āˇŠāļ āˇ’ āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠāļ¯ āļļāļŊāļąāˇŠāļą, āļ’āļš āˇ€āˇāļŠ āļąāˇ‘ (āļ¯āˇāļąāˇŠ ⎄āļ¯āļŊāļ¯, āļšāļŊ⎒āļąāˇŠ āļ‰āļŗāļąāˇŠāļ¸ āˇ€āˇāļŠ āļąāˇāļ¯āˇŠāļ¯ āļ¯āˇāļąāˇŠāļąāˇ™ āļąāˇ‘)

    āļ¸āļ§ āˇ„āˇ’āļ­āˇ™āļąāˇŠāļąāˇ™ āļ‹āļąāˇŠ login āļ‘āļšāļ§ OTP āļ‘āļš āļ¯āˇāļŊ āļ’āļšāˇ™āļąāˇŠ OTP āļ‘āļš āļļāˇāļą āˇƒāˇ“āļąāˇŠ āļ‘āļšāļšāˇŠ āļšāļģāļąāˇŠāļąāˇ™. āļ‘⎄⎙āļ¸ āļ‹āļąāˇāļ¸ āļ…āļģ⎖āļ§ āˇƒāˇāļš āˇ„āˇ’āļ­āˇ™āļąāˇ€āļ­āˇŠ āļ‡āļ­āˇ’āļąāˇ™ āļļāļąāˇŠ, ⎃āļŊ⎊āļŊ⎒ āļ§āˇ’āļš āļœāˇ’āļēāˇ āļšāˇ’āļēāļŊāˇ message āļ‘āļš āļ†āˇ€āļ¸ āļ­āļ¸āˇ āļģāļ­āˇŠāˇ€āˇ™āļąāˇŠāļąāˇ™.
    OW OTP EKA valid wena time eka max thiyagena karanawa athi,
    anith eka samahra welawata bank walin ena sms delay wela enawa , samahara bank wala

    āļŊāļ‚āļšāˇāˇ€āˇš āļ‰āļŗāļąāˇŠ āļ´āˇ’āļ§ āļģāļ§āļ§ āˇƒāļŊ⎊āļŊ⎒ āļē⎀āļąāˇŠāļą āļļ⎐⎄⎐ .
    track āļšāļģāļąāˇŠāļą & āļ‘⎀āļŊ⎚āļ¸ report āļšāļģ⎜āļ­āˇŠ āļļ⎐āļģ⎒ āļšāļ¸āļšāˇ”āļ­āˇŠ āļąāˇāˇ„⎐ āļ…āļŊ⎊āļŊāļąāˇŠāļą āļšāļģāļ´āˇ” āļ‹āļąāˇŠ .
    card ⎀āļŊāļ­āˇŠ āļŊ⎒āļ¸āˇ’āļ§āˇŠ āļ­āˇ’āļē⎙āļąāˇ€āˇ + card payment reverse āļšāļģāļąāˇŠāļą āļ´āˇ”⎅⎔⎀āļąāˇŠ ,
    āļ•⎀ āļ•āļą āļąāˇāˇ„⎐ āļ´āˇāļē āļœāļĢāļąāˇŠ call āļ‘āļšāˇš line āļ‘āļšāˇš āļ­āˇ’āļēāˇāļœāˇ™āļą āļ‰āļąāˇŠāļąāˇš āļļāļē⎒āļ§āˇŠ āļšāļģāļąāˇŠāļą ez cash āˇ„āˇœāļģ⎔ , āļ…āļ¯ āˇ€āˇ™āļąāļšāļąāˇŠ āļ…āļŊ⎊āļŊāļŊ āļ­āˇ’āļē⎙āļąāˇ€āļ¯

    āļ•⎀ āļšāļģāļąāˇŠāļą āļ­āļ¸āļē⎒ āļģāļĸāļēāļšāˇŠ āļ‰āļąāˇŠāļąāˇš . āļģāļĸāļē āļ•⎀ āļšāļģāļąāˇŠāļą āļ•āļą āˇ€āˇ’āļ¯āˇ’⎄āļ§ āˇ„āļ¯āļąāˇŠāļą āļ­āļ¸āļē⎒ āļ…⎀⎔āļģ⎔āļ¯āˇ” 5 āļšāļ§ āļ´āˇāļģāļšāˇŠ 225+1 āļšāˇŠ āļē⎀āļąāˇŠāļąāˇš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‰āˇƒāˇŠāˇƒāļģ āļ‰āļŗāļ´āˇ” āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‹āļąāˇŠāļœāˇš āļĸ⎜āļļ⎊ āļ‘āļš āļšāļģāļąāˇŠāļąāˇš āļąāˇāˇ„⎐ 225+1 āļšāˇāļŊāļšāļąāˇŠāļąāˇ’ āļ§āˇ’āļš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą & āļ¸āˇš ⎀⎙āļąāļšāļąāˇŠ āļ‰āļŗāļ´āˇ”
     
    • Like
    Reactions: tharakaf

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    OW OTP EKA valid wena time eka max thiyagena karanawa athi,
    anith eka samahra welawata bank walin ena sms delay wela enawa , samahara bank wala

    āļŊāļ‚āļšāˇāˇ€āˇš āļ‰āļŗāļąāˇŠ āļ´āˇ’āļ§ āļģāļ§āļ§ āˇƒāļŊ⎊āļŊ⎒ āļē⎀āļąāˇŠāļą āļļ⎐⎄⎐ .
    track āļšāļģāļąāˇŠāļą & āļ‘⎀āļŊ⎚āļ¸ report āļšāļģ⎜āļ­āˇŠ āļļ⎐āļģ⎒ āļšāļ¸āļšāˇ”āļ­āˇŠ āļąāˇāˇ„⎐ āļ…āļŊ⎊āļŊāļąāˇŠāļą āļšāļģāļ´āˇ” āļ‹āļąāˇŠ .
    card ⎀āļŊāļ­āˇŠ āļŊ⎒āļ¸āˇ’āļ§āˇŠ āļ­āˇ’āļē⎙āļąāˇ€āˇ + card payment reverse āļšāļģāļąāˇŠāļą āļ´āˇ”⎅⎔⎀āļąāˇŠ ,
    āļ•⎀ āļ•āļą āļąāˇāˇ„⎐ āļ´āˇāļē āļœāļĢāļąāˇŠ call āļ‘āļšāˇš line āļ‘āļšāˇš āļ­āˇ’āļēāˇāļœāˇ™āļą āļ‰āļąāˇŠāļąāˇš āļļāļē⎒āļ§āˇŠ āļšāļģāļąāˇŠāļą ez cash āˇ„āˇœāļģ⎔ , āļ…āļ¯ āˇ€āˇ™āļąāļšāļąāˇŠ āļ…āļŊ⎊āļŊāļŊ āļ­āˇ’āļē⎙āļąāˇ€āļ¯

    āļ•⎀ āļšāļģāļąāˇŠāļą āļ­āļ¸āļē⎒ āļģāļĸāļēāļšāˇŠ āļ‰āļąāˇŠāļąāˇš . āļģāļĸāļē āļ•⎀ āļšāļģāļąāˇŠāļą āļ•āļą āˇ€āˇ’āļ¯āˇ’⎄āļ§ āˇ„āļ¯āļąāˇŠāļą āļ­āļ¸āļē⎒ āļ…⎀⎔āļģ⎔āļ¯āˇ” 5 āļšāļ§ āļ´āˇāļģāļšāˇŠ 225+1 āļšāˇŠ āļē⎀āļąāˇŠāļąāˇš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‰āˇƒāˇŠāˇƒāļģ āļ‰āļŗāļ´āˇ” āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‹āļąāˇŠāļœāˇš āļĸ⎜āļļ⎊ āļ‘āļš āļšāļģāļąāˇŠāļąāˇš āļąāˇāˇ„⎐ 225+1 āļšāˇāļŊāļšāļąāˇŠāļąāˇ’ āļ§āˇ’āļš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą & āļ¸āˇš ⎀⎙āļąāļšāļąāˇŠ āļ‰āļŗāļ´āˇ”
    I don't think government is responsible for this type of things. This is scamming users and this is a global problem. Only way to fight is to educate people and the bank has to play a bigger role to protect their customers and Implement more security measures on their websites/apps. Most of these problems are because of poor design decisions made by banks. For an example, If the bank uses only .lk webiste then it is hard to do a homoglyph attack, because nic.lk validates this and reject such.
    90% of the time bank has to take the responsibility rest of the 10% is regularity bodies such as CBSL.
     
    • Like
    Reactions: animation

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,168
    6,654
    113
    East Blue (Goa Kingdom)
    I don't think government is responsible for this type of things. This is scamming users and this is a global problem. Only way to fight is to educate people and the bank has to play a bigger role to protect their customers and Implement more security measures on their websites/apps. Most of these problems are because of poor design decisions made by banks. For an example, If the bank uses only .lk webiste then it is hard to do a homoglyph attack, because nic.lk validates this and reject such.
    90% of the time bank has to take the responsibility rest of the 10% is regularity bodies such as CBSL.
    scam wena eka kohmath nawaththanna baha ,
    eth lankawe adu karanna ona dewal wath karanne naha

    mage point eka - government(+cbls) ekata karanna puluwan dewal tikak thiyenawa unge power walin e dewal wath mun karanne naha ,

    wadiyenma wena justpay otp scam eka , balen account walata obapu ekak nisa wenne , optout wenna ahuwama bank eken un danneth naha karana widiha.

    mewata cbsl & government thamayi waga kiyanna ona.

    lankawe OTP aniwaraya kiyana regulation ekak thiyenawa online site walata lankawe oparate wena cards waladi.

    lk ekata regulation bari una guide line ekak hari danna puluwan cbsl ekata , pal booru civil engineering etc karapu modayo hire karala pirila inne cbsl eka athule.



    lankawa athule wena scam track karanna action ganna ona . lesiyata atha pihida ganna balagena inna nikamo pirila inna adala than wala bahtuhajraya

    ahu una un Ukrainian un denna Sampath bank wage sponsored ads dapu
    ko un denna dan ,

    neethi madi kama 100% 225+1 waradda thamayi ahu wena un nidahas wenna
    thawa government eke responsibility ekak thamai hariyata chodana gonu karanna molayak thiyena un adala ayathana walata hire karana eka contact walata job nodi

    lankawe unuth scam karapu meegamuwe set eka pizza eken mattu una ko dan un ?
    bank account eka online job karanna gihin ahu una dennekge.
    ohoma ewata lankawe ona tharam un ahu wela thibba case giya - ewa pita rata scam walata lankawe onlinke job hoyana un ahu wela salli unge accounts walata ewala scam karana un.
     
    Last edited:

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    scam wena eka kohmath nawaththanna baha ,
    eth lankawe adu karanna ona dewal wath karanne naha

    mage point eka - government(+cbls) ekata karanna puluwan dewal tikak thiyenawa unge power walin e dewal wath mun karanne naha ,

    wadiyenma wena justpay otp scam eka , balen account walata obapu ekak nisa wenne , optout wenna ahuwama bank eken un danneth naha karana widiha.
    There is a CBSL guideline for financial apps and websites. It is very comprehensive and covers many areas. But, banks are not adopting it 100% due to various reasons. In some cases, the bank’s Board of Directors decides not to fully follow the CBSL guideline, and the BOD takes the responsibility if a scam occurs as a result of their decision. CBSL and LankaPay also work with third-party cybersecurity companies, so it doesn’t matter if CBSL itself does not have all the expertise.

    The same goes for JustPay. CBSL and LankaPay have already provided a solution for it, but banks were initially slow to adopt it. I think most banks have now implemented it, which is why JustPay related scams are rare today.

    That is why I say that 90% of the responsibility still lies with the banks. If they truly want to fight this, they can do a far better job. However, almost all banks tend to look for the cheapest possible solution to any problem.

    Most of these scams are not run by Sri Lankans, so it does not matter what rules and regulations we have here in Sri Lanka.
     

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,168
    6,654
    113
    East Blue (Goa Kingdom)
    There is a CBSL guideline for financial apps and websites. It is very comprehensive and covers many areas. But, banks are not adopting it 100% due to various reasons. In some cases, the bank’s Board of Directors decides not to fully follow the CBSL guideline, and the BOD takes the responsibility if a scam occurs as a result of their decision. CBSL and LankaPay also work with third-party cybersecurity companies, so it doesn’t matter if CBSL itself does not have all the expertise.
    That is why I say that 90% of the responsibility still lies with the banks. If they truly want to fight this, they can do a far better job. However, almost all banks tend to look for the cheapest possible solution to any problem.

    Cyber Security neme CBSL eke inna bahutharaya adalama nathi un CBSL eke anith responsibilities walata wath. bank self regulate wenakan inna baha gov ekak thiyenne pressure karanna thamayi. gov eke administrate karanna ina 225+1 unta chanda walata salli wisi karanna kawda ehema unoth onawata wada dangaluoth , SC yanna unath bank walata limit ekak thiyenawa regulation strick wadi unoth ehma SC yanna tharam ona naha puluwan regulation tika wath dala thiyenawada gudielines nam follow nokara indiwi , laws & regulations ona.
    The same goes for JustPay. CBSL and LankaPay have already provided a solution for it, but banks were initially slow to adopt it. I think most banks have now implemented it, which is why JustPay related scams are rare today.
    Mokadda solution eka?
    saralama solution ekak thiyenawa - opt out wena eka , ehema karanna puluwanda danta???


    Most of these scams are not run by Sri Lankans, so it does not matter what rules and regulations we have here in Sri Lanka.
    ow eka thamayi mama kiwweth
    lankawe indan oparate una dewal walata ez cash mega wasana scam mukuth karala thiyenawada rajayen?

    lankawe indan operate wena pita rata unwa scam karana ewath amaruyi kiyamu danduwam denna

    lankawe indan operate wuna ,lankawe minissunwa scam karala mattu una ewata ko dunna danduwam , chodana , sakshi hariyata usawi giyada? neeth hadala thiyenawa ewat wath action ganna

    e dewal karawanna thama 225+1 inne administrate karanna gov eka .
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    Mokadda solution eka?
    saralama solution ekak thiyenawa - opt out wena eka , ehema karanna puluwanda danta???
    Justpay is a payment platform that works across different banks, and the account holding bank has the ability to reject/accept these transaction, so if the bank wants, they can implement opt out feature (enable by default, disable by default etc). Different banks may have different solutions for this, some banks enabled this by default that is the root cause of all the problems.
    This is like banks implementing an insecure payment gateway and people asking from the government/CBSL why this is happening?

    For the people who wants to use the just pay, now the bank has the ability to do some additional checks, there are some features implemented with telco/internet connection providers to verify the internet connection (if the connection is owned by the same account holder etc). Idea is to verify if the user is using the internet connection through the same mobile number that otp has sent. (Personally I am skeptical about this solution, but the bank having ability do this level of cheks is great.)
     

    netnet

    Well-known member
  • Oct 6, 2016
    9,640
    8,364
    113
    āļ…āļąāˇš āļ¯āˇ™āļē⎒āļēāļąāˇš āļ¸āļœāˇš āļ­āˇ’āļļ⎊āļļ āļģ⎔ 70 ⎄⎐āļšāˇŠ āļšāļģāļŊāˇ. ⎄⎙āļą āļœāˇ„āļ´āļąāˇŠ āļ¸āˇāļŠ āˇ„āˇāļšāļģāˇ :sorry: :lol:
     

    Monkey D Dragon

    Well-known member
  • Sep 22, 2024
    6,168
    6,654
    113
    East Blue (Goa Kingdom)
    Justpay is a payment platform that works across different banks, and the account holding bank has the ability to reject/accept these transaction, so if the bank wants, they can implement opt out feature (enable by default, disable by default etc). Different banks may have different solutions for this, some banks enabled this by default that is the root cause of all the problems.
    This is like banks implementing an insecure payment gateway and people asking from the government/CBSL why this is happening?




    siwurak da gena kaa gahana video eketh kalin kiyala ayin karanna kiyana eka online serama, eeta passe phone eka ussala or illagena activate karala tiyenne , ethana waraddak thiyena bawa aththa phone eka ussapu eke , eth e weddith bank eke branch walata option ekak naha disable karanna oka or danne naha

    athhta lokedi oka disable karanna option ekak branch walata danuwath wela naha e weddi nam (people's or boc vid eka)

    *************************************************************************************************************************************

    Justpay eka secure widihata wada karanna hadana eka hodayi

    "default dala thibba eka opt out wena widihak hariyata danuwath nokara " waradi 100%

    oya scam yaddith bank walata gihin ahuwama danne naha opt out wena widiha
    adu tharame account ekak mokak hari justpay app ekakata link welada kiyana eka balaganna option ekak thiyenawada bank eken ahuwama banak ekaa balanna puluwanda system eken?

    " so if the bank wants, they can implement opt out feature (enable by default, disable by default etc)."
    justpay eka or cbsl idk adala un tika oya system eka account walata
    activate wena widiha gana reulation ekka launch wenna ona muladima,
    nathuwa bank ekata ona widihata karanna kiyala atha pihida ganna nam CBSL eka mokatada

    ehema una eke results thamayi dasadahas ganan otp scams walata ahu une
     
    Last edited:

    Rick Sanchezz

    Well-known member
  • Dec 19, 2020
    7,244
    11,156
    113
    Yako mata giya sathiye awa [email protected] eken account ussana phishing link ekak.. gmail eke inbox deliver una..
    spoof email ekak gmail inbox awada spam warning ekak netiwa? spf,dkim validate wela da? pudumai block une ne kiwwama. puluwan nam email header eke details tika dapan machan.

    pretty much yes.
    there are some other practicle tricks to get both login otp and transaction otp from the user.

    User goes to the fake site > Enter credentials > triggers the attacker to login with credentials > user gets the otp > submits the otp > attacker gets the otp but the take site take a long time to submit the otp/keep showing the loading screen (this is a deliberate by the attacker) > attacker login with the otp > immediately start a transaction( usually a new transaction otp says this is for a transaction, so most likely the attacker can add his account as a registered account in the portal *more details at the end of the post) > the the fake site says your otp is incorrect and submit the new otp sent (the new otp is the transaction or new account add otp) > user submits it and game over.

    other thing is some banking apps does not allow login from two different locations(two login sessions), if an attacker take over an account and keep using it, the real user has no way of login to the account until the attacker logs out. I think banks have disabled multiple login attempts as a security mechanism, but it could work in favor of the attacker.

    *more details at the end of the post
    about this. Attacker never gets the money in to his own account. Attacker always has few contacts with shops (usually sellers from clarified sites, or facebook market place) they already have account numbers of some shops or sellers, and attacker transfer the money to those clueless sellers, they will send the item to the attacker. or there could be another layer (like a drop-shipping the item to someone else). It is very hard to track down the real attcker.

    combank nam login wenakota otp request karanne neha. anyway, oya kiwwa wage phishing site ekedi loading wenawa kiyala dala OTP ganna eka try karanna puluwan. wede ehema nam oka realtime salli adina wede wennat one.

    hebei mataka widihata munge multiple sessions allow karala neha. devices 2kin access karoth parana session eka logout wenawa. netnam keylogger ekak tiyenne one. ehema netnam mun cards walin adinawa wenna one. samahara ecommerec platform wala OTP request karannet nehane.


    āļ•⎀ āļšāļģāļąāˇŠāļą āļ­āļ¸āļē⎒ āļģāļĸāļēāļšāˇŠ āļ‰āļąāˇŠāļąāˇš . āļģāļĸāļē āļ•⎀ āļšāļģāļąāˇŠāļą āļ•āļą āˇ€āˇ’āļ¯āˇ’⎄āļ§ āˇ„āļ¯āļąāˇŠāļą āļ­āļ¸āļē⎒ āļ…⎀⎔āļģ⎔āļ¯āˇ” 5 āļšāļ§ āļ´āˇāļģāļšāˇŠ 225+1 āļšāˇŠ āļē⎀āļąāˇŠāļąāˇš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‰āˇƒāˇŠāˇƒāļģ āļ‰āļŗāļ´āˇ” āļ‹āļąāˇ”āļ­āˇŠ āļ‘āļšāļē⎒ āļ‹āļąāˇŠāļœāˇš āļĸ⎜āļļ⎊ āļ‘āļš āļšāļģāļąāˇŠāļąāˇš āļąāˇāˇ„⎐ 225+1 āļšāˇāļŊāļšāļąāˇŠāļąāˇ’ āļ§āˇ’āļš āļ¯āˇāļąāˇŠ āļ‰āļąāˇŠāļą & āļ¸āˇš ⎀⎙āļąāļšāļąāˇŠ āļ‰āļŗāļ´āˇ”

    hema magulatama 255 japa karala wedak ne ban. Bank eka dena ganna owa monitor karala, threat asses karala unge brand + usersla protect karaganna. Un layer pita layer demmath wedak ne phishing sites tika tiyenakan.

    Lankawe un kese wetat reputed fintech companies nam phishing domain eka register wela 1,2 hours yana kota domain eka clientHold wela take down karalath iwarai.
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    combank nam login wenakota otp request karanne neha. anyway, oya kiwwa wage phishing site ekedi loading wenawa kiyala dala OTP ganna eka try karanna puluwan. wede ehema nam oka realtime salli adina wede wennat one.

    hebei mataka widihata munge multiple sessions allow karala neha. devices 2kin access karoth parana session eka logout wenawa. netnam keylogger ekak tiyenne one. ehema netnam mun cards walin adinawa wenna one. samahara ecommerec platform wala OTP request karannet nehane.
    āļ¸āˇš ⎀⎐āļŠāˇš āļšāļģāļ¯āˇŠāļ¯āˇ’ user ⎀ āļŠāˇ’⎀āļēāˇ’āˇƒāˇŠ āļ¯āˇ™āļšāļšāˇ’āļąāˇŠ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™ āļąāˇāˇ„⎐āļąāˇš
    User āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™ āˇ†āˇšāļšāˇŠ ⎃āļē⎒āļ§āˇŠ āļ‘āļšāļ§, scammer/hacker āļ­āļ¸āļē⎒ real site āļ‘āļšāļ§ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™. āļ‘āļ­āļšāˇœāļ§ āļ‘āļš āļŊ⎜āļœāˇ’āļąāˇŠ āˇƒāˇ™āˇāļąāˇŠ āļ‘āļšāļē⎒ āļ­āˇ’āļē⎙āļąāˇŠāļąāˇ™
    ⎄⎐āļļ⎐āļē⎒ āļ¯āˇāļąāˇŠ ⎄⎐āļ¸ āļļ⎐āļ‚āļšāˇ”⎀⎙āļ¸ āļŊ⎜āļœāˇŠ āļ‹āļąāˇāļ§ āļ´āˇƒāˇŠāˇƒāˇ™ āļēāˇ–āˇƒāļģ⎊āļ§ SMS āļ‘āļšāļšāˇŠ āļēāļąāˇ€āˇ, āļ’āļ­āˇŠ āļēāˇ–āˇƒāļģ⎊ fake site āļ‘āļšāļ§ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļą āˇ„āļ¯āļą āļąāˇ’āˇƒāˇ āļ’ SMS āļ‘āļšāļ­āˇŠ ignore āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ.

    āļ¸āˇšāļš āļģ⎒āļēāļŊ⎊ āļ§āļē⎒āļ¸āˇŠ ⎀⎙āļąāˇŠāļą āļ•āļąāļ­āˇŠ āļąāˇāˇ„⎐, ⎆⎔āļŊ⎊ āļ´āˇāļ­āˇŠ āļ‘āļš automate āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ āļąāˇš. āļ‘āļ­āļšāˇœāļ§ āļšāˇœāļē⎒ ⎀⎙āļŊ⎚ āļ¸āˇœāļą āļēāˇ–āˇƒāļģ⎊ āļŊ⎜āļœāˇŠ āļ‹āļąāļ­āˇŠ pre-define āļšāļģāļŊāˇ āļ­āˇ’āļēāļą automation āļ‘āļš āļģāļąāˇŠ ⎀⎙āļŊāˇ user āļœāˇ™ account āļ‘āļš āˇ„āˇ’āˇƒāˇŠ āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ.
     

    Rick Sanchezz

    Well-known member
  • Dec 19, 2020
    7,244
    11,156
    113
    āļ¸āˇš ⎀⎐āļŠāˇš āļšāļģāļ¯āˇŠāļ¯āˇ’ user ⎀ āļŠāˇ’⎀āļēāˇ’āˇƒāˇŠ āļ¯āˇ™āļšāļšāˇ’āļąāˇŠ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™ āļąāˇāˇ„⎐āļąāˇš
    User āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™ āˇ†āˇšāļšāˇŠ ⎃āļē⎒āļ§āˇŠ āļ‘āļšāļ§, scammer/hacker āļ­āļ¸āļē⎒ real site āļ‘āļšāļ§ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļąāˇ™. āļ‘āļ­āļšāˇœāļ§ āļ‘āļš āļŊ⎜āļœāˇ’āļąāˇŠ āˇƒāˇ™āˇāļąāˇŠ āļ‘āļšāļē⎒ āļ­āˇ’āļē⎙āļąāˇŠāļąāˇ™
    ⎄⎐āļļ⎐āļē⎒ āļ¯āˇāļąāˇŠ ⎄⎐āļ¸ āļļ⎐āļ‚āļšāˇ”⎀⎙āļ¸ āļŊ⎜āļœāˇŠ āļ‹āļąāˇāļ§ āļ´āˇƒāˇŠāˇƒāˇ™ āļēāˇ–āˇƒāļģ⎊āļ§ SMS āļ‘āļšāļšāˇŠ āļēāļąāˇ€āˇ, āļ’āļ­āˇŠ āļēāˇ–āˇƒāļģ⎊ fake site āļ‘āļšāļ§ āļŊ⎜āļœāˇŠ ⎀⎙āļąāˇŠāļą āˇ„āļ¯āļą āļąāˇ’āˇƒāˇ āļ’ SMS āļ‘āļšāļ­āˇŠ ignore āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ.

    āļ¸āˇšāļš āļģ⎒āļēāļŊ⎊ āļ§āļē⎒āļ¸āˇŠ ⎀⎙āļąāˇŠāļą āļ•āļąāļ­āˇŠ āļąāˇāˇ„⎐, ⎆⎔āļŊ⎊ āļ´āˇāļ­āˇŠ āļ‘āļš automate āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ āļąāˇš. āļ‘āļ­āļšāˇœāļ§ āļšāˇœāļē⎒ ⎀⎙āļŊ⎚ āļ¸āˇœāļą āļēāˇ–āˇƒāļģ⎊ āļŊ⎜āļœāˇŠ āļ‹āļąāļ­āˇŠ pre-define āļšāļģāļŊāˇ āļ­āˇ’āļēāļą automation āļ‘āļš āļģāļąāˇŠ ⎀⎙āļŊāˇ user āļœāˇ™ account āļ‘āļš āˇ„āˇ’āˇƒāˇŠ āļšāļģāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ.
    That's the point! mata amataka una user phishing site ekata log wela inne kiyala.😅😅
    mehe nam itin minissu danne neti nisa godak ahu wenne. Ape un SSL neti unath click karala yanawane.
     

    NEMISIS

    Well-known member
  • Nov 13, 2013
    11,403
    19,560
    113
    Colombo
    That's the point! mata amataka una user phishing site ekata log wela inne kiyala.😅😅
    mehe nam itin minissu danne neti nisa godak ahu wenne. Ape un SSL neti unath click karala yanawane.
    ⎆⎒⎁⎒āļąāˇŠ ⎃āļē⎒āļ§āˇŠ āļ‘āļšāļ§ āļ‹āļąāļ­āˇŠ āļļāļąāˇŠ lets encrypt ⎀āļœāˇš āļ‘āļšāļšāˇ’āļąāˇŠ ssl āļœāļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ āļąāˇš. āļ’āļš āļąāˇ’āˇƒāˇ āļ¸āˇš ⎀āļœāˇš āļ‘āļšāļšāļ§ āˇ„āˇœāļŗāļ§āļ¸ āļ¯āļąāˇŠāļą āļ‘āļšāˇ™āļšāˇŠ āļ‹āļąāļ­āˇŠ āļ…⎄⎔ ⎀⎙āļąāˇŠāļą āļ´āˇ”āļŊ⎔⎀āļąāˇŠ
    Domain āļ‘āļš āļąāˇ’āˇƒāˇ email ⎄āļ¯āļąāˇŠāļąāļ­āˇŠ āļ´āˇ”āļŊ⎔⎀āļąāˇŠ, āļ‘āļ­āļšāˇœāļ§ āļļ⎐āļ‚āļšāˇ”⎀⎙āļąāˇŠ āļ‘⎀āļąāˇ€āˇ ⎀āļœāˇšāļ¸ email āļ‘⎀āļąāˇŠāļąāļ­āˇŠ āļ´āˇ”āļŊ⎔⎀āļąāˇŠ āļąāˇš.
     
    • Like
    Reactions: Rick Sanchezz

    kasun090354t

    Well-known member
  • Aug 21, 2011
    24,285
    36,390
    113
    āļšāˇ‘āļœāļŊ⎊āļŊ
    āļ…āļąāˇš ⎄⎔āļšāˇāļąāˇ€ āļ¸āˇ™āˇ„⎙āļ¸ āļ‘āļšāļšāˇŠ āļ¯āˇāļąāˇŠāļąāˇš āļ¯āļąāˇŠāļąāˇš. āļ¸āˇ”⎅⎔ āˇƒāˇ™āˇƒāļ­āļ¸ āļ•āļšāˇš āļ­āˇ’āļē⎙āļąāˇŠāļąāˇš.. :lol: :lol:. Website log ⎀⎙āļąāˇŠāļą āˇ€āˇ™āļąāˇ€āˇ āļœāˇ’āļē āļ¸āˇāˇƒāˇ™āļ­āˇŠ log āļ‹āļąāˇ. āļ‹āļąāˇŠ āļ”āļē ⎀⎙āļą website āļšāļ­āˇāˇ€ āļ¯āˇāļąāˇŠ āļšāˇāļŊāļēāļšāˇŠ āļ­āˇ’āˇƒāˇŠāˇƒāˇš āļšāˇ’āļēāļą āļąāˇ’āˇƒāˇ āļ¯āˇ„āļ´āˇāļģāļšāˇŠ ⎀⎒āļ­āļģ āļļāļŊāļŊāˇ log ⎀⎙āļąāˇŠāļąāˇš. āļ’āļ­āˇŠ āˇƒāˇ”āˇ€āļģ⎊ āļąāˇ‘ āļ¯āˇāļąāˇŠāļąāļ¸āˇŠ āļ¸āļ§..
     
    • Like
    Reactions: wtsamantha

    kasunkaru

    Well-known member
  • Jan 25, 2018
    7,558
    5,824
    113
    daana ekak daapalla sampath eke dual authentication hinda pattama safe. wena eka bank ekakwat ochchra safe naa