Welcome, Guest: Register On Nairaland / LOGIN! / Trending / Recent / New
Stats: 3,194,489 members, 7,954,891 topics. Date: Saturday, 21 September 2024 at 11:51 AM

Equitorial Bank Website Used For Interswitch 419 Scam - Webmasters (3) - Nairaland

Nairaland Forum / Science/Technology / Webmasters / Equitorial Bank Website Used For Interswitch 419 Scam (11420 Views)

Royal Rumble! Paga Vs. Voguepay. Vs Gtpay. Vs Interswitch. Vs Zenith Global Pay / Powerful Webmaster Needed For Interswitch Intergrated Website / Interswitch /etransact And Vpay Cards For N15,000 Set Up ? (2) (3) (4)

(1) (2) (3) (4) (5) (Reply) (Go Down)

Re: Equitorial Bank Website Used For Interswitch 419 Scam by rasputinn(m): 7:57pm On Jun 04, 2009
I never do bank transactions via the internet
Re: Equitorial Bank Website Used For Interswitch 419 Scam by rasputinn(m): 8:08pm On Jun 04, 2009
Phishing indeed
Re: Equitorial Bank Website Used For Interswitch 419 Scam by Opoki(m): 9:53pm On Jun 04, 2009
You might not believe this, These fraudsters have allies among the bank officials
who give out vital information that could aid clonning of a website and ftp,
This was personally revealed by my uncle who is working with cybercrime.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by Opoki(m): 10:19pm On Jun 04, 2009
You might not believe this, These fraudsters have allies among the bank officials
who give out vital information that could aid clonning of a website and ftp,
This was personally revealed by my uncle who is working with cybercrime.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by Nobody: 12:33am On Jun 05, 2009
I usually get this mails too,

This people extract emails from this website. Most of NL members get this email.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by na2day2(m): 2:34am On Jun 05, 2009
look at it on the bright side, it shows that the future of IT and IT security will be very strong in Nigeria, thats jobs baby jobs wink wink
Re: Equitorial Bank Website Used For Interswitch 419 Scam by Nobody: 4:26am On Jun 05, 2009
sledjama:

I saw a thread here about a month now, this particular website was hacked.
how come? how can they let it happen again.



how come i see my previous post on the reply page
but doesn't show up on the threads

is it also coming down to Nairaland?
Re: Equitorial Bank Website Used For Interswitch 419 Scam by larimo(m): 8:09am On Jun 05, 2009
Its not a new thing, looking for the gullible ones. It only calls for vigilance and wisdom.

If one has a problem with his ATM, he should see his bank. I am sure no one ever got his card directly from Interswitch.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by lagerwhenindoubt(m): 9:04am On Jun 05, 2009
Just on the side, for those who have complained about time-outs or 501 errors. and slow posts.

If you have VISTA then it is very likely that Auto-Tune is enabled.

See this article to solve this problem
Disable TCP Auto-Tuning to Solve Slow Network, Cannot Load Web Page or Download Email Problems in Vista

http://www.mydigitallife.info/2007/03/22/disable-tcp-auto-tuning-to-solve-slow-network-cannot-load-web-page-or-download-email-problems-in-vista/

When Windows Vista is connected to high speed broadband Internet connection, there may be some incompatibilities and conflict problem or error such as the following:

* Poor intermittent network performance.
* Slow network loading.
* Unable to open and load some websites or webpages using Internet Explorer or Firefox, where the blue loading bar keeps running for a long time, but the pages fail to load.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by kshow1(m): 10:51am On Jun 05, 2009
larimo:

Its not a new thing, looking for the gullible ones. It only calls for vigilance and wisdom.

If one has a problem with his ATM, he should see his bank. I am sure no one ever got his card directly from Interswitch.

Good talk and advice.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by jusx50: 12:34pm On Jun 05, 2009
I've not received such an email though but i guess unemployment/laziness causes it and if govt creates job opportunities for youths, this crime rate will stop, brilliant job by these scammers but beware !!!!
Re: Equitorial Bank Website Used For Interswitch 419 Scam by babaogun(m): 1:06pm On Jun 05, 2009
@Everyone
Important points for online banking

Your bank is never going to request for any information via email. they can tell you to go to the nearest branch to verify any detail.

Cheers folks.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by mboma(m): 5:02pm On Jun 05, 2009
i almost fall for that stuff, i was thinking its was from[b] interswicth[/b] dat day the server was very slow so i decide to go the next day only to here the info on my radio set dat scam guyzz are foreging the interswich web.immidiatley i delected all the message. i think God ho! i for don wreck!
Re: Equitorial Bank Website Used For Interswitch 419 Scam by mboma(m): 5:13pm On Jun 05, 2009
i almost fall for that stuff, i was thinking its was from[b] interswicth[/b] dat day the server was very slow so i decide to go the next day only to hear the info on my radio set dat scam guyzz are foreging the interswich web.immidiatley i delected all the message. i think God ho! i for don wreck!
Re: Equitorial Bank Website Used For Interswitch 419 Scam by Nobody: 5:29pm On Jun 05, 2009
mboma, congrat.

lagerwhenindoubt:

Just on the side, for those who have complained about time-outs or 501 errors. and slow posts.

If you have VISTA then it is very likely that Auto-Tune is enabled.

See this article to solve this problem
Disable TCP Auto-Tuning to Solve Slow Network, Cannot Load Web Page or Download Email Problems in Vista

http://www.mydigitallife.info/2007/03/22/disable-tcp-auto-tuning-to-solve-slow-network-cannot-load-web-page-or-download-email-problems-in-vista/

When Windows Vista is connected to high speed broadband Internet connection, there may be some incompatibilities and conflict problem or error such as the following:

* Poor intermittent network performance.
* Slow network loading.
* Unable to open and load some websites or webpages using Internet Explorer or Firefox, where the blue loading bar keeps running for a long time, but the pages fail to load.

How come it happens only on nairaland.
i spend most of my lifetime online but i dont see that happening elsewhere
Re: Equitorial Bank Website Used For Interswitch 419 Scam by lagerwhenindoubt(m): 5:57pm On Jun 05, 2009
just stickin my thumb in the air here,

could it be that nl gets at minimum 1000 posts within a second such that the web-server crawls to a halt even with asynchronous processing?
Re: Equitorial Bank Website Used For Interswitch 419 Scam by soludo2008(m): 7:15pm On Jun 05, 2009
shocked Bank fraudsters are on rampage. I hope that someone will not call for my head if I say that over 80% bank fraud have traces to the bankers themselves . A member of the Association of Christian Bankers should confirm my guessing.

Re: Equitorial Bank Website Used For Interswitch 419 Scam by DrLorenz1(m): 7:22pm On Jun 05, 2009
@ post

I don't fall for such scams. I've been sent such emails before and i don't bother opening them. I could just for fun just to see if the scammers would use the info i put in there lol. When they see that the info is wrong, body go tell them. grin. I have a friend who wanted me to help him and his group of friends design a page on a fake nokia website supposedly top be used like they do for MTN Winners scam. I posted him so tay he had to leave me alone grin

@aeso
Where do you stay in Australia?
Re: Equitorial Bank Website Used For Interswitch 419 Scam by soludo2008(m): 7:27pm On Jun 05, 2009
shocked Bank fraudsters are on rampage. I hope that someone will not call for my head if I say that over 80% bank fraud have traces to the bankers themselves . A member of the Association of Christian Bankers should confirm my guessing.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by xzile: 8:53pm On Jun 05, 2009
man i see.its high time people should wise up.i've goten such few many times.like mode nine i only press delete cuz they cant hustle a hustla.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by ayodeji1(m): 11:15pm On Jun 05, 2009
i almost fell for it as well.i recieved so many of such until i decided to call all the banks i have account with to verify if its truly from them before i finally realised it was a scam.but what is this country turning into?i wonder.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by adeomos(m): 11:01am On Jun 06, 2009
one needs to be very carefull this days
Re: Equitorial Bank Website Used For Interswitch 419 Scam by agabaI23(m): 12:30pm On Jun 06, 2009


Dear value customer,

We noticed that you need to update your Halifax Online Account . However, You will need to update some of your records in our Resolution center, if not, this will result in your online account been suspended. Please update your records with us on or before June 8th, 2009.

please contact us immediately by clicking on this link below:

Click Here To Start

Thank you for your prompt attention to this matter.
We apologize for any inconvenience.

Thank you for using Halifax !
The Halifax plc.

Information on protecting yourself from fraud, please review the Security Tips in our Security Center.

Re: Equitorial Bank Website Used For Interswitch 419 Scam by Everbright(f): 3:02pm On Jun 06, 2009
Just got one now.
But you know what! Just click on delete when you get such to avoid being tempted. cool
Re: Equitorial Bank Website Used For Interswitch 419 Scam by aeso(m): 5:12pm On Jun 06, 2009
na2day?:

look at it on the bright side, it shows that the future of IT and IT security will be very strong in Nigeria, thats jobs baby jobs  wink wink

Unfortunately senior management in Nigeria and elsewhere never make IT security a priority and it is always pushed down the list if it ever gets discussed at management meetings. This is because it is seen as an unnecessary cost and an obstacle to a rich customer experience. However, once a security breach occurs, it becomes [i]top [/i]agenda in an [i]emergency [/i]meeting. Let's hope it creates more jobs so guys like us can relocate back and contribute to Naija's development.
Re: Equitorial Bank Website Used For Interswitch 419 Scam by aeso(m): 5:58pm On Jun 06, 2009
nitation:

For those lamenting on the web administrator!

You should ask yourself if the bank took the proper procedure in employing the better guys to maintain their online server.

2) How much was "positively" invested in the so-called ETB online website.

3) What checks and balances was put to place on those maintaining the website and how do they respond to problems when encountered; DO this people (ETB) even consider their customer's protection/safety.

Lastly, the web admin doesn't have to give access before a less secured site can be compromised. I give kudos to aeso for sharing his thoughts here, but believe me phishing has gone way beyond how it seem.

My contribution

- nitation


Thanks.

webpro:

How is it possible that this criminals got into ET Bank's website control panel and created a subdomain to upload a phishing website. believe me, the person incharge of managing ET Bank's website is directly responsible for this. As someone who has grounded knowledge in Etical soiling and forency investigation, i know well, how a website is hacked into, so u wont tell me to believe that the fraudstars actually hacked into ETB's website and used it to upload a fraud page.

Please other web programmers here should know what am talking about. Its only if the bank uses a kanel shell code which is vulnerable to attacks, or any other easy web uploading scripts that this happens. Moreso, this fraudstars are not even hackers because what they do is not regarding as soiling so they would not possibly be able to go into their cpanel.

I'm open to more arguments on this


The bank should question their site admin for this! PERIOD!

Have you heard of famous websites that have been hacked in the past? CNN, White House by Chinese hackers? Do a google search to find out. I don't dispute your view of a possible collusion with an ETB officer in this, but as a forensic or "forency" expert you claim to be, you should bear a more flexible approach in your investigations.
Believe me it is quite easy, although may require some patience. Here's one avenue:

1. Run an nslookup to get web server's IP address.
2. Scan and  probe server for services running, do OS fingerprinting to discover what OS is running. Possibly detect which web server is in use as well.
3. Scan to see if there are vulnerabilities on the server that have [b]not [/b]been patched. If none found, subscribe to mailing lists for zero-day attacks and wait till patiently new vulnerability is reported. Quickly run an exploit before web/server admins have time to patch systems.
4. Run an exploit to hijack web server. Elevate your privileges/permissions and plant a backdoor for future privileged access. Design your [fake] interswitch web page and upload on server using ssh. Design exactly like real interswitch, or just download copy of the real site if you don't have the time.
5. Create new database on existing database server. Link [fake] interswitch web page form to database to "harvest" proceeds of phish.
6. Send bogus email to several thousands of users.
7. Run operation for a few hours only to escape detection. Clear funds in "mugu" accounts.
8. Cover your tracks by clearing the system logs of all traces of activity.

So it's as [easy] as that. The problem I see is that most webmasters are ignorant of security issues.
Ask yourself who gets the best jobs? It has never been, and never will be, the most suited/skilled. It's always the individual who blows his trumpet the most with a 10-page CV or who gets there on merit.

The lesson here is that web servers must always be patched regularly. Users must also look for a padlock/key sign on their browser when posting confidential info. If you don't see a padlock, close the page immediately. If you do see a padlock, click on it to check the site's certificate to ensure it the real Interswitch, as anyone can easily setup a secure server.

I am open to more argv on this,
Re: Equitorial Bank Website Used For Interswitch 419 Scam by aeso(m): 6:35pm On Jun 06, 2009
Dr. Lorenz:

@ post

I don't fall for such scams. I've been sent such emails before and i don't bother opening them. I could just for fun just to see if the scammers would use the info i put in there lol. When they see that the info is wrong, body go tell them. grin. I have a friend who wanted me to help him and his group of friends design a page on a fake nokia website supposedly top be used like they do for MTN Winners scam. I posted him so tay he had to leave me alone grin

@aeso
Where do you stay in Australia?

brotha, na Melbourne I dey oh! U dey my side?
Re: Equitorial Bank Website Used For Interswitch 419 Scam by aeso(m): 6:55pm On Jun 06, 2009
@ webpro:
http://cyberinsecure.com/white-house-network-hacked-by-chinese-on-multiple-occasions/

So kpanel or cpanel access isn't needed here as you believe. The chinese gained access to the white house networks over and over again and the American cybersecurity experts had no clue what had happened. They even served malware (viruses, Trojans, etc.) to visitors to the site on one occasion and probably used that to gain access to those PCs that downloaded the Trojans as well!

So we are in an insecure online world! sad sad cry
Re: Equitorial Bank Website Used For Interswitch 419 Scam by joobreel(m): 8:50pm On Jun 06, 2009
Internet security!!! How secure can it be some people work 24/7 to breach it. I bow o
Re: Equitorial Bank Website Used For Interswitch 419 Scam by femzy(m): 7:33am On Jun 07, 2009
aeso:



I am open to more argv on this,

Why argue with him about what Blackhats can do ,
Re: Equitorial Bank Website Used For Interswitch 419 Scam by cystein(m): 11:52am On Jun 07, 2009
Well guys this aint a difficult thing to do. What happens in this case is the scammers pick the page source but edit the form action for example. If i have a form that i want to defraud you with i can easily set it as follows.

<form action="http://mywebsite.com/snb/9071:8080" that instead posts me your card details enough to give me access to your account. Always call the bank on the original numbers and not the contacts issued on the site

(1) (2) (3) (4) (5) (Reply)

Challenges Facing Nigerian Bloggers / How To Get Started With Blogging In Less Than 5minutes / Fg Moves To Block Internet Streaming

(Go Up)

Sections: politics (1) business autos (1) jobs (1) career education (1) romance computers phones travel sports fashion health
religion celebs tv-movies music-radio literature webmasters programming techmarket

Links: (1) (2) (3) (4) (5) (6) (7) (8) (9) (10)

Nairaland - Copyright © 2005 - 2024 Oluwaseun Osewa. All rights reserved. See How To Advertise. 67
Disclaimer: Every Nairaland member is solely responsible for anything that he/she posts or uploads on Nairaland.