Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

Beware PayPal Users! Hackers are using new Phishing Trick!

Hackers are using a new type of Phishing Trick to steal the credit and debit card details of PayPal Users. Phishing is very old and high profitable technique for hackers to target the victims. Hackers are using same phishing techniques but they are changing its way of use. A malware researcher and security expert reported about this phishing attack. The online name of that researcher is “@dvko1uk”.

 

How Hackers are Targeting Victims?

Hackers are redirecting PayPal users to a promised PayPal website. This website looks like original PayPal website but when they fill their details, it goes on the server which is in the control of hackers. Hackers are using this trick with the help of JavaScript. Hackers are targeting victims through Emails. May be, Hackers are getting Email ID’s of people from Dark Web. No Doubt, a number of Email details are available on the Dark Web after some major data breaches such as Tumblr, LinkedIn and MySpace.

 

Logic behind this Attack?

Hackers are using a promised PayPal Website. Hackers are Using “Continue” button on promised website. With the help of hidden redirection JavaScript, Hackers could get the details of victims when he or she will click on this “Continue” button. In the genuine PayPal website, there is not any “Continue” button. There is only a “Finish” button in the end of genuine PayPal website. Average users could not detect these type of situations, therefore they are clicking on “Continue” button and passing their information to hackers.

 

 

Also read: Use of HTTPS will be a must for all iOS Apps by 2017! Apple said!

 

“The JavaScript used by hackers, contains special type of coding which could intercept the interaction of victim’s with official PayPal website. Hackers are sending link of this website to victims. When victim clicks on that link, he will go to genuine PayPal website. After that when he or she will fill details, then JavaScript will do its work and it will redirect the user to phishing page.”

 

Tips for PayPal Users

  • Never visit those links directly, which you are getting through emails. First check the complete details of Email by seeing original header.
  • Hackers could use domain names, which look likes PayPal’s official websites. For eg. www.paypalnew.com, www.paypalpayments.com etc. Before filling your details, be sure you are using genuine website.
  • Use pro version of AV tools which are giving Email Security too.

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.